Skip to content
Proactive security updates

Maintenance by platform: six systems, one quality standard

Shopware, WordPress, TYPO3, Contao, Drupal and Joomla follow their own update cycles and security models — we maintain each platform with specialized processes instead of a one-size-fits-all scheme. The SLA terms are identical for every system: maintenance contracts from €199 per month.

SLA packages from €199 per month 6 platforms under managed service Staging test before every update

since 2013

in business

6

platforms under managed service

45 min

first response in the Enterprise SLA

50+

managed projects

A maintenance process that runs identically for every platform overlooks the decisive differences between the systems. As an e-commerce system, Shopware brings the complexity of order processing, plugin dependencies and multi-layered caching. WordPress thrives on a vast ecosystem of plugins and themes — enormous flexibility on one hand, a large attack surface on the other. TYPO3 is designed as an enterprise CMS for extensive, multilingual installations with clearly defined LTS cycles. Contao, Drupal and Joomla in turn each have their own release policies, extension ecosystems and typical vulnerabilities. We maintain all six platforms with system-specific care routines built on the same service modules — and on the same terms: the SLA maintenance contract starts at €199 per month, regardless of which system you run.

Six platforms, one control center

One maintenance system, six platforms
Maintenance per platform, compared
Shopware CE
E-commerce
Core and plugin updates
Checkout and payment tested
Cache and database care
WordPress
CMS & shop
Core, plugin and theme care
Security hardening for wp-admin
Shop checkout end-to-end
TYPO3
Enterprise CMS
LTS cycle in view
Extensions Composer-managed
Cache tuning
Also Joomla, Drupal and Contao — same process, same SLAStaging before every update
SLA packagesfrom €199 per month
Managed service6 platforms
The platform control center of our managed service: version status, staging tests, vulnerability matching and backups of all systems in one overview. Example view — values are illustrative.

Six platforms, six specialized care approaches

For online shops we go one level deeper: the Shopware maintenance page describes our managed service for revenue-critical Shopware shops with automated checkout tests and performance care, while the WordPress maintenance page covers the counterpart for WordPress websites and WordPress shop systems with payment processing. Two special cases have a page of their own because they sit outside the normal maintenance cycle: the jump to a new main version under Shopware major upgrade and the cleanup after a security incident under WordPress hacked. For the ongoing terms, your entry page makes no difference: all systems run on the same three SLA tiers with first response in 8 hours, 4 hours or 45 minutes — the matching prices are on the pricing page.

One process, six variations

The core of our approach is the same for every platform: assessment, full backup, update on a production-like staging environment, automated and manual tests, controlled deployment and a documented rollback path. What differs are the review steps: for Shopware we test checkout and payment, for WordPress the plugin compatibility, for TYPO3, Contao, Drupal and Joomla the extension and content structures.

  • Backup before every change, tested for recoverability
  • Platform-specific test plans instead of generic click-checks
  • Rollback in minutes if an update causes problems
Uniform maintenance process per platformidentical for all six
Inventory
Full backup
Staging test
Deploy
Monitoring
Automated and manual tests before deploy
Rollback point on every intervention
Monthly report per platform

Vulnerability matching across all systems

Every platform maintains its own security bulletins — from Shopware security releases through the vulnerability databases of the WordPress ecosystem to the security advisories of TYPO3, Drupal, Contao and Joomla. We keep a complete inventory of every component in your installation and continuously match it against these sources. Critical flaws are patched with priority, long before the regular update cycle would reach them.

  • Component inventory per system: core, plugins, extensions, themes
  • Prioritized patches for critical security bulletins
  • Monthly report with version status and resolved risks
Vulnerability matching
Shopware security releasesWordPress ecosystemTYPO3 advisoriesJoomlaDrupalContao
Bulletins from all six systems continuously consolidated
Critical patches across platforms within 24 h

How the platforms differ in maintenance

AspectShopware CEWordPressTYPO3
Update logicCore releases plus plugin dependenciesFrequent core, plugin and theme updatesLTS lines with a fixed support period
Critical pointCheckout, payment and multi-layered cachingPlugin variety as the largest attack surfaceExtension compatibility during upgrades
Typical riskUpdate disrupts order process or performanceOutdated extension opens the door to attackersMissed LTS migration without security updates
Our focusAutomated checkout tests before every deployInventory and continuous vulnerability matchingPlannable migration before end of support

The same methodology applies to Contao, Drupal and Joomla, each with its own checkpoints: we maintain Contao along the LTS releases with Composer-based package management, for Drupal we follow the official security advisories with their fixed release windows, and for Joomla the focus is on extension hygiene and hardening frequently attacked default configurations. Across more than 50 managed projects (project experience) we have translated the platform-typical pitfalls into standardized, repeatable workflows — documented in runbooks that we continuously refine. This documentation is also your safeguard: if a contact person is unavailable, every care step remains traceable.

