For most two-person startups, self-hosted WordPress has the lowest cash cost over three years. It only has the lowest total cost if one founder can spend a small, steady amount of time each month on updates, backups and security, and does not bill that time at a consultant's rate. WordPress.com Business and managed hosts such as WP Engine or Kinsta cost more in fees but take most of that maintenance work away. The deciding figures are not the hosting fees. They are the renewal price of premium plugins, the cost of an incident, and how much each founder's hour is worth.
TL;DR:
- The technical founder with spare evenings (for example, a developer building a SaaS landing page and blog): self-host on a small VPS or a personal cloud server, because the hosting bill stays small and the maintenance is familiar work.
- The non-technical pair selling a service (for example, two consultants who need a credible site and a contact form): use WordPress.com Business, because a fixed yearly fee costs less than learning server administration.
- The WooCommerce shop with real revenue at stake (for example, a two-person direct-to-consumer brand): use a managed host like Kinsta or WP Engine, because staging, backups and support cost less than one bad outage during a sale.
- The content-heavy startup expecting traffic spikes (for example, a media newsletter that gets shared widely): self-host behind a CDN or pick a managed plan with generous visit limits, because per-visit plan limits are where managed hosting costs rise.
- The bootstrapped team planning to pivot (for example, founders still testing product-market fit): self-host with a lean free plugin stack, because leaving is cheap and nothing is locked into a plan tier.
- The team handling customer data under strict rules (for example, a health or legal tech startup): self-host where you control the hosting location, because data location and access logs matter more than saving admin hours.
The central tradeoff is simple: self-hosting spends your time to save money, and managed WordPress spends money to save your time.
Table of contents
- How much does WordPress really cost a two-person startup over 3 years?
- What goes into the total cost beyond the hosting bill
- What does self-hosting WordPress cost in year one, year two and year three?
- How WordPress.com Business pricing and plan limits play out over three years
- What do WP Engine and Kinsta charge once you hit visit and storage limits?
- Premium plugins and themes: the renewal costs that grow each year
- How many hours a month does self-hosted WordPress maintenance actually take?
- Backups, staging and disaster recovery across the three options
- Is self-hosted WordPress secure enough without a managed host's protection?
- What happens to the cost when traffic grows or WooCommerce is added?
- Where to run self-hosted WordPress: VPS, home server or personal cloud server
- Data sovereignty and hosting location for a small WordPress site
- How hard is it to switch between self-hosted and managed WordPress later?
- Which option fits your startup: recommendations by profile
How much does WordPress really cost a two-person startup over 3 years?
WordPress itself costs nothing. The software is released under the GPLv2 licence, and you can download it from wordpress.org free of charge. The real cost is everything around it, and over 36 months those extra costs add up to far more than the first invoice suggests.
A fair comparison needs three kinds of cost. Cash is what goes on the card: hosting, domains, premium plugins and backup storage. Time is the hours a founder spends on updates, fixing things and restores. Risk is the expected cost of downtime, a hacked site or lost orders. Pricing pages only show the first kind. For a two-person team, the second and third often decide the answer.
| Option | What the bill covers | What you still handle |
|---|---|---|
| Self-hosted on a VPS | Server, domain, any paid plugins, off-site backup storage | Server updates, WordPress updates, security, backups, restores |
| WordPress.com Business | Hosting, updates, backups, security for the platform | Plugin choices, content, anything a plan limit blocks |
| WP Engine | Managed hosting, staging, backups, support | Plugin licences, overage if you pass the visit limits |
| Kinsta | Managed hosting, staging, backups, CDN, support | Plugin licences, add-ons, moving to a higher tier as you grow |
The pattern is the same across all four. Self-hosting has the smallest fixed bill and the largest time cost. Managed plans reverse that. Over three years, renewals and growth decide which side comes out ahead. Plugin renewals and plan upgrades happen every year, while the time you spend learning to run a server mostly happens in year one.
