Maintenance and quality · Drupal 10, 11 and 12

Drupal maintenance for agencies

If maintenance always gets pushed to later and every delivery ships with the fear of breaking something, this is for you. A service built above all for agencies that deliver Drupal projects, though you can also hire me directly as an end client.

I am the Drupal technical partner your agency leans on: tests, code analysis, performance, security and configuration, worked on every month so no delivery breaks anything. Everything goes through Git, your team reviews and deploys, and the relationship with your client stays yours.

A flat 1.790 €/mo fee per project, no meetings and no hours to burn through.

The problems this takes off your plate

Every delivery is a small risk: a security patch not yet applied, a change that breaks something in production, an end client who finds out before you do. And the technical debt keeps growing, because there is never a spare hour for maintenance.

This service exists so your agency stops carrying all of that. For a closed fee of 1.790 €/mo I become your Drupal technical partner: updates on time, tests that warn before anything breaks in production, clean code and a continuous audit watching the whole project. You keep delivering; I make sure nothing breaks.

Your side of the deal is close to zero: access to the Git repository and a copy of the database. No meetings, no hour bags, no lock-in: if one month it stops paying off, you leave.

  • Updating Drupal core and contributed modules
  • Patches that break
  • Drupal security advisories
  • Spaghetti code
  • Deprecated code
  • Drupal running slow
  • PHPStan and PHPCS warnings
  • Afraid to touch the code
  • No PHPUnit tests
  • Composer errors
  • Form spam
  • Technical debt
  • Layouts without reusable components
  • Drupal caching problems

How it works

You hand me access

The Git repository and an up-to-date copy of the database. That is everything I need from you.

The first week

Your project running in my environment, DruScan connected with its first audit, and the three E2E tests written.

Every month

A batch of work lands on branches of your repository: updates, tests, clean-up and configuration. Your team reviews and merges whenever it suits.

Month to month

No lock-in: you stay only while the service pays off. To leave, one month of notice.

What this would cost done by hand

Do it by hand and it is easily some ten working days a month of a senior developer: updates, tests, code analysis, performance and configuration, plus the context switching between them. At 50 € an hour and up, that is around 4.000 € a month, and with more senior profiles the figure climbs well past it.

The fee stays under half of that and not by cutting corners: the how is right below. And one rule that never changes: nothing is merged into any branch without my review first.

Price comparison

Hours a month of a senior developer 80 h
Their minimum hourly rate 50 €/h
What that senior developer costs 4.000 €/mo
My monthly plan 1.790 €/mo
What you save 2.210 €/mo

Your alternatives, one by one

Hiring a senior in-house

From 4.000 € a month, if one turns up: it is a scarce profile that takes months to find.

A bag of consulting hours

Every topic is a new estimate and the hours run out right when you need them most. Unpredictable by design.

Doing nothing

The most common option: technical debt and security risk grow on their own, and the fix gets more expensive the later it comes.

This plan

A closed price, no lock-in, and your team reviewing every delivery. Your side of the effort is close to zero.

How can it cost less than half?

No magic and no half-done work. Two design decisions of the service.

Automation with my own AI

An important part of the work is done by my own AI agents and skills, built for these exact tasks. I know which model I use for each thing and what it costs: local servers make the simple tasks cheaper, and for the complex ones I use the best paid APIs, which pay for themselves: with a better result on the first try, I review the same file fewer times and save human review time.

Zero time thieves

Email works as a notice system: notifications of what is being done and a summary of every delivery. It is not a chat or a WhatsApp, not an I-reply-you-reply game that eats the hours. Meetings and email management almost disappear, and the time not spent on tasks that add nothing is cost I take off the price.

Do not take my word for it: hire one single month. There is no lock-in: check what the audit finds on your site and what gets solved in that first month, and decide with that.

What comes as a gift

The plan includes pieces that carry a real price tag of their own. I throw them in at no cost.

