Your £5-a-month hosting isn't cheap

It's cheap right up until the day something breaks. Here's what the monthly fee actually covers, what it leaves out, and what to check before you renew.

Nick Ioannou, Senior Web Project Manager at 21 Degrees Digital.
Nick Ioannou 8 min read

Every hosting migration I run starts with the same conversation. We look at what the business pays now, we look at what we'd charge, and someone asks, fairly, why they'd pay more for something they already have.

It's a good question. The honest answer is that they probably don't have the thing they think they're paying for.

A £5 plan buys you space on a server you share with a lot of other websites. That's a perfectly reasonable product. What it leaves out is anyone looking after your site. Nobody updates your plugins or checks the site still works afterwards. Nobody tests the backups. And when something breaks at 6pm on a Friday, you're in a support queue explaining WordPress to someone whose job is the server.

So the better question is what the first bad day will cost you, and who's going to fix it.

What your first bad day costs

Your own number is easy to work out, and it's more useful than any industry average. Take the enquiries or orders your website brings in during an average week and what one is worth to you. Divide that by the hours you're open. The answer is roughly what an hour of a broken website costs you during the working day.

For plenty of small businesses it's a few hundred pounds. For an online shop in November, it's a lot more. And a bad day is rarely an hour. A hacked site or a plugin update that takes out your checkout can run for days before anyone notices, especially when nobody is looking.

Then add the cost that doesn't show up in the sum. Someone who finds your site broken doesn't come back later to check whether you've fixed it. They click the next result.

A backup you've never restored is a hope

Most budget plans say backups are included. Ask three questions about them.

First, where are they stored? If they sit on the same server as your site, one hardware failure takes out the site and the backups together.

Second, how far back do they go? A hack that happened three weeks ago and got noticed yesterday needs a backup older than three weeks. Plenty of plans keep seven days.

Third, who does the restore? On a budget plan, usually you, at the worst possible moment, in an interface you've never opened.

Almost nobody asks whether their backups have been tested. A backup only counts once someone has restored it and watched the site come back.

Your site might be running software that no longer gets security fixes

WordPress runs on PHP, and every version of PHP has an expiry date. After that date it gets no more official security fixes, however many new problems turn up.

PHP 7 is the worst case. Its last version, 7.4, stopped getting security fixes on 28 November 2022. [1] A site still running it has gone almost four years without an official patch to the software everything else sits on.

PHP 8 isn't automatically safe either. Support for 8.0 ended in November 2023, and 8.1 followed at the end of 2025. [1] PHP 8.2 gets its last security fixes on 31 December this year. [2]

Old PHP is also starting to lock sites out of WordPress itself. WordPress 7.0 came out in May and dropped support for PHP 7.2 and 7.3 altogether. [3] Sites on those versions can't take the update, so they're stuck on an older WordPress as well as an older PHP. Plenty of plugins set their own minimum PHP version too, so the longer a site sits on an old version, the more of it stops getting updates.

Sites get stuck because an upgrade can break an older theme or plugin. Plenty of budget hosts leave you on the old version and say nothing, and the site gets a little less secure every month while nobody takes charge.

The PHP version is one of the first things I check on a migration, and on older sites it's out of support more often than we'd like. The upgrade itself is rarely difficult. It needs someone to test the site on the new version, fix whatever breaks, and then switch over.

That's development work rather than hosting, and we price it separately. Your host should still be telling you when your version is running out and what it'll take to move. If yours has never mentioned it, that tells you something.

Plugins are where the break-ins happen

WordPress itself is in decent shape. Patchstack logged 11,334 new vulnerabilities across the WordPress ecosystem in 2025. Only six were in WordPress core, and all six were low priority. 91% were in plugins. [4]

The speed is the worrying part. For the most heavily exploited flaws, Patchstack measured a weighted median of five hours between a vulnerability going public and mass attacks starting. And 46% of vulnerabilities had no fix from the developer at the point they were disclosed. [4]

Five hours. If the only person updating your plugins is you, whenever you remember, you're relying on luck.

Good hosting won't make you immune, and nobody can apply a fix that doesn't exist yet. What it gives you is someone watching for problems with the plugins you actually run, who applies updates quickly and checks the site afterwards.