What goes into the total cost beyond the hosting bill
The hosting bill is the easy part to see. Most of the three-year total sits in smaller costs that only show up once the site is live. Each one is small on its own, but together they are what make a cheap-looking setup expensive.
- Domain renewal: you pay it every year whatever you choose, and some registrars charge far more to renew than they did the first year.
- TLS certificates: Let's Encrypt certificates are free but expire after 90 days, so a self-hosted setup needs automatic renewal that someone checks is working.
-
Transactional email: WordPress sends email through
wp_mail(), which uses PHP mail by default and often lands in spam, so most teams add an SMTP plugin and a sending service such as Amazon SES or Mailgun. - Off-site backups: a backup kept on the same server does not protect you, so you need storage somewhere else, such as Backblaze B2 or an S3 bucket, plus a plugin like UpdraftPlus to send backups there.
- CDN and DNS: Cloudflare's free plan covers many small sites, but image-heavy pages or WooCommerce checkouts can push you towards paid features.
- Uptime monitoring: if nobody is watching, the first person to notice an outage is usually a customer.
- Founder hours: every update, failed restore and plugin conflict costs time, and time is what a two-person team has least of.
Where you run the site changes which of these you manage yourself. A self-managed VPS, a home server and a NAS all leave TLS, networking and backups to you. Yundera is a managed Personal Cloud Server, built on CasaOS, that runs self-hosted apps as Docker containers on a server dedicated to the user. On that kind of setup, public HTTPS access comes with the subdomain, but email, off-site backups and plugin upkeep are still your job.
What does self-hosting WordPress cost in year one, year two and year three?
Self-hosting costs change shape over three years. Year one has most of the learning and setup work. Years two and three are cheaper in time, but plugin renewals and growing storage start to show up on the bill.
| Cost line | Year one | Years two and three |
|---|---|---|
| Server | Small VPS, home server, NAS or a platform such as Yundera, often the smallest size that runs PHP and MySQL | Same size unless traffic or WooCommerce needs more memory |
| Setup time | Heaviest: web server, database, TLS, SMTP, backups, caching | Light: occasional rebuild or migration |
| Software upkeep | WordPress applies minor updates automatically, but a person must test the major releases that come out a few times a year | Same routine, plus PHP 8.x version upgrades that can break older plugins |
| Operating system | Choose an Ubuntu LTS release to get 5 years of standard support | Plan one OS upgrade if you started late in a release's life |
| Premium plugins | First-year prices, often discounted | Full renewal prices on every licence you kept |
| Backup storage | Small, a few snapshots | Grows with each upload and every retained copy |
| Incidents | Most likely, while the setup is still new | Less frequent, but each one takes longer if nobody has practised a restore |
The mistake teams make is judging the whole cost on year one alone. In year one, self-hosting looks expensive in hours and cheap in cash. By year three, you spend far fewer hours, but the cash cost has quietly risen through plugin renewals and storage. That third year is the right number to hold up against a managed plan's renewal price, not the introductory one.
One routine keeps the time cost predictable. Set a fixed monthly maintenance window, put every update through a staging copy first, and run a timed test restore once a quarter.
How WordPress.com Business pricing and plan limits play out over three years
WordPress.com Business is the only WordPress.com plan most startups need to think about, because it is the first plan where you can install your own plugins and themes. That access is what makes it a real alternative to self-hosting. The three-year cost depends less on the price shown on the page and more on how you pay and what the plan does not include.
- Billing term: monthly billing costs the most per month, while annual and multi-year terms cost less per month but require payment upfront. For a startup short on cash, paying for 36 months at once can be a hard call.
- Introductory pricing: the first-term price is often discounted, and renewals charge the standard rate. Build your three-year total on the renewal price, not the checkout price.
- Bundled domain: an annual plan includes a domain registration for the first year only. From year two, you pay the domain renewal separately.