DruScan Business plan The control panel an agency actually needs: every Drupal project you run, at a glance.
  • The score of every environment of every project, compared side by side.
  • See whether a project improves or worsens, across environments and over time.
  • The history proves that the tasks resolved genuinely raise the score.
  • Automatic alerts the moment something starts to slip.
  • The list of the modules you have installed, with their versions.
399 €/yr Included
Playwright set-up and three E2E tests Playwright installed and configured on your project, and three end-to-end (E2E) tests written during the first month. An E2E test simulates a person browsing in a real browser and checks a complete user flow, such as signing in or running a search: if a change breaks that journey, you find out before it reaches production. 500 € At no cost
Your project set up in my environment Repository, database and configuration running on my infrastructure during the first days of the service. Real hours of work I do not charge for: I need it in place to deliver the service. At no cost

Build your plan

Every line below is part of the service. Click any of them to see its description and what it includes, and switch on or off the parts that add to the price: that is how you build your made-to-measure plan, with the total breakdown updating as you go.

Monthly recurring cost

One-off extras

Total breakdown

Monthly recurring cost 1.790 €/mo + VAT
One-off extras 0 € + VAT
Total: monthly + one-off 1.790 € + VAT

About your project

These answers do not change the price of what you have configured. They tell me whether it fits your project as it is, or whether the proposal should suggest an adjustment. All of them are required.

This is the one way I work: everything goes through Git and every delivery is a branch. If your project does not use it yet, setting it up is the first thing we do.
Environments of your own*
Tick every one you have.

Contact details

Sending this request commits you to nothing: within two working days at most, the closed proposal reaches you in writing, with the scope spelled out. Prices are quoted without VAT, and the fee is month to month, with no lock-in.

Frequently asked questions

The fine print, in plain words: everything here is already reflected in the price above.

