codexier.

Maintenance & Security

Why Software Needs Updating Even When Nothing Changes

By CodexierPublished 4 min read

A common question from owners: the website or app works, we have not asked for any changes, so why is there a maintenance bill? The honest answer is that software does not stand still just because you do. It runs on top of libraries, servers, browsers, phone operating systems and other companies' APIs, and all of those keep changing. This guide explains the mechanism, so upkeep budgets make sense.

Software rots even when untouched

Engineers call it software rot, although nothing in the code decays. What happens is that the environment around it shifts. In a modern website or app, your own code is often the smaller part; the rest is open-source libraries, frameworks and services, each with its own release cycle. When those move forward and your project does not, the gap grows every month. Eventually something breaks, or a security update you urgently need is only available for a version several steps ahead of yours.

Dependencies and security advisories

Every library your project uses can have vulnerabilities, and new ones are published continuously in public databases. Attackers use the same lists and scan the internet for sites and apps running the vulnerable versions. The fix is almost always a new version of the library; the question is whether your project can take it.

  • Automatic tools, such as GitHub's Dependabot or npm audit, show which dependencies have known problems.
  • Most fixes are minor updates that can be applied quickly if the project is kept current.
  • Frameworks and languages have end-of-life dates; after them, no security fixes are published at all. PHP versions and old Node.js releases are common examples.
  • WordPress plugins are dependencies too, and among the most common entry points for attacks.

What happens when this is ignored for years is covered in risks of running an old website.

Browser, OS and API changes

What changesTypical effect on you
Browsers update every few weeksOld code paths stop working; cookie and privacy rules tighten
iOS and Android release yearlyApps must target new versions to stay in the stores; permissions change
App store requirementsDeadlines to update SDKs and privacy declarations, or updates are blocked
Third-party APIs (payments, maps, login)Old API versions are retired on announced dates
Hosting platformsRuntime versions are retired; builds fail until upgraded
Laws and standardsNew requirements, such as accessibility or consent rules

None of these are optional: they are changes other parties make on their own schedule, and your software must follow.

Small regular updates vs big jumps

Updating one version at a time is routine: read the change notes, update, run the tests, check the key pages, release. Jumping four major versions at once means several sets of breaking changes on top of each other, dependencies that no longer fit together, and sometimes a framework that has been replaced entirely. The cost does not grow in a straight line; it jumps.

  1. Monthly: security patches and minor updates.
  2. Quarterly: review of dependencies with major new versions, and a plan for them.
  3. Yearly: runtime and framework versions against their end-of-life dates, plus app store requirements.
  4. Always: a backup and a way to roll back before any update goes live.

Budgeting for upkeep

Treat upkeep as a running cost, like insurance or hosting, and decide it when the project is built. A fixed monthly plan makes cost predictable and means someone is responsible. Doing it ad hoc can work for a simple site if someone reliably does it; the risk is that it is forgotten until something breaks.

When you do not need a plan: a static website with no plugins, no forms and no backend can go months without attention. For apps, we offer app maintenance and scaling; for websites, a monthly maintenance package. If you are unsure what your project needs, book a short call and we will look at its dependencies with you.

Frequently asked questions

Can we just update when something breaks?

You can, but it means updating under pressure, often across several versions at once, and security problems do not announce themselves by breaking anything. Regular updates are cheaper overall.

How often should a website be updated?

Security patches as soon as they are published, minor updates monthly and major versions planned a few times a year. WordPress sites need more frequent attention than static sites.

Why does an app need updates if we do not add features?

Apple and Google require apps to target recent operating system versions and SDKs. Apps that fall behind can be hidden from new users or blocked from publishing updates.

What does it cost to skip maintenance for years?

Often a partial or full rebuild, because the gap has become too large to bridge with updates. The cost depends on the project, but it is usually much higher than the maintenance it replaced.

Not sure how far behind your software is?

Bring access to your code repository or tell us what your site runs on. On a short call we will tell you how outdated it is and what keeping it current would take.

Book a free 15-minute call