- Developer access: Business includes SFTP, SSH and database access, so a technical founder can still debug problems. You do not get root access to the server, so you cannot install system packages or tune PHP beyond what the platform lets you change.
- Plugins you still pay for: the plan pays for hosting, not for premium plugin licences, so your SEO, forms and membership renewals cost the same as they would on a VPS.
- Store features: a serious WooCommerce shop may push you onto a higher Commerce tier, which moves you into a different price band.
This plan works best as a fixed, predictable cost. It works worst when you need something the platform does not allow. That usually means leaving for Kinsta, WP Engine or a VPS, and paying for the migration on top.
What do WP Engine and Kinsta charge once you hit visit and storage limits?
WP Engine and Kinsta both sell plans in tiers. Each tier sets a limit on sites, visits and storage. The entry price is only an accurate guide to your three-year cost if the site stays inside those limits. Once you go over, you either pay overage fees or move up a tier, and the next tier is usually a big jump rather than a small step.
| Limit | How it raises the bill | What to watch |
|---|---|---|
| Monthly visits | Overage fees on each block of extra visits, or a forced move to a higher tier | Both hosts count unique visitors over a 24-hour window, and bot traffic can count too |
| Storage | Paid add-on or higher tier once media and backups fill the quota | WooCommerce product images and uncompressed uploads grow fastest |
| Bandwidth or CDN usage | Charges or tier changes on plans that measure data transfer | Large downloads, video and podcast files served from the same site |
| Number of sites | A second site, such as a docs or app marketing site, can need a bigger plan | Staging copies usually do not count, but separate production sites do |
| Add-ons | Extra fees for features like extra backups, security add-ons or additional PHP workers | Features you enable once and then forget are billed every month |
For a two-person startup, the danger is a success spike, not steady growth. A launch post that goes viral or a mention in a newsletter can push one month over the visit limit. On a self-hosted server behind Cloudflare, the same spike usually costs nothing extra as long as caching holds.
Before you commit to a year, look at the analytics from your current site. Estimate your visits in year three, including bots, and price the tier you will need then, not the tier you need today.
Premium plugins and themes: the renewal costs that grow each year
Premium plugins are the part of the WordPress budget people forget to check. They cost the same whether you self-host, use WordPress.com Business or pay Kinsta, so the hosting choice does not change this line. What does change is how many plugins you keep adding over three years. Most are sold as yearly licences, and each one renews on its own date.
- Licence expiry is not a shutdown: plugins are GPL, so the code keeps running after the licence lapses, but updates and support stop. Running old code on a public site is a security debt that someone eventually has to pay.
- Renewal versus first-year price: many vendors discount the first year, so your year-two cost for Gravity Forms, WP Rocket or Yoast SEO Premium can be higher than what you paid at checkout.
- Site-count tiers: a single-site licence covers one production site. Adding a second site, such as a documentation site, can force every licence up to the multi-site tier at the same time.
- Page builders and themes: Elementor Pro or a premium theme ties your layouts to that vendor, so dropping the licence later means rebuilding pages instead of simply cancelling.
- WooCommerce extensions: subscriptions, bookings and payment gateway add-ons are often sold separately, and a shop can end up with more of these licences than every other plugin combined.
- Free alternatives: Rank Math or Yoast free, Contact Form 7 and a well-configured server cache cover many needs at no licence cost, as long as you accept less vendor support.
Run wp plugin list once a quarter. For each paid plugin, write down its renewal date and what you would use instead. If nobody on the team can name a reason to keep a plugin, cancel it before it renews.
How many hours a month does self-hosted WordPress maintenance actually take?
Nobody can give you an honest single number, because the hours depend on your setup more than on WordPress. Instead, count the tasks and time each one yourself over your first three months. After that, the monthly total usually settles into a predictable routine with occasional spikes.
