Affiliate disclosure: Some links in this article are affiliate links. If you purchase through them, I earn a commission at no extra cost to you. I only recommend services I've personally tested.
His spreadsheet said $70 a month. His Cloudways invoice said $267. Fifteen WordPress client sites, five DigitalOcean 1GB servers at $14 each — the base math checked out fine. What didn't show up in his spreadsheet: SafeUpdates tacked on per application, CDN enabled on most sites, email add-ons running on three. His effective cost per client was north of $17. For sites that averaged maybe 2,000 visits a month.
A week later, I was helping a different agency — 30 clients, similar traffic levels — troubleshoot a DNS issue on their RunCloud setup. Their total hosting bill: RunCloud Pro at $19/month, plus ten DigitalOcean droplets at $6 each. Total: $79/month. That's $2.63 per client.
Same WordPress sites. Same visitor range. One agency paying six times more per client than the other.
That gap didn't come from one agency being smarter than the other. It came from them being on fundamentally different architectures — and neither of them realized the choice they'd made years ago had a cost curve attached to it. The first agency was on a managed VPS platform where costs scale with add-ons. The second was on a server management panel connected directly to a cloud provider, where the panel fee stays fixed regardless of how many sites you run.
Every "best hosting for agencies" article I've seen in the SERP treats this as a brand decision. Cloudways 4.5 stars, Kinsta 4.3, RunCloud 4.2 — pick the highest number. That framing misses the point entirely. You're not choosing a brand. You're choosing a cost architecture. And the wrong one gets more expensive with every client you add.
Three Architectures, Not Ten Brands
Strip away the brand names and every agency hosting option falls into one of three structural categories. These aren't tiers of quality — they're fundamentally different models for how you pay, how much control you get, and what breaks when something goes wrong.
Architecture 1: Per-Site Managed
WP Engine, Kinsta. You pay per WordPress installation. The provider owns the server, manages the stack, handles caching, security, backups, and gives you a dashboard per site. You don't touch the server. You don't choose the server. You don't even know which server your site is on, because it doesn't matter — that's the whole point.
The pricing model is straightforward: more sites, higher tier, more money. WP Engine's Growth plan covers 10 sites for $96/month. Their Scale plan covers 30 sites for $242/month. Kinsta starts at $35/month for a single site and ranges up to $1,650/month at the top end.
The value proposition is real: zero server management, container-level isolation between sites, and support that actually understands WordPress. For a solo freelancer with 4 clients, this is hard to beat. The problems start when you're signing your 15th client and your hosting bill is climbing faster than your revenue.
Architecture 2: Server Panel + Direct VPS
RunCloud, GridPane, SpinupWP. You rent your own VPS from DigitalOcean, Vultr, or Hetzner. You install a management panel that configures Nginx, PHP, SSL, and gives you a WordPress-focused dashboard. You pay the cloud provider for the server and the panel company for the software. Two invoices, two relationships, more control.
RunCloud Pro costs $19/month and manages up to 50 servers with unlimited applications. GridPane's Core tier is free. SpinupWP's Team plan is $39/month. The server cost is whatever DigitalOcean or Vultr charges — a 1GB droplet at $6/month, a 4GB at roughly $24. You decide how many sites to pack onto each server based on traffic and resource needs.
This is where the cost curve bends. The panel fee is fixed or nearly fixed, and the per-server costs are at raw cloud pricing without a management markup. Add a client? You're adding maybe $2/month in server capacity, not jumping to a new pricing tier.
The tradeoff is real, though. One GridPane reviewer on G2 put it directly: "difficult to set up for those without technical knowledge" — and they added that the "pricing structure has been criticized as confusing and quite expensive for businesses." That confusion often isn't about the panel price itself (GridPane Core is free). It's about juggling the two-bill model, sizing servers correctly, and knowing what to do when Nginx throws a 502 at 11 PM.
Architecture 3: Reseller / Shared
SiteGround GoGeek, A2 Hosting reseller tiers, traditional cPanel reseller packages. You get a single shared hosting account that can run dozens of WordPress sites. The provider handles everything server-side. You get cPanel or a proprietary panel, and you can white-label the hosting to your clients.
SiteGround's GoGeek plan runs $44.99/month at renewal and supports unlimited sites with white-label client access. At 30 clients, that's $1.50 per client. At 50, it's $0.90.
