info@toimi.pro
Thank you!
We have received your request and will contact you shortly
Okay
Web development

What belongs on a WordPress maintenance checklist? Weekly, monthly and quarterly tasks

15 min
Web development

Weekly: back up, update plugins on a staging copy first, and check uptime and forms. Monthly: test a restore, scan for malware, prune unused plugins and users, and check speed. Quarterly: review the PHP version, user roles, licenses and accessibility. Most owners skip the restore test. It is the step that matters.

If you would rather not own this list, compare it with handing WordPress upkeep to a support team. Below you get the full checklist with a "how to verify" column for every task, the update routine that keeps a site from breaking, and the clauses to demand in a support contract. All figures are as of September 30, 2026.

Short answer: the checklist on one screen

Plugins are where the risk sits. Patchstack counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025. Of those, 91% were in plugins, 9% in themes, and only 6 in core (Patchstack, State of WordPress Security in 2026, as of September 30, 2026). The same report says 46% of vulnerabilities had no fix from the developer in time for public disclosure. So updating is necessary. It is not enough on its own, and the checklist reflects that.

The time column is a rough estimate for a business site with 15–25 plugins and one editor. A WooCommerce store with 60 plugins takes longer. Treat the numbers as a planning floor.

TaskWeeklyMonthlyQuarterlyYearlyHow to verifyTime it takes
Full backup (files + database), stored off the server✓Backup log shows today's date; the file opens and is not 0 KB5 min
Test restore to a staging copy✓Staging loads, you can log in, the latest post and last order are there30–60 min
Core, plugin and theme updates via staging✓Staging passes the smoke test, then production gets the same versions20–40 min
Uptime and SSL expiry✓Monitor shows no gaps; certificate expiry date is more than 30 days out5 min
Forms and email delivery✓A test submission reaches the inbox, not spam10 min
Malware scan✓Scanner report is clean; no unknown files in /wp-content/uploads/15 min
Remove unused plugins, themes and users✓Plugin list matches your inventory; no inactive plugins left installed15 min
404s and broken links✓Search Console and a crawler show no new 404s on linked pages20 min
Speed and Core Web Vitals✓Field data meets LCP ≤ 2.5 s, INP ≤ 200 ms, CLS ≤ 0.120 min
Database cleanup✓Revisions, spam comments and expired transients cleared; database size noted10 min
PHP version check✓Host panel shows a PHP branch still in security support10 min
Roles and 2FA review✓Every admin is a named person; each admin account has 2FA on20 min
Premium license review✓Each paid plugin has an active license and still gets updates15 min
Accessibility spot check✓Key templates pass a keyboard-only walkthrough and an automated WCAG check60 min
Full audit: hosting, plugin inventory, contract✓Written report with decisions, dated3–4 h

Weekly tasks

Weekly work is about catching failures early. Each task is short, yet skipping one for a month is how small problems stack.

Back up files and the database. WordPress documentation says a backup has two parts, the database and the files, and you need both to restore a typical site (WordPress Advanced Administration, Backups, as of September 30, 2026). The same page suggests weekly backups for smaller sites and daily ones for busy sites. It also recommends keeping at least 3–5 recent backups in different locations. One copy on the same server as the site does not count. If the server dies, the copy dies with it.

How to verify: open the backup log and check both the date and the file size. A 0 KB archive is a failed backup that reported success.

Update on staging first. Apply core, plugin and theme updates to a staging copy. Click through the home page, a form, the cart if you have one, and the admin editor. Then repeat the same versions on production. The update routine gets its own section below.

Check uptime and SSL. An uptime monitor pings the site every few minutes and emails you when it fails. Look at the weekly report, not only the alerts. Also check the certificate expiry date. Let's Encrypt certificates are valid for 90 days by default, and Let's Encrypt recommends renewing them every 60 days (Let's Encrypt FAQ, as of September 30, 2026). Auto-renewal can fail quietly after a DNS or server change. A weekly glance costs nothing.

Test forms and email. Submit your own contact form. Check that the email arrived and did not land in the spam folder. Forms break silently after plugin updates and mail provider changes. You find out weeks later, from a lead who never heard back.

Monthly tasks

Monthly tasks check that the weekly ones actually work.

Test a restore. This is the task people skip. Take last week's backup and restore it to a staging copy. Log in and open the newest post. If you run a store, open the last order. WordPress documentation itself advises backing up automatic backups with a manual one once in a while to confirm the process works (same Backups page). A backup you have never restored is a hope. You learn which one it is on the worst day.

Scan for malware. Run a server-side or plugin scanner. Then look at /wp-content/uploads/ yourself. PHP files in the uploads folder are a classic sign of trouble. If the scan finds something, stop the checklist and follow the steps for what to do if the site is hacked.