-
Core and plugin updates: running
wp core updateandwp plugin update --alltakes minutes. Most of the time goes on testing checkout, forms and login on a staging copy before you push to production. -
Server patching:
apt upgradeand occasional reboots on a VPS, home server or NAS. The OS layer is less of your job on platforms that package WordPress as a Docker container, such as Yundera, although you still update the app itself. -
Backup checks: a backup job that reports success is not proof. Export a test with
wp db export, restore it somewhere else, and time the whole process. -
Security review: look at failed logins, unknown admin users and file changes in
wp-content. Each check is short, but it needs to happen on schedule. - Performance work: clear caches, compress images and look for slow queries when pages get sluggish. This work comes in bursts rather than every month.
- Incident response: a plugin conflict, a full disk or an expired certificate. These are rare but take the longest, and they always happen at a bad time.
To turn hours into money, multiply the monthly hours by the value of a founder's hour. Use the rate that founder could bill clients, or the value of product work they are not doing. Add a buffer for incidents. Compare that figure with the difference between your hosting bill and a managed plan. In a two-person team, one founder usually ends up owning this work, so price it at their rate.
Backups, staging and disaster recovery across the three options
Backups only matter on the day you need to restore one, so compare the three options by what a restore actually involves. For WooCommerce, also ask how many orders you could lose between the last backup and the moment the site broke.
| Recovery need | Self-hosted WordPress | WordPress.com Business, WP Engine, Kinsta |
|---|---|---|
| Daily backups | You set it up yourself with UpdraftPlus, a cron job or server snapshots | Included and automatic, with retention set by the plan |
| Off-site copy | Your job: follow the 3-2-1 rule with at least one copy on separate storage | Stored by the host, and you need an extra export if you want a copy outside the host |
| Staging site | Manual clone of files and database, plus search-and-replace for URLs with wp search-replace
|
One-click staging, then push to live when ready |
| Restore speed | Depends on how often you practise it and how big wp-content/uploads is |
A button in the dashboard, usually quick for small sites |
| WooCommerce orders | A nightly backup can lose a full day of orders on restore | Same risk unless the plan offers more frequent backups |
| Full host failure | You rebuild on another server from your off-site copy | You wait for the provider, or restore elsewhere from your own export |
Managed hosts are better at the everyday cases: you break something with an update and roll back in minutes. Self-hosting can be better at the rare disaster, but only if you have been keeping an independent copy of the database and wp-content. Many managed customers never make that copy, and they discover the gap when an account is suspended or a billing problem locks them out.
Whichever option you choose, keep wp-config.php settings, the latest database export and the uploads folder somewhere your hosting provider cannot reach. Test restoring from it twice a year.
Is self-hosted WordPress secure enough without a managed host's protection?
Yes, if you treat security as a routine rather than a product. Most WordPress compromises come through outdated plugins, weak admin passwords and abandoned themes, not through WordPress core. A managed host reduces some of that risk, but it cannot protect a site that runs a vulnerable plugin you chose to install.
- Plugin auto-updates: since WordPress 5.5 you can switch on auto-updates for each plugin. Turn them on for low-risk plugins and keep manual, tested updates for WooCommerce and payment gateways.
- Admin access: use unique passwords and two-factor authentication through a plugin such as WP 2FA or Wordfence. Keep administrator accounts to the two founders only.
-
Hardening in
wp-config.php: setDISALLOW_FILE_EDITtotrueso a stolen login cannot edit PHP files from the dashboard. Keep the database credentials out of any public repository. -
Attack surface: block
xmlrpc.phpif nothing uses it, rate-limitwp-login.phpwith fail2ban or your firewall, and delete unused themes and plugins instead of just deactivating them. - Edge filtering: Cloudflare in front of the origin hides its IP and absorbs a lot of automated traffic. Its free plan includes basic protections, and managed rulesets need a paid tier.
- Detection: file-integrity scans and alerts when a new admin account appears. Without them, a quiet compromise can sit unnoticed for months.
What managed hosts really add is people and speed. Kinsta and WP Engine run server-level firewalls, patch PHP for you, and some clean up malware if a site is infected. On a self-hosted server, cleanup is your job, and it is the most expensive hour in this whole cost model. Put a realistic incident allowance into your three-year budget rather than assuming it will not happen.