The math looks incredible until you remember what you're buying: shared server resources, shared IP addresses, and performance that degrades when someone else on the same physical machine runs a poorly optimized WooCommerce store. This architecture exists, it works for low-traffic informational sites, and I'm not going to pretend it doesn't. But it's a different product category from the first two, and the savings come with strings.
The Math Nobody Shows You
Below is what 10 and 30 client sites actually cost across all three architectures, using current published pricing. I'm assuming lightweight WordPress sites averaging 1,000-5,000 monthly visits each — the kind of client sites most agencies manage.
Server sizing assumption for Architecture 2: three WordPress sites per DigitalOcean 1GB droplet ($6/month). This is conservative for lightweight sites and tight for anything running WooCommerce or heavy page builders. Adjust upward for heavier sites.
| Architecture | Stack | 10 Clients: Total | 10 Clients: Per Client | 30 Clients: Total | 30 Clients: Per Client | 50 Clients: Total | 50 Clients: Per Client |
|---|---|---|---|---|---|---|---|
| Per-site managed | WP Engine | $96/mo (Growth plan) | $9.60 | $242/mo (Scale plan) | $8.07 | Custom pricing required | Varies |
| Per-site managed | Kinsta | ~$350/mo (extrapolated from $35/site base) | ~$35.00 | Custom pricing required | Varies | Custom pricing required | Varies |
| Panel + VPS | RunCloud Pro + DO | $19 + 4×$6 = $43/mo | $4.30 | $19 + 10×$6 = $79/mo | $2.63 | $19 + 17×$6 = $121/mo | $2.42 |
| Panel + VPS | GridPane Core + DO | $0 + 4×$6 = $24/mo | $2.40 | $0 + 10×$6 = $60/mo | $2.00 | $0 + 17×$6 = $102/mo | $2.04 |
| Panel + VPS | SpinupWP Team + DO | $39 + 4×$6 = $63/mo | $6.30 | $39 + 10×$6 = $99/mo | $3.30 | $39 + 17×$6 = $141/mo | $2.82 |
| Reseller | SiteGround GoGeek | $44.99/mo (flat) | $4.50 | $44.99/mo (flat) | $1.50 | $44.99/mo (flat) | $0.90 |
A few things jump out of this table.
WP Engine at 30 clients is actually cheaper per client than at 10 — the tier structure gives volume discounts. But it's still 3x the cost of RunCloud + DigitalOcean at the same scale. That $163/month difference is $1,956/year. For an agency with 30 clients, that's not a rounding error.
Kinsta's per-site pricing makes it the most expensive option at scale unless you negotiate an agency deal. Their published pricing starts at $35/month for a single site, and while they offer volume plans, the public pricing page doesn't show clear tier discounts the way WP Engine does. If you're running 10+ client sites on Kinsta and haven't negotiated custom pricing, you're almost certainly overpaying.
GridPane Core at $0/month for the panel looks absurd until you understand the catch: the Core tier covers up to 25 sites with no panel fee, but you're managing your own servers with no dedicated support from GridPane. If you need their 360 Support, it's $20/site for 6-25 sites and $15/site for 26-50 sites — which changes the math significantly. At 30 sites with 360 Support, you'd pay $450/month for support alone, making it more expensive than WP Engine.
SiteGround reseller looks like the obvious winner on cost. I'll explain in the next section why it isn't.
And here's the number that's missing from this table: add-on costs on managed platforms. Cloudways lists its DO 1GB server at $14/month — that's a 133% markup over DigitalOcean's direct price of $6/month. Fair enough, you're paying for management. But community users who've itemized their invoices report that stacking SafeUpdates, CDN, and email add-ons across multiple applications pushes a single "cheap" server well past $80/month. One RunCloud reviewer on G2 made a similar point about panel-side paywalling: "Several features like memory usage stats and bandwidth are hidden behind a top-level paywall." The base price comparison is table stakes. The real cost comparison happens after add-ons.
