Maintaining a Shopify or Next.js Site: What It Actually Takes
What Shopify handles for you, what you need to have looked after, and how often. With a checklist for your Shopify store or headless Next.js site.
TL;DR: Shopify takes care of servers, platform security and payments. Everything you add on top needs looking after: your theme, apps, integrations and, on a headless site, the whole store your customers see. That's manageable once you know where things break and it happens on a regular schedule.
A store is never really finished. Every quarter Shopify changes something about how integrations work, the software under your site gets security updates, apps pile up, and every campaign adds pages and scripts. None of it breaks all at once. It breaks slowly: stock levels that suddenly no longer match your warehouse, a product page that gets a bit slower every month, a pop-up that stops some of your customers from checking out.
Below is what needs to happen on a Shopify store and on a headless Next.js site, why, and how often. And what you can do yourself versus what's better left to your developer.
What maintenance covers
Maintenance is everything that happens after launch to keep your site working as intended. It comes down to five kinds of work:
- Security: installing updates for the software your site runs on.
- Compatibility: making sure updates to Shopify, apps and other systems don't break anything.
- Speed: keeping your site fast as content and scripts pile up.
- Fixes: repairing bugs, broken forms and failed integrations.
- Small improvements: a new content block, a change to the checkout flow.
Day-to-day work on content and products isn't part of this. Your own team usually handles that, in Shopify or in the CMS.
What Shopify does for you, and what it doesn't
A standard Shopify store runs entirely on Shopify's platform. On a headless site, the store your customers see is a separate app, for example built with Next.js, that gets its products from Shopify and its content from a CMS such as DatoCMS. That gives you more freedom in design and speed, but also more to look after:
| Who handles what? | Standard Shopify | Headless (Next.js + Shopify + CMS) |
|---|---|---|
| Servers and hosting | Shopify | Hosting platform (e.g. Vercel) and your developer |
| Platform updates | Shopify, automatically | Shopify and the CMS vendor, automatically |
| Payments and checkout security | Shopify (PCI DSS Level 1) | Shopify |
| The store your customers see | Your theme, kept up by you or your developer | The Next.js site, kept up by your developer |
| Extra features | Apps | Custom code and third-party building blocks |
| Integrations with other systems | Your developer or the app vendor | Your developer |
| Speed | Apps, theme code, images and other media | Caching, images and other media |
In short: with Shopify you don't have to think about servers. You do have to think about your theme, apps and integrations.
Maintaining a Shopify store
Theme updates
If you use a theme from the Shopify Theme Store, updates come out now and then. Shopify adds the new version as a copy in your theme library. Your live store stays as it is until you publish the new version yourself. If someone has edited your theme's code, Shopify tries to carry those edits over. If it can't, you get a notice and they have to be moved across by hand. The more your theme has been changed, the more often that happens (Shopify Help Center).
Two habits that save a lot of trouble:
- Always preview the new version first. Click through a product page, the cart and the checkout before you publish.
- Ask your developer to keep track of what was changed in the theme and why. Without that overview, nobody knows what got lost in the next update.
A custom theme gets no updates from a theme vendor. Nothing changes without you knowing, but your developer does have to keep it up to date.
Integrations with other systems
Is your store connected to an ERP, warehouse system, POS or accounting software? Then that integration talks to Shopify through an API: a fixed agreement on how systems exchange data. Shopify releases a new version of that agreement every quarter and supports each version for at least 12 months (Shopify.dev).
If an integration is never updated, it doesn't break loudly after that. Shopify quietly switches it to a newer version. Data can then come in slightly differently than the integration expects. You find out when orders stop coming through properly or your stock levels are off.
You don't need to track this yourself. Do ask your developer or app vendor whether they do, and when the next update of your integrations is planned.
Apps
Every app you install can add scripts, widgets and code to your store. Newer apps clean that up when you remove them. Older apps often leave code behind in your theme, even long after you stopped paying for them.
That's why it pays to review your apps regularly:
- Do you still use the app, and does it do something your theme or Shopify can now do on its own?
- Did a removed app leave code behind? Your developer can check that in a few minutes.
- Has a key page got slower since you installed a new app?
A slow store costs sales, and Google pays attention to speed too. It uses three numbers for this, the Core Web Vitals:
- LCP: how quickly the main part of the page is on screen.
- INP: how quickly the page responds when someone clicks or types.
- CLS: how much the page shifts around while it loads.
Google bases these numbers on real visitors. You can find them yourself in Google Search Console. A Lighthouse test, which you often see in reports, is a snapshot on one device. It's useful for tracking down a problem, but Google looks at the numbers from real visitors.
Maintaining a headless Next.js site
A headless site is fully custom. That gives you more freedom, but it also means your developer has more to look after. The most important part is keeping the software the site runs on up to date.
December 2025 showed why that matters. A serious security hole was found in software that Next.js 15 and 16, among others, run on (CVE-2025-55182, known as "React2Shell"). Hosting platform Vercel told everyone to update right away, even sites that already had extra protection. Nobody could have prevented this when the site was built. The only thing that mattered: was there someone who knew the site and could ship the update the same day?
What to look for in your developer:
- Small, regular updates. A site that gets a little maintenance every month can be made safe within an hour when a security hole appears. A site that has sat still for two years first needs a big catch-up. That takes days instead of hours.
- A test version of every update. On Vercel, every change gets its own test link. You can click through the checkout flow there yourself before the update goes live.
- Speed under load. When I rebuilt the Milkshake Festival site in Next.js and DatoCMS, I made sure it holds up during traffic peaks. The old site threw errors at exactly those moments (see the case).