What happens to the cost when traffic grows or WooCommerce is added?
A brochure site with a blog is mostly static pages. A cache can serve those pages without running PHP, so extra traffic costs very little. WooCommerce changes that, because carts, checkouts and account pages are different for every visitor and cannot be served from a shared page cache.
-
Uncacheable pages:
/cart/,/checkout/and/my-account/run PHP and query the database for every visitor. On a VPS that means more memory. On Kinsta or WP Engine it can mean more PHP workers or a higher tier. - Object caching: Redis cuts repeated database queries on dynamic pages. Self-hosted, it is one more service to run and keep an eye on. On managed plans, it is sometimes a paid add-on.
-
Order storage: WooCommerce 8.2 made High-Performance Order Storage the default for new stores. Older stores that still keep orders in
wp_postsshould migrate before order volume makes the database slow. -
Scheduled tasks: the default
wp-crononly runs when someone visits the site, which is unreliable for subscription renewals. SetDISABLE_WP_CRONand callwp cron event run --due-nowfrom a real system cron instead. - Payment compliance: hosted payment fields from Stripe or PayPal keep card data off your server and usually put you in the simplest PCI DSS questionnaire, SAQ A. Collecting card numbers yourself makes compliance far more work.
- Extension licences: shipping, tax and subscription plugins add renewal lines, often several at once.
The pattern over three years is clear. Traffic growth by itself barely moves a self-hosted budget, but it pushes managed plans up through visit limits. Adding WooCommerce raises the cost on both sides. For a store, the cost of downtime now includes lost sales, which makes paying for managed support easier to justify.
Where to run self-hosted WordPress: VPS, home server or personal cloud server
Once you decide to self-host, the next choice is where the server lives. That choice decides how much of the stack you manage below WordPress itself. It is the second-largest time factor after your plugin list.
| Option | What you manage | Main tradeoff |
|---|---|---|
| VPS (Hetzner, DigitalOcean, OVHcloud) | OS, web server, PHP, database, TLS, firewall, backups | Full control and a public IP, but every layer of the stack is your job |
| Home server | Hardware, OS, networking, power, plus everything a VPS needs | Hardware you already own, but CGNAT, blocked ports 80 and 443, and slow home upload speeds can rule it out |
| NAS (Synology, QNAP) | Container or package setup, router forwarding, DNS, TLS | Convenient if you already own one, but a public store on the same box as company files mixes risks |
| Managed personal cloud server | WordPress, plugins, content, off-site backups | Dedicated server with one-click app installs and HTTPS handled, less control over the underlying system |
| Shared hosting | WordPress and plugins only | Low effort, but noisy neighbours and limited PHP settings |
For the first four options, running WordPress in containers is the most portable approach. The official wordpress Docker image plus a mariadb container, with wp-content and the database on named volumes, can be moved between a VPS, a NAS and a dedicated server without reinstalling anything.
Pick based on who owns the pager. If one founder is comfortable with Linux, a VPS is the most flexible choice. If neither wants to manage networking and certificates, choose an option that handles those layers. Otherwise, the hours you save on hosting fees will go into troubleshooting DNS and TLS. A home server works for staging but is a risky place for a store that needs to stay online.
Data sovereignty and hosting location for a small WordPress site
Even a small WordPress site handles personal data: contact form entries, comment IP addresses in wp_comments, newsletter signups and, with WooCommerce, full names and addresses on every order. If you serve customers in the EU, the GDPR requires you to know where that data is stored and who can access it.
Advantages of controlling the hosting location:
- Known jurisdiction: you choose the country the server runs in, instead of reading it from a provider's list of subprocessors.
- Shorter processor chain: fewer companies to cover with a data processing agreement under GDPR Article 28.
- Direct access to logs: web server and database logs stay under your control, and you can hand them over during an audit or a breach investigation.
