The WordPress Maintenance Checklist: What to Do Daily, Weekly, Monthly, and Yearly

A practical WordPress maintenance checklist from a team that's done it since 2009: what to check daily, weekly, monthly, and yearly to keep your site safe.

Keeping a WordPress site healthy comes down to a simple routine: watch for security alerts, update carefully, make sure your backups work, clean out what you don’t use, and review the bigger picture once or twice a year. Here’s the full checklist we’d give anyone maintaining their own site, organized by how often each task needs doing.

We’ve been maintaining WordPress sites since 2009, and this is the same ground we cover for our clients. Use it to do the work yourself, or to check what your current provider is doing.

Download the checklist (PDF) →

Before you start

  • Admin access. You’ll need an Administrator login for your WordPress site.
  • A backup you know works. Before any maintenance, make sure you have a recent backup, and that you know how to restore it. A backup you’ve never tested is only a hope.
  • A staging site, for bigger jobs. A staging site is a private copy of your website where you can test changes first. You don’t need one for routine updates, but it’s worth using before major changes, like a redesign or a big new feature.

Daily

  • Check for security alerts. If your site has a security plugin, or your host sends alerts, glance at them every day. Catching suspicious activity early is the difference between a quick fix and a full cleanup.

Weekly

  • Update plugins and themes carefully. Run updates one at a time, or in small groups, and check your site after each round. Look at the homepage, a few key pages, and your contact form. If something breaks, you’ll know which update caused it.
  • Confirm your backups ran. Backups fail quietly. Check that the latest one actually exists and has a recent date.
  • Review comments and spam. Approve real comments, delete the spam, and keep it from piling up.

Monthly

  • Restore a backup to a test site. This is the only way to know your backups really work. Do it before you need it.
  • Check your site’s speed. A free tool like Google PageSpeed Insights will show if something has slowed your site down, like an oversized image or a new plugin.
  • Remove unused plugins and users. Deactivated plugins can still be a security risk, and old user accounts are an open door. If you’re not using it, delete it.

Quarterly and yearly

  • Check your PHP version and hosting. PHP is the software your site runs on. Old versions stop getting security fixes, and your host’s control panel will show which one you’re on.
  • Renew your domain and SSL certificate. Better yet, set both to auto-renew, and make sure the payment card on file is current. An expired domain takes your website and email down with it.
  • Review who has access. Go through your WordPress users, hosting account, and domain registrar, and remove anyone who no longer needs access.
  • Refresh outdated content. Check your team page, hours, prices, and services. Outdated information makes a business look neglected, even when the site is technically healthy.

The part most checklists skip

Everything above keeps your site safe. But that’s only half the job. The other half is keeping it current: new staff on the team page, this month’s blog post, updated hours, a new service. A perfectly maintained site with last year’s information still costs you customers.

That’s where most businesses fall behind, because content changes never feel urgent until a customer points one out.

How long does all this take?

Honestly, it depends, and that’s the catch.

Clicking “Update” only takes a few minutes. The time goes into what happens when an update breaks something or changes how part of your site works. Then a quick task becomes an afternoon of troubleshooting.

And there’s a catch-22. The less often you update, the bigger the jump between versions, and the more likely something breaks when you finally do. The hardest part of this checklist isn’t any single task. It’s doing all of them regularly, week after week, alongside everything else on your plate.

Or hand it off

If this checklist looks like more than you want to take on, you have two options with us:

  • Website Maintenance ($99/month) covers the technical side: updates, backups, security and uptime monitoring, and malware cleanup, with same-day help when something breaks. Content updates aren’t part of this plan.
  • Website Care ($199/month) covers everything in Website Maintenance, plus a team that handles your content changes, like refreshed team pages, new hours, and blog posts, with 2 hours a month included.

(Not sure which fits? Here’s how care plans and maintenance plans compare.)

Compare plans and pricing →

FAQ

How often should I update WordPress plugins?

At least weekly. Many updates are security fixes, and putting them off makes each update bigger and riskier. Check your site after every round.

Should I turn on automatic updates?

For plugins and themes, our answer is usually no. Running them automatically, with no plan for when something goes wrong, is playing with fire. Do you want to wake up to a broken website? Small WordPress security releases are the exception: leave those on. Here’s why.

What’s a staging site, and do I need one?

A staging site is a private copy of your website for testing changes. For routine updates, most sites don’t need one: a recent backup and a careful check afterward matter more. Staging is worth it for bigger or more sensitive work, like a redesign or a major new feature.

What should I do if an update breaks my site?

Don’t panic, and don’t keep clicking. If you can, restore your most recent backup. Then update one item at a time to find the cause, or get help from someone who knows WordPress.

Jeffery Patch

Founder, Lead Geek · MaintainPress

Jeff has been building and looking after WordPress sites since 2009.

Rather hand it off?

Tell us what your site needs, and we'll recommend the right plan. Month-to-month, no contracts.