Infrastructure & operations

Application maintenance and continuous improvement

A site that ages well, because someone looks after it

In short
An application maintenance contract covers security updates for the framework and dependencies, defect fixes, monitoring, backups and a pool of improvement hours. Budget 12 % to 20 % of the initial development cost per year; without maintenance, an application becomes vulnerable within eighteen months.
Price this project Talk to an expert

From 540 € excl. VAT · from 12-month term

Why an unmaintained application becomes dangerous

A Laravel application rests on around thirty direct dependencies, themselves resting on several hundred. Every month, some publish security fixes. After a year without updates, an application typically accumulates several publicly documented vulnerabilities — and therefore easily exploitable ones.

The cost of catching up grows non-linearly. Moving from one major version to the next takes a few days; catching up on three major versions looks like a rewrite.

The quarterly review

This is the most useful part of the contract and the one most often missing elsewhere. Once a quarter we review three things: accumulated technical debt, how performance indicators have moved, and improvement opportunities visible in usage data.

The aim is to avoid the most common situation in our industry: an application that works, that nobody touches, and that turns out to be beyond saving the day a change becomes necessary.

What you receive

  • Critical security patches applied within 72 hours
  • Defect fixes within the delivered scope
  • Uptime and error monitoring
  • Daily backups tested monthly
  • Improvement hours rolling over for three months
  • Monthly report and quarterly review

Technologies used

  • Laravel 12
  • Dependabot
  • Sentry
  • Grafana
  • GitHub Actions
  • Pest

Frequent questions about this service

Yes, after a two-to-five-day audit that determines whether the codebase can be taken over and at what cost. We decline to commit to an application whose maintainability we cannot vouch for.

Dependency monitoring is automated. A critical vulnerability triggers work within 72 hours, and immediately if it is being actively exploited. You are told what was done and what the result was.

Your project deserves better than a generic quote

Tell us what you want to achieve. We reply with an analysis, a range, and the questions nobody else asked you.

Reply within 4 business hours · No commitment · Your data stays with us