What Happens When One Client Gets Hacked
Cost isn't the only axis that separates these architectures. The security model is fundamentally different, and the difference matters most in the scenario agencies dread: one client's site gets compromised, and you need to know whether your other 29 clients are exposed.
| Dimension | Per-Site Managed (Kinsta / WP Engine) | Panel + VPS (RunCloud / GridPane + DO) | Reseller (SiteGround GoGeek) |
|---|---|---|---|
| Isolation method | Container per site (LXC/Docker). Each site runs in its own isolated environment. | PHP-FPM pools per site on same server. Filesystem-level user separation, but sites share the OS kernel and server resources. | Shared cPanel account. Sites share PHP, filesystem space, and often the same user permissions. |
| Blast radius of a compromise | Contained to that single site's container. Other sites on the same physical hardware are unaffected. | Depends on attack vector. A PHP exploit stays contained by FPM pools. A kernel-level or root exploit exposes all sites on that server. | High. A compromised site can potentially read/write files belonging to other sites. Shared IP means all sites affected if the IP gets blacklisted. |
| Shared IP risk | None — each site typically gets its own IP or is behind a CDN that abstracts the origin IP. | Moderate — sites on the same droplet share an IP. One site sending spam can trigger blacklisting for all. | High — all sites on the shared server share an IP. |
| Recovery effort | Provider handles malware scanning and removal. Restore from automated backup in minutes. | Agency handles remediation. Backups exist if you configured them. Expect 2-4 hours per compromised site. | Provider runs server-level scans but doesn't fix individual WordPress infections. You're cleaning it yourself. |
| Who pays for the cleanup | Included in your plan (Kinsta/WP Engine both offer malware removal). | You. Or the freelancer you hire at $150/hour. | You. |
The security story is where per-site managed platforms earn their markup. When a client's WordPress installation gets injected with a cryptominer — and at agency scale, it's when, not if — Kinsta's container isolation means you're dealing with one compromised site, not a portfolio-wide incident.
On RunCloud or GridPane, the isolation is softer. PHP-FPM pools prevent one site's PHP process from reading another site's files, which stops the most common WordPress attack vectors. But the sites still share an operating system. A privilege escalation vulnerability in the Linux kernel (they happen every year) could theoretically give an attacker access to everything on that droplet. It's a smaller risk than the cPanel/shared hosting scenario, but it's not zero.
And then there's the support boundary problem. One G2 reviewer laid it out about RunCloud: "Support is non-existent, and you will receive help only if something's wrong with the RunCloud panel, so you are on your own with your configuration and applications." When a client's hacked site is your emergency, managed platforms handle remediation for you. Panel + VPS means the cleanup is your problem — and at 2-4 hours per site, a multi-site compromise on one server can cost you a full workday.
Reseller hosting is the worst of both worlds: lowest isolation, highest blast radius, and the cheapest price point that makes agencies forget they're trading security for margin until something breaks.
This is the real tradeoff, and I want to be direct about it: panel + VPS is cheaper and less secure than per-site managed. Not dramatically less secure for most attack scenarios — PHP-FPM isolation handles the common cases. But the long tail of "what if something really goes wrong" is wider, and the agency bears 100% of the remediation cost.
The Graduation Problem
If you've read this far, the conclusion seems obvious: start on per-site managed when you have a few clients, then "graduate" to panel + VPS once your client count makes the cost differential painful. Sections 3 and 4 build a clear case — panel + VPS is cheaper at scale, and the security difference is manageable with basic hygiene.
This is what that graduation actually looks like.
Migrating a WordPress site from WP Engine or Kinsta to a RunCloud-managed VPS means exporting the database, transferring files, reconfiguring DNS, testing the site on the new server, setting up SSL, configuring caching, and verifying that every contact form, cron job, and third-party integration still works. For a standard brochure site with a few plugins, that's 1.5-2 hours of focused work. For a WooCommerce store with payment gateways and custom integrations, it's 3-4 hours.
Now multiply. An agency with 20 client sites migrating from Kinsta to RunCloud + DigitalOcean is looking at 30-50 hours of migration labor, spread across multiple weekends because you're not going to take 20 client sites offline simultaneously. During that window, you're paying both the old platform and the new one. You're fielding client questions about "why is my site slow today." You're debugging the one site that breaks because its caching plugin conflicts with Nginx FastCGI caching.
One agency owner on Trustpilot described the end of a long Cloudways relationship: they "moved our sites away from them" after support was "very slow to deal with a problem." What that review doesn't mention — and what no review ever mentions — is how many hours that migration took. Moving "our sites" is a sentence. Doing it is a project.
