The Monthly WordPress Maintenance Checklist

Most website emergencies don’t come out of nowhere. They build up quietly.

A plugin doesn’t get updated. A backup stops running and nobody notices. A contact form breaks, and you only find out three weeks later when a customer mentions they tried to reach you. By the time something actually goes wrong, it’s been going wrong for a while.

I’ve been building and fixing websites for a long time, and I can tell you the sites that stay out of trouble aren’t the ones with the fanciest setup. They’re the ones where somebody takes an hour once a month and actually looks.

That’s what this WordPress maintenance checklist is. It’s the routine I run on client sites, written so you can do it yourself.

Before you touch anything: make a fresh backup. Every step below is safer when you know you can roll back.

1. Confirm your backups are actually working

Notice I said confirm, not have. A lot of people “have” backups that stopped running months ago.

If you don’t have a backup system yet, this is what I teach: install the UpdraftPlus plugin. The free version is plenty for most sites. Set it up once and it runs on its own:

  • In Settings → UpdraftPlus Backups → Settings, set both the files and database schedules to Fortnightly.
  • Set it to keep 2 backups. That gives you about a month of coverage without eating up storage.
  • Under remote storage, connect a destination like Google Drive or Dropbox so your backups live off the server.
  • If your site changes every day, like an online store, back up the database more often.

Then, every month:

  • Open UpdraftPlus and check the date of the most recent backup. Make sure it actually ran.
  • Confirm the backups are showing up in your remote storage. If the server goes down, a backup sitting on that same server goes down with it.
  • Every few months, do a test restore to a staging site. A backup you’ve never restored is a guess.

2. Update WordPress, plugins and themes

Out-of-date software is the number one way sites get hacked. It’s not glamorous, but it matters.

  • Update plugins and themes first, then WordPress core.
  • Do them a few at a time rather than all at once, so if something breaks you know what caused it.
  • Read the changelog on major updates (a jump like 5.x to 6.x). Big version jumps are where things tend to break.
  • Delete plugins and themes you aren’t using. Deactivated isn’t enough. Inactive code can still be exploited.

If your site is important to your business, run updates on a staging copy first. Most good hosts offer one-click staging.

3. Click through your own site

When was the last time you used your website like a customer?

  • Load the homepage and your most important pages on your phone and on a computer.
  • Click the main menu items and buttons. Do they go where they should?
  • Look for anything that looks off after updates: broken layouts, missing images, odd spacing.

It takes ten minutes, and you’d be surprised what you find.

4. Test every form

This is the one that costs people real money. A broken contact form doesn’t throw an error. It just quietly stops sending you leads.

  • Submit each form on your site, including contact, quote request and newsletter signup forms.
  • Make sure the email actually arrives, and check your spam folder too.
  • If you use a form plugin that stores entries, check that the test shows up there.

If form emails are landing in spam or not arriving at all, your site’s email setup probably needs attention. That’s covered in SPF, DKIM & DMARC in Plain English.

5. Check security and users

  • Run a scan with your security plugin or your host’s scanner.
  • Go to Users and look at every account. Remove anyone who no longer needs access, like old contractors, former employees, or that developer from three years ago.
  • Make sure every admin account has a strong password, and two-factor authentication if you can turn it on.
  • Watch for admin users you don’t recognize. That’s a red flag that needs attention right away.

Want to go deeper on security? I wrote a whole book on it. WordPress Security Made Simple: The No-Nonsense Guide to Protecting Your WordPress Site walks through locking down your site step by step, in plain English.

6. Check speed

A slow site loses visitors, and Google notices too.

  • Run your homepage through Google PageSpeed Insights. Pay most attention to the mobile score.
  • If it’s dropped since last month, look at what changed: a new plugin, big images, a new embed.
  • Compress any large images you’ve uploaded recently.

You don’t need a perfect score. You’re looking for a site that loads quickly and isn’t getting worse.

7. Look at Google Search Console

If you haven’t connected Google Search Console, do that first. It’s free, and it’s Google telling you directly how it sees your site.

  • Check for new errors under Pages (pages Google can’t index).
  • Glance at Performance to see whether clicks and impressions are trending up or down.
  • Watch for any security or manual action warnings.

8. Clean up

  • Empty the spam comments and trash.
  • Clear old post revisions and transients if you have a database cleanup tool.
  • Clear your cache after all your updates are done, then look at the site one more time.

9. Check your renewals

This one sounds silly until it happens to you.

  • When does your domain expire? Is it set to auto-renew? Is the card on file still valid?
  • Is your SSL certificate renewing automatically? (Look for the padlock in your browser.)
  • Is the email on your registrar and hosting accounts one you actually check?

I’ve seen businesses go offline because a renewal notice went to an old email address nobody looked at anymore. Don’t let that be you.

The WordPress maintenance checklist (short version)

Print this out, or bookmark it, and put an hour on your calendar once a month:

  1. Confirm backups ran (UpdraftPlus, fortnightly, keep 2) and are stored off-site
  2. Update plugins, themes and core (after a backup)
  3. Click through the site on desktop and mobile
  4. Test every form
  5. Scan for security issues and review users
  6. Check speed
  7. Review Search Console
  8. Clean up spam, trash and cache
  9. Check domain, SSL and account renewals

Is it exciting? No. But an hour a month is a lot cheaper than a hacked site, a lost week of leads, or a domain that expired while you weren’t looking.

If you want the full security picture, grab a copy of my book, WordPress Security Made Simple. And if you’d rather not deal with any of this yourself, that’s fine too. That’s exactly what I do for my clients at That One Web Guy.

Similar Posts