How long until my project is fully up to date?
Almost never within the first month: the fee buys a batch of work every month, month after month. The more custom code and configuration your site carries, the more findings will turn up and the more months it takes to get everything up to date. A big project does not pay more each month: it pays more months. And when you want to shorten that road, that is exactly what the acceleration sprints are for.
What does my team have to do to get this running?
You hand me access to the Git repository and an up-to-date copy of the database, and that is it: I do the work and push it to a branch, and your team reviews it and merges whenever it suits them. You delegate it and stop thinking about it.
What is DruScan's continuous audit based on?
DruScan builds on Audit, a module I wrote and contributed to the Drupal community, free and open source: it audits the project and scores it. DruScan is the layer that turns those scores into history, alerts and a screen you can read without being a developer.
What exactly does the audit check?
It runs 24 audits and scores each area from 0 to 100: pending updates and security advisories, permissions and exposed accounts, caching at every level, database size, errors in the logs, fields and views set up wrong, technical SEO, images, multilingual and code quality with PHPStan, PHPCS and the automated tests. One detail that matters: the analysis runs on your server, and the only things sent to DruScan are the scores and the list of module versions. Your code, your content and your users never leave home. And there is no monthly report to wait for either: you see the same live panel I see.
Is there a lock-in or a minimum commitment?
No. It is a monthly fee you can walk away from whenever you want: the only ask is one month of notice, not a few days. I can afford that because the set-up is time I put in without billing it, and I only earn it back if you stay. So the pressure is on me, every single month: the service has to keep being worth more than it costs, or you leave.
How does billing work?
Billing is monthly and always in advance, before any work starts: I only work on months already paid. I am a freelance working alone, and charging in advance is what lets me spend my time on the projects instead of chasing payment for work already delivered. The set-up on my infrastructure comes included, at no separate cost. One-off extras, such as the sprints, go on their own invoice, separate from the fee, and can be booked whenever you need them. All prices are quoted without VAT. And everything is per project: an agency with several projects takes one plan for each.
Does the fee cover jumping to the next major Drupal version?
The fee covers the minor versions of the branch you are on: every 10.x if you run Drupal 10, every 11.x if you run Drupal 11. Jumping from 10 to 11, or from 11 to 12, is a different job, a major-version migration: the upgrade needs contrib compatibility checks, deprecated code replaced and many more tests, so it is quoted separately, at a closed price agreed before anything starts.
Do the tests guarantee an update will not break anything?
On every round I run the tests the project already has, and the more there are, the easier the two of us rest. But let me say it plainly: most projects arrive with very little coverage, and the tests cover the code written for you, not the community modules themselves. Updating twenty contrib modules at once is something no amount of tests can certify as risk-free. Which is why the branch reaches you for review, why the test coverage the plan includes is worth what it costs, and why on very large portals, where stability weighs more than running the latest of everything, it makes perfect sense to take only the security updates and, every few months, run a full round to bring the rest up to date.
Does anything reach production automatically?
Not from the update pipeline, not from any other tool in the process. The branch arrives reviewed and with the project tests run, but a human always presses the button.
Who runs the tests, and where?
Every test, PHPUnit and Playwright alike, I write and run on my own machine before delivering, so nothing broken reaches you. They all live in your repository, and anybody on your team can run them locally, on any branch. Continuous integration and scheduled runs on your own server are your team's to set up: on infrastructure of mine, nothing runs automatically.
Why does working without external AI models cost extra?
Part of my work leans on AI agents. When a project demands that not one line of code reaches an external model, for a strict NDA or a public-sector client, there is an option that keeps the analysis on models hosted on my own infrastructure, and it carries an extra monthly cost. The difference is not the hardware, it is the models. The powerful external ones, such as those from Anthropic or OpenAI, require sending data their way, but in exchange they are very capable: they leave the code in an acceptable state within few iterations before my review. The ones I can host locally are more limited and make more mistakes, and that with an infrastructure that is not small: we are talking several thousand euros invested. With them my human review needs more passes and more time on every task to guarantee the same quality. Running them costs me less than paying the external APIs, but that saving does not cover my extra hours, and that time is what shows up in the price.
Will one sprint leave my project fully fixed?
In each sprint I get through as much as two weeks allow, always starting with what matters most. How far that reaches depends on how much custom code the project carries and on the state it is in: on a small site it can mean clearing the whole list, and a big one takes several sprints. Whatever is left keeps moving through the monthly plan, and you can always book another one later.

A flat monthly fee per project, no surprises

The base plan is a monthly Drupal maintenance and support subscription, per project, that covers the five areas every Drupal project needs looked after, for one closed price. If your agency runs several projects, each one gets its own plan. It is the alternative to hour-based Drupal consulting: instead of paying a Drupal consultant to find and fix problems, the fee covers my autonomous work, reviewing the project and fixing what I find as I go, with no on-demand requests. And it works the way maintenance works: recurring monthly effort, detecting and fixing another batch of each area every month, so the technical debt shrinks little by little and the project then stays up to date. From there you only add what your project actually needs: the update rhythm, and the extras.

Everything the monthly plan includes
  • Unit and kernel tests: they check on their own that each change breaks nothing.
  • PHPStan and PHPCS: clean code, cheaper to maintain.
  • Performance and frontend: a faster site on less server.
  • Site configuration: permissions, caching, security and settings kept in check.
  • Three Playwright E2E tests to start, walking your site the way a real user would. Plus the upkeep of every test.
  • The DruScan Business dashboard and the set-up, at no extra cost.
1.790 €/mo

DruScan, continuous audit of your project

DruScan.com is a web service I built and run myself. You connect your Drupal site to it and it audits it over and over: security, pending updates, configuration, performance and code quality, all turned into a score you can follow over time. It is a paid product, 399 € a year on the Business plan, and because it is mine I include that plan at no cost for as long as we work together. I need the panel to decide what is worth doing on your project, so it makes no sense to charge you for it on top.