This migration cost is the real lock-in mechanism, and it grows linearly with your client count. The irony is sharp: the architecture that's cheapest at scale (panel + VPS) is also the one you have to invest the most labor to reach. The longer you wait, the more sites you have to migrate. The more sites you have to migrate, the harder it is to justify the disruption. This is how agencies end up on Cloudways at 40 clients, paying $4,000+ a year more than they need to, because migrating 40 sites is a three-week project that nobody has time for. I've watched it happen. The owner knows the math — they've run the spreadsheet three times. But every quarter, something more urgent comes up. A new client launch. A site redesign. A developer quitting. The migration slides to next quarter. Again. Eventually they stop opening the spreadsheet.
So when should you actually graduate?
Not at a specific client count. At a specific margin threshold. If your per-client hosting cost is eating more than 15-20% of what you charge that client for hosting or maintenance, and you have the technical ability (or a team member who does) to manage a VPS, you're past the crossover point. For most agencies, that's somewhere between 10 and 20 clients — early enough that the migration is still a long weekend, not a month-long project.
The worst time to graduate is when you're at 40 clients and the cost pain is unbearable. By then, you've accumulated 80+ hours of migration debt. The best time is when you're at 12 clients and the migration is 18-24 hours of work total.
Match the Architecture to Your Stage
I've shown the cost math, the security tradeoffs, and the migration reality. So I'll stop hedging and tell you what I'd actually do at each stage.
Solo freelancer, 1-8 client sites
Use per-site managed. WP Engine Growth (up to 10 sites) or Kinsta.
At this stage, your time is worth more than the cost premium. You don't have a team to handle server issues. You don't have the buffer to absorb a 4-hour security incident at 2 AM. And the per-client cost at $9.60-$12 is justifiable when you're charging clients $50-150/month for maintenance plans.
Do not start on reseller hosting to save money. The isolation and support gap will cost you more in client trust the first time something breaks.
Small agency, 8-20 client sites
Transition to panel + VPS. RunCloud Pro or SpinupWP Team with DigitalOcean or Vultr.
This is the graduation window. Your per-client cost on WP Engine is approaching the point where the savings from switching pay for themselves within 3-4 months. At 15 clients, switching from WP Engine (somewhere between the Growth and Scale tiers) to RunCloud + DO saves you roughly $160-190/month, and the migration is a manageable 22-30 hours across two weekends.
You need someone on the team who can SSH into a server and read an Nginx error log. If nobody on your team can do that, factor in the learning curve — GridPane and RunCloud both have good documentation, but the G2 feedback about GridPane being "difficult to set up" is accurate for teams coming from fully managed environments. RunCloud's interface is closer to what cPanel users expect.
GridPane Core (free) is tempting, but I'd recommend RunCloud Pro for agencies in this range. The flat panel fee buys you a cleaner UI, better onboarding, and support that at least covers panel issues. You can always switch to GridPane later if you want the performance edge and don't need hand-holding.
Mid-size agency, 20-60+ client sites
Panel + VPS is the only architecture that makes financial sense. RunCloud Pro or GridPane Core, multiple VPS instances, strict server-per-client-tier segmentation.
At 30 clients, the panel + VPS total from the table above is under $80/month. WP Engine's published 30-site tier is over three times that. The annual difference is close to $2,000 — and it compounds every year. At 50 clients, the gap widens further.
At this scale, you should be segmenting servers by client tier: high-traffic WooCommerce clients on dedicated 4GB+ droplets, low-traffic brochure sites packed 5-8 per 1GB droplet. This gives you isolation where it matters most without overspending on server resources for sites that get 500 visits a month.
You should also have a sysadmin or senior developer who owns the infrastructure. Not optionally — as a requirement. Panel + VPS at 50 sites is an infrastructure role, not a side task.
When not to follow this framework at all
If your client sites aren't WordPress, none of this applies. If any client requires HIPAA or PCI compliance, they need dedicated infrastructure that none of these architectures provide. And if your agency model is white-label SaaS (Duda, Flavor CMS, GoHighLevel), you're in a different product category entirely — you're not managing hosting, you're reselling a platform.
One more: if your agency's revenue model depends on reselling hosting at a visible markup, the panel + VPS route makes your margins transparent to anyone who Googles "DigitalOcean pricing." Per-site managed platforms obscure your cost basis. That matters if hosting margin is a significant revenue line for you, not just a pass-through expense.
FAQ
Can I start on Kinsta with 5 clients and switch to GridPane later without losing data?
