Article

A practical WordPress maintenance checklist for business websites

Most WordPress problems come from skipped updates, backups nobody has tested, and too many people with admin access. This checklist covers the routine work, in the order that keeps the risk down.

Before you start: two rules

1. Never experiment on your live site. If you are not sure what an update or setting will do, try it on a staging copy first. Many hosts offer one-click staging; if yours does not, a developer can create one.

2. Have a backup you have actually restored. A backup that has never been restored is a hope, not a plan. WordPress's own backup documentation makes the point that you need both the database and the files to restore a site.

Why maintenance matters

WordPress, and the plugins and themes it runs, are updated regularly to fix bugs and security problems. The WordPress hardening guide is blunt: older versions of WordPress are not maintained with security updates. Leaving updates for months makes each eventual update riskier, because more changes land at once.

At the same time, updating carelessly can break a site: a plugin update can change a form, a layout or an integration. The routine below balances both risks.

Weekly (15 to 30 minutes)

  • Check the site loads on a phone and a computer, including the home page, one service page and the contact page.
  • Submit the contact form with a test message and confirm it arrives in the right inbox.
  • Confirm last night's backup completed and is stored somewhere other than the website's own server.
  • Review available updates in the WordPress dashboard. Note which ones are security releases.
  • Scan for obvious problems: unexpected pages, spam comments, or warnings in the dashboard.

Monthly (1 to 2 hours)

  • Apply updates on staging first. Update WordPress core, plugins and themes on the staging copy, then check key pages and forms.
  • Take a fresh backup of the live site, then apply the same updates to live.
  • Re-test the contact form and key pages after updating.
  • Check Site Health under Tools → Site Health and read the Status tab. It flags common configuration problems, such as an outdated PHP version or inactive plugins and themes that should be removed (Site Health documentation).
  • Remove plugins and themes you do not use. Deactivated plugins still contain code that can be exploited; delete them rather than leaving them installed.
  • Check the TLS certificate (the padlock) expiry date if your host does not renew it automatically.
  • Record what changed: date, versions before and after, and anything that broke and how it was fixed.

Quarterly (half a day)

  • Test a restore. Restore a recent backup to a staging or temporary location and confirm the site works. Record the date and result.
  • Review user accounts. Remove people who have left, reduce administrators to those who need it, and make sure each person has their own login.
  • Require strong authentication for administrators, such as two-factor authentication, where your setup supports it.
  • Review plugins against need. For each plugin, ask what it does, who relies on it, and whether it is still maintained.
  • Check the hosting account: PHP version, disk space, who has access to the control panel, and that billing contacts are current.
  • Review content accuracy: services, staff, prices, hours and locations that may have changed.

Once a year

  • Confirm ownership: the domain, hosting, WordPress admin and analytics accounts are in the organization's name, with at least two people able to access them.
  • Renewal dates: domain, hosting and premium plugin licences.
  • Recovery plan: who would restore the site, from which backup, and how long it would take? Write it down.

Things not to do on a live site

  • Do not install unknown plugins "to try them".
  • Do not edit theme files directly in the WordPress editor. Changes are lost on the next theme update, and a typo can take the site down.
  • Do not run bulk database clean-ups or "optimization" plugins without a restorable backup.
  • Do not share one admin login between several people.
  • Do not assume a security plugin replaces updates and backups. It does not.

What this checklist does not cover

This routine reduces risk; it does not make a website perfectly secure. It is not a security audit, penetration test or compliance review, and it does not replace advice from a specialist if you suspect your site has been compromised. If your site is hacked, take it offline or put up a maintenance page, keep your backups safe, and get specialist help before restoring.

Copy this checklist

You are welcome to copy this checklist for your organization's internal use. If you would rather have someone else run it, see website care.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. Hardening WordPress, WordPress Developer Resources
  2. Backups, WordPress Developer Resources
  3. Upgrading WordPress, WordPress Developer Resources
  4. Site Health screen, WordPress.org Documentation

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Get a straight answer for your situation

General advice only goes so far. Tell us about your environment and we will tell you what we would do, what it would cost and what to watch out for.

  • A named specialist who owns the outcome, not a chat window
  • Advice checked against your actual systems, contracts and risks
  • Written scope and costs in CAD before any work starts