Prune plugins, themes and users. Deactivated plugins still sit on disk. Their code can still be reached. Delete what you do not use. Remove users who left the company. Keep a short inventory: plugin name, why it exists, who owns it.

Find 404s and broken links. Check the Pages report in Google Search Console and run a crawler over the site. Fix links that point to deleted pages. Redirect old URLs that still get traffic.

Check speed. Google's "good" thresholds are LCP within 2.5 s, INP of 200 ms or less, and CLS of 0.1 or less, measured at the 75th percentile of page loads (web.dev, Web Vitals, as of September 30, 2026). Compare this month with last month. A new plugin or a heavy hero image usually shows up here first. When a metric slips, work through these Core Web Vitals fixes.

Clean the database. Post revisions, spam comments and expired transients grow the database month by month. Take a backup first, then clear them out.

Quarterly and yearly tasks

These tasks change slowly. But when they go wrong, they go wrong for months before anyone notices.

PHP version. WordPress recommends PHP 8.3 or greater, with MariaDB 10.11+ or MySQL 8.0+ and HTTPS support (WordPress.org Requirements, as of September 30, 2026). The same page notes that older PHP still runs WordPress but has reached end of life. On the PHP side, 8.2 gets security fixes until December 31, 2026, and 8.3 until December 31, 2027 (PHP.net, Supported Versions, as of September 30, 2026). A site on PHP 8.2 has one quarter left, so plan the switch now. Test it on staging, since old plugins break on new PHP.

Roles and two-factor authentication. List every administrator. Each one should be a named person, not "admin" or a shared agency login. Downgrade editors who only publish posts. Turn on 2FA for every admin account through a security plugin or your identity provider.

Premium licenses. A paid plugin with an expired license stops getting updates, and often nobody notices for months. Check each license date and who pays for it. Put renewals in a calendar.

Accessibility. WCAG 2.2 is the current W3C Recommendation, published December 12, 2024 (W3C, WCAG 2.2, as of September 30, 2026). Once a quarter, walk key templates with the keyboard only. Run an automated checker on the home page, a service page, a form and the checkout. Automated tools catch only part of the issues. The keyboard test catches more.

Yearly audit. Once a year, write it down: where the site runs, what every plugin does, which theme files were edited, and whether your support terms still fit. This is the document you hand to whoever works on the site next.

Updates without breaking the site: staging, auto-updates, rollback

Updates are where maintenance goes wrong. The fix is a routine, and it has four parts.

Staging. A staging site is a copy of production on a separate URL, blocked from search engines. Many managed hosts create one in a click. Update there first. Run the same smoke test every time: home page, a key landing page, a form, the checkout, the block editor.

Auto-updates. WordPress has applied minor and security core releases automatically since version 3.7 (WordPress.org, Updating WordPress, as of September 30, 2026). Major releases still need a click. WordPress 5.5, released August 11, 2020, added per-plugin and per-theme auto-update toggles in the admin (WordPress 5.5 "Eckstine", as of September 30, 2026).

So when do you switch plugin auto-updates on? A workable rule:

  • Turn on for small, single-purpose plugins with a clean update history and no effect on checkout or forms.
  • Turn on for security plugins, where speed matters more than a rare conflict.
  • Keep off for page builders, WooCommerce and its extensions, membership plugins and anything that touches payments.
  • Keep off if your theme overrides plugin templates. An update can silently outdate them.

Auto-updates run without staging, and that is the trade. You accept a small risk of breakage in exchange for closing a hole faster. Given that 46% of vulnerabilities went public before a fix existed (Patchstack, cited above), speed on the fixes that do exist has real value.

Rollback. Before each update session, take a fresh backup and note the current versions. If production breaks, restore the backup or reinstall the previous plugin version. Write down what broke and why. Next month, that plugin goes on the "staging only" list.

Change log. Keep one line per update: date, component, old version, new version, result. When something breaks three weeks later, the log tells you where to look.

Doing it yourself vs a support contract

Add up the time column. Weekly tasks take about 40–60 minutes, or roughly 3–4 hours a month. Monthly tasks add about 2–2.5 hours. Quarterly and yearly tasks average about 1 hour a month. That puts a small business site at roughly 6–8 hours a month, before any incident. Stores and membership sites need more.

Doing it yourself works when you have a technical person with those hours, and a staging site. It stops working when the checklist slides because a launch took priority. Look at your last three months honestly. Were restores tested? Were updates staged?

If you hand it off, the contract decides what you actually get. The general side of upkeep for any site, and its costs, is covered in general website maintenance costs. For WordPress specifically, ask for these clauses.

