Skip to content
WordPress 3 min read Sajid Aslam

WordPress Maintenance: What Should Be Checked Every Month?

What a monthly maintenance routine should actually cover, and why the item everyone skips is the one that matters most.

Monthly WordPress maintenance task list

Short answer

Monthly: core, theme and plugin updates applied on staging first; a restore test; a security scan; uptime and error log review; a performance spot check; and a look at form submissions to confirm enquiries are still arriving. The restore test is the one most often skipped and the one that matters most.

Maintenance plans are easy to sell and easy to under-deliver, because most of the work is invisible when it is going well. Here is what should actually be happening.

Every month

Updates, on staging first

Apply WordPress core, theme and plugin updates to staging. Look at the site. Then apply to live.

The order matters. Applying straight to live and discovering a conflict means your customers found it before you did.

Take a backup immediately before the live pass, every time, with no exceptions.

Test a restore

The item that gets skipped, and the only one that determines whether any of the others matter.

Restore last night's backup to staging and confirm the site comes up with the content intact. A backup that has never been restored is an assumption, and the day you need it is the worst possible day to discover it was wrong.

Monthly is a reasonable cadence. Quarterly is the absolute minimum.

Security scan

Run a malware and integrity scan. Review:

  • Admin users — is anyone there who should not be?
  • Failed login attempts — a sudden spike means someone is trying
  • File changes in core directories that you did not make
  • Plugins with published vulnerabilities

Uptime and error logs

Check uptime for the month and look at the PHP error log. Recurring warnings are a fault developing in slow motion — much cheaper to address before it becomes an outage.

Performance spot check

Run your two or three most important URLs through a performance test on a mobile profile. You are looking for drift, not perfection. A gradual slide usually means images being uploaded at full size or a plugin that has grown.

Check Search Console's Core Web Vitals report as well — that is real user data rather than a lab simulation.

Confirm enquiries are arriving

Submit the contact form. Confirm the email arrives. Check the spam folder.

This sounds trivial. Silent form breakage is one of the most expensive faults a business website has, because nothing looks wrong — the form still submits, the success message still shows, and the enquiries simply stop. Nobody notices for weeks.

Scan for internal 404s. They accumulate quietly whenever content is renamed or removed.

Every quarter

  • Full plugin audit — is everything installed still needed and still maintained?
  • Check PHP version against what is currently supported
  • Review user accounts and remove anyone who has left
  • Check SSL certificate expiry and auto-renewal
  • Review analytics for pages that have quietly stopped receiving traffic

Annually

  • Domain renewal — confirm it is set to auto-renew and the card on file is valid
  • Paid plugin and theme licence renewals
  • Hosting plan review against actual usage
  • Full accessibility check
  • Review whether the site still matches what the business does

What a maintenance plan should include

If you are paying someone for this, the plan should cover:

ItemFrequency
Core, theme and plugin updatesMonthly, staging first
Off-site backupsDaily, retained at least 30 days
Restore testMonthly or quarterly
Security monitoringContinuous
Uptime monitoringContinuous
Performance checkMonthly
Error log reviewMonthly
Support responseDefined, in writing

The website maintenance service covers this from £99/month, and WordPress security and maintenance sets out how the routine runs.

Doing it yourself

Entirely reasonable for a simple site. The essentials, in order:

  1. Automatic backups to somewhere other than your hosting account
  2. Automatic WordPress core security updates
  3. A monthly calendar reminder for plugin updates
  4. Uptime monitoring — free tiers are fine
  5. A quarterly restore test

Those five cover most of the risk. What you are buying with a paid plan is someone noticing before you do, and knowing what to do next.

Worked examples

Related services

Related reading

FAQ

Questions about this

If yours isn't here, send it over — I reply within one working day.

For WordPress core security releases, yes — those are low risk and should be automatic. For plugins and major versions, automatic updates trade one risk for another: you avoid running vulnerable code, but an update can break the site at 2am with nobody watching. The middle ground is automatic security updates plus a monthly reviewed pass on everything else.

Usually nothing, right up until it matters. The risk is cumulative: outdated plugins accumulate known vulnerabilities, an eventual forced PHP upgrade breaks something that has been untouched for months, and the backup nobody tested turns out not to work. The cost of neglect arrives all at once.