The part of the speed stat your hosting has most say over

You'll have seen the Deloitte figure: speed up your mobile site by 0.1 seconds and retail conversions rise 8.4%. [5]

Read the study before you quote it. Google commissioned it from Deloitte and the agency Fifty-five. They tracked the mobile sites of 37 large brands in retail, travel, luxury and lead generation for 30 days at the end of 2019. The gains only showed up when every page improved by 0.1 seconds on four separate metrics. [5] It's a decent study of big brands' mobile sites. It doesn't promise a regional plumber 8% more work.

The useful part is one of those four metrics, server response time. That's how long your server takes to send back the first byte of the page, and it's largely down to your hosting. A crowded shared server is slowest exactly when someone lands on your site, and no image plugin will fix that.

What you should be paying for

Before I'd call hosting "managed", I'd want all of this covered:

  • Plugin, theme and core updates applied regularly, with the site checked afterwards
  • Backups kept off the server, going back at least 30 days, and actually tested
  • Monitoring that checks your forms and pages work, as well as whether the server answers
  • Being told when your PHP version is running out, with the upgrade offered well before the deadline
  • A named person who picks up the phone and already knows your site

That costs more than £5 a month. It should cost a lot less than the first bad day. It's also the list we rebuilt our own web hosting around this year.

You might not need any of this

Some businesses genuinely don't. Say your site is a handful of pages that you rarely change, and nothing on it takes payments. If you're happy to log in and update it every week, budget hosting and a calendar reminder is a sensible choice. It's the same logic as the electrician in my last piece .

The trouble is the middle. Plenty of businesses have a site that brings in real work, runs 30 plugins and takes enquiries through a form. It's sitting on a plan designed for a hobby blog, and that's where £5 turns out to be the expensive option.

A test you can run in five minutes

Log into WordPress and go to Tools, then Site Health, then the Info tab. Open the Server section and find the PHP version.

If it's 8.1 or lower, it's no longer getting official security fixes. If it starts with a 7, that's been true since November 2022 at the latest. If it's below 7.4, it can't run the current version of WordPress either. If it's 8.2, the fixes stop on 31 December.

Then try to answer these without looking anything up:

  • When was the site last backed up, and where is the copy?
  • Who finds out if the site breaks at 2am?
  • How many plugins are active, and who last updated them?
  • What does your hosting renew at next year?

If you had to guess at any of those, you know what your £5 is buying.

Want someone to have a look?

Our free digital marketing audit covers the technical side, including PHP, plugins and server response time, so you'll know what needs doing and in what order. Or if you'd rather just talk hosting, have a word with us .

Sources

  1. The PHP Group (2026) Unsupported Branches . Available at: https://www.php.net/eol.php (Accessed: 28 September 2026).
  2. The PHP Group (2026) Supported Versions . Available at: https://www.php.net/supported-versions.php (Accessed: 28 September 2026).
  3. WordPress.org Hosting Team (2026) WordPress 7.0 Server Compatibility . Available at: https://make.wordpress.org/hosting/handbook/compatibility/version/7-0/ (Accessed: 28 September 2026).
  4. Patchstack (2026) State of WordPress Security in 2026 . Covers vulnerabilities disclosed in 2025. Available at: https://patchstack.com/whitepaper/state-of-wordpress-security-in-2026/ (Accessed: 28 September 2026).
  5. Deloitte Digital and Fifty-five (2020) Milliseconds Make Millions . Commissioned by Google. Based on 37 brands' mobile sites over 30 days at the end of 2019. Available at: https://www.deloitte.com/ie/en/services/consulting/research/milliseconds-make-millions.html (Accessed: 28 September 2026).

Frequently asked questions

  • Is cheap hosting bad?

    No. It's a server, and for a small site you look after yourself it's often fine. The problems start when a site that brings in real business sits on a plan where nobody looks after it.

  • What PHP version should my WordPress site be on?

    One that's still getting security fixes, which php.net lists. If yours is 8.1 or lower, it's overdue, and 8.2 joins it on 31 December.

  • What's the difference between shared and managed hosting?

    Shared hosting gives you space on a server. Managed hosting adds the people who update, monitor, back up and fix your site.

  • How do I check my hosting in five minutes?

    Check your PHP version in WordPress Site Health. Then find out where your last backup is, who gets alerted when something breaks, and what your plan renews at.

Stay sharp on what works

No fluff. No clickbait. Just content that actually helps.

By subscribing you agree to our Privacy Policy.