-
Exit without permission: a full copy of the database and
wp-contentis always yours, whatever happens to a billing account.
Checklist before you pick a host:
- Region choice: Kinsta and WP Engine let you choose a data centre region on their cloud providers. Check whether your WordPress.com plan gives you any say over location.
- Third-party calls: Gravatar, remotely loaded Google Fonts and embedded analytics send visitor data elsewhere. A Munich court fined a site owner in 2022 for loading Google Fonts remotely, so host fonts locally.
- Email path: order and form emails go through your SMTP provider, which becomes a processor too.
- Backup location: an off-site bucket in another country moves the data just as much as the server does.
- Retention: delete old form entries and inactive customer accounts on a schedule rather than keeping them forever.
Self-hosting does not make you compliant on its own. What it gives you is a shorter, clearer list of places your data goes, and a short list is easier to audit.
How hard is it to switch between self-hosted and managed WordPress later?
It is easier than with most platforms, because WordPress is the same software everywhere. A site is a database plus a wp-content folder, and a migration moves both. The difficulty comes from what each host adds on top of WordPress and from anything the site does while the move is in progress.
- Migration tools: Duplicator, All-in-One WP Migration and Migrate Guru package the site into one archive. WP Engine and Kinsta also offer their own migration tools or assisted moves, which lowers the cost of moving onto them.
-
URLs and serialized data: if the domain or path changes, use
wp search-replacerather than raw SQL. It handles serialized PHP arrays that a plain find-and-replace would corrupt. -
Host-specific code: managed hosts add their own must-use plugins and caching layers in
wp-content/mu-plugins. Remove them after moving out, or they will fail silently or conflict with your own cache. - DNS cutover: lower the DNS record TTL to 300 seconds a day before the move, so visitors reach the new server within minutes instead of hours.
- WooCommerce orders: orders placed on the old server after the export are lost. Schedule a short maintenance window or freeze checkout during the final sync.
-
Email and integrations: SPF and DKIM records, payment webhooks and API keys stored in
wp-config.phpall need checking on the new host.
For a two-person startup, this means the first hosting decision is not permanent. A site with a few plugins can move in an afternoon. A store with years of orders and many extensions needs a staged rehearsal. The practical lesson for your three-year budget: avoid host-only features you cannot rebuild elsewhere, and leaving stays cheap.
Which option fits your startup: recommendations by profile
Use your team's skills, your revenue risk and your expected growth to choose. The hosting price alone should not decide it.
| Profile | Recommendation | Main reason |
|---|---|---|
| Developer founder, marketing site and blog | Self-host on a VPS | Low cash cost, and the upkeep uses skills the founder already has |
| Two non-technical founders, service business | WordPress.com Business | Fixed yearly cost, no server work |
| WooCommerce store with daily orders | Kinsta or WP Engine | Staging, backups and support are worth more than one outage |
| Content site expecting viral spikes | Self-host behind Cloudflare | Traffic spikes do not trigger visit overages |
| EU startup collecting customer data | Self-host in a region you choose | A shorter list of data processors, and logs you control |
| Pre-product-market-fit team likely to pivot | Self-host with free plugins only | No yearly commitments to cancel |
| Agency-style team running several client sites | Managed multi-site plan | One dashboard and support contract across every site |
Next steps:
If you self-host:
- Deploy the
wordpressandmariadbcontainers with named volumes. - Set up off-site backups and test one restore before launch.
- Put a fixed monthly maintenance window in both founders' calendars.
If you choose WordPress.com Business:
- Price the three-year total using renewal rates, not the introductory price.
- Check that every plugin you need is allowed on the plan.
- Schedule a regular full export stored outside WordPress.com.
If you choose Kinsta or WP Engine:
- Estimate year-three visits, including bots, and pick that tier.
- List every add-on and its monthly price.
- Keep your own off-site copy of the database and
wp-content.
Top comments (0)