DruScan Business plan
  • Environment comparison: the scores of development, testing and production, side by side.
  • Automatic alerts the moment something starts to slip.
  • Ninety days of score history, to see whether the project is getting better or worse.
  • The list of the modules you have installed, with their versions.
399 €/yr Included

Getting set up

Before anything else I need your project running in my own environment: repository, database, configuration. It happens during the first days of the service, it is real work, and I do not charge for it: it is included at no cost.

Your project set up in my environment
  • Your repository cloned and the site running on my machine.
  • Your configuration reproduced, working from a sanitised copy of the database: if you cannot sanitise it yourselves, I do it before installing anything.
  • DruScan connected and the first audit run, so there is a baseline to compare against.
  • The way we work agreed in writing: branches on your repository, changelog, and who approves what before it goes live.
At no cost

Core and contrib updates

What you get is one less worry: a security advisory never catches the site unpatched, and updating stops being the task nobody finds time for. If you leave this part to me, I update Drupal and the community modules on a recurring basis, via Composer, at the pace you choose. Drupal publishes its new versions on Wednesdays, so I work to that release calendar. Each round goes on a branch of your own repository (update/YYYY-WW): I run the automated tests and send you a summary of what changes and what risk each item carries. You review it and decide when it goes live.

Frequency

Drupal core publishes its bug fixes on the first Wednesday of the month and its security advisories on the third, and I prepare the branch against that calendar. The community modules follow their own: new versions, security ones or not, can land any week. That is what a weekly cycle picks up as it comes and a monthly one lets pile up. If your own team already does the updating, leave them out and this section costs nothing; if I do them, the rhythm you pick is added to the monthly fee.

Frequency

What gets updated

This decision is separate from the frequency and does not change the price. My recommendation is to update everything: nothing piles up and each round stays small. On very large portals, with a great many community modules and where stability weighs more than running the latest version, it can make more sense to take only the security ones and ask for a full catch-up every so often.

What gets updated

Supervised deployments

Every push of code to production is a deployment: a round of updates, a fix I have made, or any change that needs publishing. Here you decide who runs them. If your team already deploys, this section costs nothing: I hand over the branch and they ship it as always. If you prefer to leave it to me, I connect to the server and run it supervised from start to finish, at 100 € per deployment, whatever kind it is. It is the option meant for the end client with no technical team, and for the agency that prefers that I deploy what I built myself.

Who pushes it to production

Who pushes it to production

How many deployments a month

An approximation, so the total below means something: deployments are billed apart from the fixed monthly fee, one by one, as they actually happen.

How many deployments a month

Automated code tests (unit and kernel)

Automated tests re-check the whole project in minutes, every time somebody touches the code. Without them, the way you find out that a change broke something is a user hitting it in production. These tests cover the logic built specifically for your project, not what Drupal already ships, and they report before the branch goes out. In technical terms they are unit and kernel tests written with PHPUnit, the Drupal standard: the unit ones check one piece of logic on its own, and the kernel ones check that same piece running against a real Drupal, with its database, its configuration and the modules it depends on. And one note that I think matters: now that so much code is written or reviewed with AI, these tests are the only thing that separates 'it works' from 'it does not crash'.

Monthly coverage

Progressive coverage, included in the monthly plan Every month another slice of the custom code gets covered, starting with whatever gets touched most, up to the minimum coverage we agree on together. Anything new that lands ships with its own tests, so the figure keeps climbing instead of decaying. Included in the monthly plan

User interface tests (Playwright)

These tests open a real browser and use your site the way a person would. Each test replays one complete journey, step by step. On a shop, for example: open a product, add it to the basket, change the quantity at the checkout, fill in the form, place the order — and then check in the admin panel that the order really got created. On a content site: open the search from the home page, type a word, check the right page shows up among the first results, go into it, and check its image opens large in a modal, with its alternative text in place. The idea is always the same: the journeys your site cannot afford to break get walked automatically after every code change, configuration change or update, before any of it reaches production. They are end-to-end (E2E) tests, written with Playwright: I do not work with Cypress or Behat.