How we get started with your platform

We record version status, installed extensions, server environment and known issues of your system. The result is a condition report with a prioritized action plan — the foundation for the right maintenance contract.

One maintenance contract for every platform

from €199 per month net
  • Basis €199 per month — first response within 8 hours
  • Business €349 per month — first response within 4 hours
  • Enterprise €699 per month — first response in 45 minutes
  • Updates, monitoring, backups and reporting in every package

Basis, Business or Enterprise — the SLA tier determines response time and scope, not the platform. Minimum term 6 months.

What the platform means for maintenance effort

The choice of system says less about the monthly cost than about how the work is distributed across the year. With Shopware the focus is on few but substantial releases: a core jump touches order processing, payment integration and caching at the same time, so every deploy is preceded by a full test run on a production-like copy. WordPress distributes the effort differently — many small updates at short intervals, but with a high dependency on third-party code. What counts here is less the individual update than the discipline of keeping the extension inventory small and current. TYPO3 rewards planning: within an LTS line the ongoing effort stays low, but moving to the next line needs its own time slot and its own budget. Contao, Drupal and Joomla sit in between, each with its own release rhythm, which we track in our monitoring.

Regardless of the system the building blocks stay the same; only their weighting shifts. Security updates and our backup service are included in every tier because they are the basis of any recovery. Performance maintenance matters most where many extensions or large data volumes drag down load times; SSL certificates and GDPR updates affect every platform equally because they depend on law and infrastructure, not on the CMS. And if something does fail, emergency support applies no matter which system runs underneath. That is exactly why our SLA tiers are cut by response time and scope, not by platform.

Typical starting points from our handover practice

Shopware CE
Starting point
The shop was several minor versions behind because an earlier update attempt had disrupted the checkout.
Measure
Set up a production-like staging copy, catch up version by version with an automated purchase run after each step, rollback point before every deploy.
Result
Updates now run in a planned maintenance window instead of as a special project; the order path is retested automatically after every deploy.
WordPress
Starting point
Numerous extensions had accumulated over the years, some of them no longer actively developed.
Measure
Full inventory of all components, comparison against public vulnerability advisories, replacement or removal of unmaintained extensions after testing.
Result
The inventory is documented, every remaining component has a stated purpose and is continuously checked against advisories.
TYPO3
Starting point
The installation was close to the end of its LTS support period, with no date set for the move.
Measure
Compatibility check of all extensions, scheduling of the move outside peak business hours, test plan for editors and front end.
Result
The move happened in an announced window; the next LTS migration is scheduled in the maintenance plan well in advance.

Illustrative sequences from typical handover situations (project experience) — anonymized, without naming clients and without promising results.

Not sure which care your system actually needs?

We check version status, extensions and obvious risks in your installation and tell you which SLA tier fits — free of charge and without obligation.

How these procedures work in practice is documented continuously in our technical blog. Staging Environments for Safe Shop Updates describes the test environment that plays the same role across all six systems. Update Testing: Avoid Regressions After Shop Updates shows which checks after an update are actually meaningful, and Maintenance Windows: Shop Updates Without Downtime explains how to schedule updates without losing sales. For shop systems in particular, Checkout Monitoring: Catch Silent Order Failures is worth reading as well.

Key Takeaways

  • Maintenance by platform: Shopware CE, WordPress, TYPO3, Contao, Drupal and Joomla, each with its own care routines
  • One pricing model for all systems: SLA packages from €199 per month with first response in 8 hours, 4 hours or 45 minutes
  • Every change follows the same chain: verified backup, staging test, controlled deploy, defined rollback point
  • Continuous vulnerability matching across the complete component inventory of all systems
  • Several platforms can be bundled into one contract with unified reporting

Frequently Asked Questions About Maintenance by Platform

What can we help you with?

One click is enough — everything after that is optional.

Tell us briefly about the project

Everything on this step is optional.

When would you like to start? (optional)
How can we reach you?

We usually get back to you within one business day.

By submitting you consent to the processing of your details to handle this request. Details in our privacy policy.

All industries at a glance