Yes, but "without losing data" undersells the effort. You'll export each site's database and files, set up the WordPress installation on your GridPane-managed server, import the data, reconfigure DNS, and test everything. Budget 2 hours per brochure site, 3-4 hours per WooCommerce site. At 5 sites, that's a single long weekend. At 20 sites, it's a multi-week project. No data loss if you do it right, but "right" means testing each site thoroughly before flipping DNS — don't batch-switch 5 sites in one night.
Is Cloudways still worth it for agencies after the DigitalOcean acquisition?
DigitalOcean acquired Cloudways in 2022, and the pricing hasn't decreased — it's trended up through add-on expansion. Cloudways charges $14/month for a DO 1GB server that costs $6/month direct from DigitalOcean. That 133% markup is the management premium, and it was always the deal. What's changed post-acquisition is that there's less reason to expect Cloudways to compete aggressively on price, since the parent company has no incentive to cannibalize its own direct VPS sales. For agencies with fewer than 8 sites who want managed simplicity, Cloudways is still a reasonable middle ground. For agencies at 15+ sites, the markup compounds to the point where a flat-rate panel subscription plus direct DO droplets saves you hundreds per year.
How do I bill my clients for hosting without them seeing my actual costs?
WP Engine and Kinsta both let you add clients to a portal with their own login — the client sees their site, not your invoice. This is the simplest path if your clients expect a branded hosting dashboard. The failure mode nobody warns you about: clients who can log into WP Engine directly sometimes start asking why they need you at all. If your value proposition beyond "I manage your hosting" is thin, giving clients portal access can undermine your own retainer.
On panel + VPS, there's no built-in white-label billing. Most agencies using RunCloud or GridPane handle it through a separate invoicing tool — FreshBooks, Stripe billing, or a recurring PayPal invoice — and bundle hosting as a line item in the monthly retainer. The decision rule: if fewer than half your clients ask for hosting login access, bundle it and don't overthink the presentation. If most clients want to see "their" hosting dashboard, either use SiteGround GoGeek (which includes white-label client access at its renewal price) or accept that you'll spend 2-3 hours rigging a client-facing status page through a third-party tool. The worst approach is promising white-label access, failing to deliver it cleanly, and having a client stumble into your actual cost structure.
What happens to my other clients' sites if one gets hacked on a shared VPS?
If the attack is a typical WordPress exploit — SQL injection through a vulnerable plugin, malware injected via a compromised admin account — PHP-FPM pools on RunCloud and GridPane prevent the compromised site's PHP process from touching other sites' files. Your other clients are safe from these common vectors. If the attack involves a Linux kernel privilege escalation (rarer, but not hypothetical — several CVEs in the last two years), an attacker could gain root access to the entire droplet. At that point, every site on that server is potentially compromised. The mitigation isn't a plugin or a setting — it's server segmentation. Don't put your highest-value clients on the same droplet as that one client who installs nulled themes.
At what point should I hire a sysadmin instead of paying for managed hosting?
A part-time sysadmin (10-15 hours/month) costs $500-1,500/month depending on your market. WP Engine's 30-site tier runs north of $240/month. RunCloud Pro plus DO at the same scale is under $80. So the question isn't "sysadmin vs. managed hosting" — it's "sysadmin + cheap infrastructure vs. expensive managed hosting with no sysadmin." The math favors hiring at around 30-40 clients: you're spending $79/month on infrastructure plus $800/month on a part-time sysadmin ($879 total), compared to scaling up to an enterprise managed plan that could cost $500-1,000/month without giving you any infrastructure expertise. The sysadmin becomes the better investment because they fix things that no hosting provider will touch — application-layer bugs, plugin conflicts, client-specific performance issues.
Can I use WordPress Multisite instead of separate installations for client management?
You can. I wouldn't. Multisite shares a single database across all sites, which means a database corruption or a botched update affects every client simultaneously. Plugin compatibility is a constant headache — one client needs a plugin version that breaks another client's site, and you can't update per-site. Client offboarding is a nightmare: extracting a single site from Multisite into a standalone WordPress installation is a 4-6 hour project involving database surgery. Separate installations per client, managed through a panel like RunCloud, give you the isolation that agency work demands. The only scenario where Multisite makes sense is when all client sites are identical in structure (same theme, same plugins, same functionality) — essentially a template network, not individual client projects.