ClauseWhat to ask forRed flag
Response and resolution timesSeparate targets per severity: site down, feature broken, cosmeticOne number for everything, or "best effort" only
BackupsFrequency, retention period, off-server location, and a monthly restore test with a report"We keep backups" with no location or restore test
Update policyUpdates go through staging; a named rollback path; a version change logUpdates applied straight to production
Security monitoringScanning frequency, what happens on a detection, who pays for cleanupCleanup excluded or billed at an open rate
Included hoursMonthly hours stated; rate and approval step for anything overUnlimited "small tasks" with no definition
Monthly reportUpdates done, backup and restore status, uptime, scan results, Core Web VitalsNo report, or a report with no numbers
Access and exitAll accounts in your name; credentials handed back on termination within a stated timeThe vendor owns the hosting or domain account

One more test. Ask how the vendor proves a backup works. On our side, the support team checks that a backup can actually be restored before touching anything else. Before the first fix, you get a written audit of the install: hosting limits, plugin inventory, theme edits, error logs and security posture. That document is yours whether or not you continue. The price of ongoing work is an estimate after a brief, based on what the audit finds.

FAQ

How often should I update WordPress plugins?

Check for plugin updates weekly and apply them on staging first. Security releases for plugins you depend on should go out within days. Once a flaw is public, anyone can look for sites that still run the old version. Low-risk plugins can run on auto-update. Page builders, WooCommerce extensions and payment plugins should wait for a staging test before they reach production.

Do I need a staging site for a small WordPress site?

Yes, if the site takes leads or payments. A staging copy lets you test updates, PHP upgrades and restores without risking the live site. Many managed hosts include staging at no extra step. On a brochure site with five pages and no forms, a fresh backup before each update is a workable minimum.

Is my host's backup enough?

Not on its own. Ask your host where its backups are stored and how long they are kept. A copy in the same data center shares the same failure. WordPress documentation recommends keeping 3–5 recent backups in different locations. Keep the host backup, add an off-server copy you control, and test a restore every month.

Which plugins should I avoid installing?

Avoid plugins with no update in the last year, few active installs, or unanswered support threads about security. Also avoid duplicates: two caching plugins or two SEO plugins cause conflicts. Before adding any plugin, write down the job it does and who will own it. If nobody can answer, skip it.

Can I switch on auto-updates for WordPress core?

Minor and security core releases already install automatically on most sites. Major versions still need you to click update, unless you or your host enable them. For major releases, wait a few days, update staging, run your smoke test, and then update production. Keep a fresh backup before every major update.

Top articles ⭐

All categories
Best Web Development Companies in Denver (2026)
Denver’s web development teams offer the best of both worlds: West Coast creativity and Midwest dependability. They’re close enough to Silicon Valley to stay ahead on frameworks and tools, yet grounded enough to prioritize results over hype. Artyom Dovgopol Denver’s web dev scene surprised me. No buzzword rush — just…
October 31, 2025
13 min
920
All categories
Website design for conversion growth: key elements
Your website is a complex ecosystem of interconnected elements, each of which affects how users perceive you, your product, and brand. Let's take a closer look at what elements make websites successful and how to make them work for you. Artyom Dovgopol Web design is not art for art’s sake,…
May 30, 2025
11 min
0
All categories
User account development for business growth
A personal website account is that little island of personalization that can make users feel right at home. Want to know more about how personal accounts can benefit your business? We’ve gathered everything you need in this article – enjoy! Artyom Dovgopol A personal account is your user’s map to…
May 28, 2025
15 min
0
All categories
Website redesign strategy guide
The market is constantly shifting these days, with trends coming and going and consumer tastes in a state of constant flux. That’s not necessarily a bad thing — in fact, it’s one more reason to keep your product and your website up to date. In this article, we’ll walk you…
May 26, 2025
13 min
0
All categories
Rebranding: renewal strategy without losing customers
Market success requires adaptation. Whether prompted by economic crisis, climate change, or geopolitical shifts, we'll explain when rebranding is necessary and how to implement it strategically for optimal results. Artyom Dovgopol A successful rebrand doesn’t erase your story; it refines the way it’s told. Key takeaways 👌 Rebranding is a…
April 23, 2025
13 min
0
All categories
Website development cost 2026: pricing and factors
We've all heard about million-dollar websites and "$500 student specials". Let's see what web development really costs in 2026 and what drives those prices. Artyom Dovgopol Know what websites and cars have in common? You can buy a Toyota or a Mercedes. Both will get you there, but the comfort,…
January 23, 2025
6 min
0
Your application has been sent!

We will contact you soon to discuss the project

Close