What the monthly plan already covers

Three tests at no cost, and the upkeep of all of them The first time you take out the monthly plan I write three tests at no cost: the home page loading what it should, the login working, and a third one that matters to your project, such as the search finding what it must. Only that first time; any test beyond those three is hired in the one-off batches. The monthly plan also maintains every test, mine or not, old or new: when an update or a code change makes one fail, fixing it or adapting it so it goes back to green is part of the fee. Included in the monthly plan

Static analysis: PHPStan and PHPCS

PHPStan reads the code without running it and finds faulty PHP that would otherwise only surface in production: a call to something that no longer exists, a value arriving empty where nothing expects it. PHPCS checks that the code is written in one single style, the one the Drupal community agreed on. It sounds cosmetic and it is not: code that follows the standard is code any developer can pick up, review and change without deciphering it first, and that is exactly what makes a project cheap or expensive to maintain. Tools like SonarQube measure much of this same ground, so it is also what shows up in a technical audit. I run both on my machine on every change I make, and your team can run them too or wire them into its own pipeline. The work is getting the project clean the first time and keeping it that way.

Monthly clean-up

Progressive clean-up, included in the monthly plan Every month I clear a batch of the pending findings, and whatever new code lands in the repository I keep clean from the start so the backlog does not grow back. Included in the monthly plan

Performance and frontend good practice

Your custom code is reviewed, back end and front end, for what makes the site slow, what hurts your Core Web Vitals, and what will make it expensive to maintain: queries repeated hundreds of times on a single page, cache metadata that hands one visitor another visitor's content, Twig templates that break invalidation, CSS and JavaScript loaded on every page to be used on one. Whatever turns up gets fixed, in small, reviewable deliveries, one topic at a time.

Monthly work

Progressive work, included in the monthly plan I work through the findings in order of what costs the site most, and I review the code landing in the meantime with the same criteria so nothing is added to the pile. Included in the monthly plan

Site configuration

I review the site configuration, the part that is not custom code but still costs security and performance when it is set up wrong: multilingual set up badly, caching implemented wrong both on pages and on each view, views with so many relationships that their queries turn slow, Pathauto URL patterns and modules that should not be enabled in production. I also clean up: modules that sit disabled in the codebase and can simply be removed. All of it gets measured and fixed batch by batch, and every adjustment leaves the project safer, faster and easier to maintain.

Monthly fixes

Progressive fixes, included in the monthly plan What the panel reports gets corrected batch by batch, worst first, and settings that change along the way are checked with the same criteria. Every change arrives as a reviewable delivery or as exported configuration, never as a direct touch in production. Included in the monthly plan

Confidentiality and use of AI

Part of my work leans on AI, but not on generic AI: on my own agents and skills, built and tuned for this exact workflow, which read code, spot patterns and draft a first version that reaches a quality hard to match otherwise. I always review that work by hand, and nothing is merged into a branch without that review. Here you only decide where the underlying models run: it is the one decision on this page that puts your code in front of a third party. Everything else stays with me: I work on my own machine, always from a sanitised copy of the database, so I never handle the real names or email addresses of your users.

Confidentiality and use of AI

Acceleration sprints

The sprints are one-off payments that speed one specific area up, instead of waiting months while the monthly plan works through it bit by bit. They are also how you set priorities: if you want every possible test in place before I even look at PHPCS, you book the coverage sprint and that area jumps the queue. They can be booked at the start or at any point of the service. Each one is two weeks of calendar, not two weeks of exclusive dedication, worked with the same agents and the same review as everything else, and that is why they can carry a closed price instead of a consulting estimate by the hour.

Unit and kernel tests

PHPStan and PHPCS

Performance and frontend

Site configuration

More UI tests (Playwright)

These are the same Playwright tests from the user interface part: journeys checked in a real browser. The monthly plan includes three of them, written once, when you first sign up, not three new ones every month. From there the plan keeps every test alive, and any journey beyond those three is developed as a one-off batch: the bigger the batch, the cheaper each test, because the set-up work is shared.

More UI tests (Playwright)