WordPress maintenance is often reduced to clicking an update button. That is only one part of the work. A business website needs a controlled routine covering security, backups, performance, forms, search visibility and commercial functionality.
The purpose of maintenance is not to keep software versions looking current. It is to reduce the likelihood that a customer encounters a broken form, failed payment, slow page or security warning. The following checklist can be used monthly, with more frequent monitoring for busy e-commerce and membership websites.
1. Confirm that backups are completing
Check that automated backups are running on schedule and being stored outside the main hosting account. A backup that sits only on the same server may become unavailable during a hosting failure or account compromise.
Verify that both the database and website files are included. Keep several restore points and record retention periods so the team knows how far back recovery can go.
2. Test a restoration process
A successful backup notification does not prove that restoration will work. Periodically restore the website to staging or a safe recovery environment. Confirm that pages, media, forms, user accounts and transactions appear correctly.
Document who can start a restoration, where credentials are stored and how DNS or hosting support will be contacted during an emergency.
3. Apply WordPress, theme and plugin updates safely
Review updates before applying them. Check compatibility notes, recent support reports and whether the update affects checkout, forms or other critical functions. Create a fresh backup and use staging for major changes.
After updating, test the main customer journeys. A technically successful update may still change layouts, scripts or integrations.
4. Remove unused software and accounts
Inactive themes, abandoned plugins and old administrator accounts expand the attack surface. Remove software that is no longer required rather than leaving it disabled indefinitely.
Review users and roles. Former employees, agencies and temporary contractors should not retain access after their work ends. Each person should have an individual account with the minimum permissions required.
5. Review security activity
Check firewall events, failed logins, malware scans and file-change alerts. Repeated attempts against a particular username or URL may justify stronger restrictions. Investigate unexpected administrator accounts, modified files or changes to payment settings immediately.
Two-factor authentication should be required for administrators and other high-privilege users.
6. Test forms and email delivery
Submit every important form using a real external email address. Confirm that the visitor receives the expected message and that the internal notification reaches the correct team. Check spam folders and CRM records.
Website email should normally use an authenticated transactional email service rather than depending entirely on the web server’s default mail function.
7. Test checkout, booking or membership flows
For commercial websites, complete a test transaction using the payment gateway’s sandbox or an approved low-value live procedure. Confirm taxes, shipping, currencies, confirmation emails, account access and order status.
Also test failure scenarios such as an incomplete payment, expired session or invalid discount code. Customers often experience problems at the edges of the process.
8. Monitor uptime and server health
Use external uptime monitoring because a website cannot reliably report its own outage. Review response times, recurring downtime and resource limits. Sudden increases in database load, storage or PHP errors may indicate a technical problem before customers complain.
Ensure the hosting environment uses a supported PHP version and has adequate memory, processing capacity and storage.
9. Check page speed and Core Web Vitals
Test important pages on mobile and desktop. Focus on the homepage, main service pages, high-traffic articles, product pages and checkout. Large images, third-party scripts and poorly controlled plugins are common causes of gradual slowdown.
Do not chase a perfect laboratory score while ignoring user experience. Prioritise fast visible content, stable layouts and responsive interactions.
10. Find broken links and missing pages
Scan for internal and external broken links. Update links after page changes and create redirects when useful URLs move. Review the website’s 404 report to identify visitors and search engines requesting old addresses.
Legal, contact, blog and account pages should never lead to generic server errors. They are trust signals as well as functional pages.
11. Review analytics and search data
Confirm that analytics and conversion events are still recording. Compare traffic, enquiries, sales and top landing pages. In Search Console, review indexing problems, mobile usability and unusual changes in impressions or clicks.
Maintenance should produce decisions. A page receiving traffic but few enquiries may need clearer copy, stronger proof or a better call to action.
12. Record completed work and next actions
Maintain a simple monthly record showing updates, tests, issues, fixes and recommendations. This creates accountability and makes recurring problems easier to identify.
High-risk items should have an owner and target date. Maintenance loses value when findings are repeatedly reported but never resolved.
Recommended maintenance frequency
- Continuous: uptime, security and transaction monitoring.
- Weekly: backups, critical updates, forms and commercial checks.
- Monthly: complete checklist, analytics review and report.
- Quarterly: restoration test, account audit and performance review.
Sonnywebs managed services combine maintenance, security, reporting and improvement work. Review the support plans or request a website health review.