- Publishing on your own. Check now and then that your team can still preview and publish pages on their own. That sometimes breaks quietly after an update.
Maintenance for every site
Accessibility
Since June 2025 the European Accessibility Act applies to webshops of companies with 10 or more employees or more than €2 million annual turnover. In March 2026 the Dutch regulator ACM tested about 100 of the largest Dutch webshops, plus telecom and energy sites. On 61% of them, people who rely on assistive tools could not place an order at all (ACM, in Dutch; NL Times).
Accessibility isn't a one-off job. Every new campaign page, pop-up or app can break it again. A test you can do yourself: place an order using only your keyboard. If you can get through the cart and checkout without a mouse, you're already ahead of many stores.
Privacy and cookies
New tracking pixels, apps and marketing tools often set cookies or pass on data before a visitor has given consent. After adding any new tool, have someone check that your cookie banner still does what it promises.
Monitoring
Have your developer set up monitoring that raises the alarm when your site is down, errors occur or the checkout stops working. Then you know something is wrong before customers give up or start emailing you.
Checklist
Monthly
- Review your apps and remove the ones you no longer use
- Check Core Web Vitals in Search Console for the home page, collection pages and product pages
- Place a test order yourself and test your forms and newsletter sign-up
- Ask your developer whether monitoring flagged anything
- Make sure the content in your CMS is backed up
Quarterly
- Ask your developer whether your integrations still run on a supported version
- Have your theme (Theme Store) or your headless site's software updated
- Test new pages and components for accessibility, for example with the keyboard test
- Have someone check that your cookies and tracking scripts still match your cookie banner
- Have Search Console checked for pages that aren't indexed, 404s and redirects
Same day, when needed
- Serious security holes
- Broken orders, syncs or payments
What decides how much maintenance you need?
There's no standard price, because every site has different parts that can break. How much work it is depends mostly on:
- The number of integrations (ERP, POS, warehouse, email). Each one can break.
- How much custom work you have. A custom theme, custom apps or a headless site means more to look after.
- The number of markets and languages.
- How fast you need a response. Same day for checkout problems, within a week for a content change.
- How often you add new features.
A good question to ask any partner: what do I get in a month when nothing goes wrong?
Do it yourself or outsource it?
Keep content work in-house. With a well-set-up CMS that's easy. Leave the technical work (updates, monitoring, integrations, speed) to a developer who knows your site. There are roughly three ways to arrange that:
| Model | How it works | Good for | Watch out for |
|---|---|---|---|
| Maintenance plan | A fixed monthly fee for updates, monitoring and backups, often with some hours for small changes | Sites that just need to keep running, or that keep growing | Ask what happens to unused hours and how long you're tied in |
| Prepaid hours | You buy a block of hours up front, the developer deducts the time spent | Stable sites where little changes | Usually no updates, monitoring or guaranteed response time unless you ask |
| On demand | You call when you need something and pay per job | Small sites with few integrations | Slow help if the partner doesn't know your site or has no time |
What to agree on up front
Whichever model you choose, put these in writing:
- Response times, and what counts as critical. For example: the site is down or forms don't work. That gets picked up the same working day. A small change can wait a few days.
- What happens to unused hours. Do they roll over a month, or expire?
- How you see what's been done. A short monthly overview of the work and the time it took.
- How long you're tied in. A short fixed start period is normal. After that, a plan should be cancellable monthly.
- What's not included. Think of licences for your CMS and hosting, outages at those vendors, design and copy, and bugs in code someone else changed.
- How bigger work is handled. A new feature should be quoted up front, so you don't get surprises afterwards.
How I do it
After launch there's a warranty period first. Then you choose a plan that fits how much your site still changes: just keeping the technical side up to date (updates, monitoring, backups), or on top of that a set number of hours per month for small changes, an SEO check and a short check-in. For brands that keep expanding their site there's a plan with more hours and priority. After a short fixed start period, every plan is cancellable monthly. Rather not have a subscription? Prepaid hours work too. My process page explains how I work.
Build it so it needs less maintenance
Two choices when you build a site save the most work later:
- Few apps. Every app you replace with a small custom feature is one less thing to pay for, keep up to date and slow your store down.
- Modular content blocks. A lot of maintenance time goes into pages that got broken by accident. For Orangefit I built a headless site with DatoCMS where the content team builds pages in several markets and languages, without a developer.
FAQ
Does a Shopify store need maintenance?
Yes, but less than a site on your own servers. Shopify handles hosting, platform updates and payment security. Your theme, apps and integrations still need looking after.
How often should a website be maintained?
Have your site and checkout monitored all the time. Check apps, speed and integrations every month, and have the software, integrations and accessibility reviewed every quarter. Serious security holes get fixed on the day they become known.
What happens if you skip maintenance?
Usually nothing, for a while. Until your stock levels suddenly stop adding up, a security hole needs a quick update on a site that's years behind, or an app breaks the checkout. Then it costs more than keeping up would have.
Need help maintaining your site?
Want to know what maintenance your Shopify store or Next.js site needs? Tell me about your site and integrations. Book a call or email info@petercoolen.com.
Sources
- Shopify Help Center: Updating themes
- Shopify.dev: API versioning
- Shopify: PCI compliance
- Vercel: Summary of CVE-2025-55182
- ACM: Klant met beperking kan bij merendeel grote webwinkels niet terecht (Mar 2026, Dutch)
- NL Times: 6 in 10 Dutch webshops inaccessible to users with disabilities (Mar 2026)
- Google Search Central: Understanding Core Web Vitals and Google search results