A workshop pegboard with neatly hung tools, a wall calendar grid with orange check marks, and a teal toolbox on the bench, for a WordPress maintenance checklist.

هذا المقال متوفر باللغة العربية — اقرأ بالعربية

A WordPress site isn’t something you build once and forget. Plugins release fixes, PHP versions reach end of life, certificates expire and forms quietly stop sending. This WordPress maintenance checklist breaks the work into weekly, monthly, quarterly and yearly tasks, so a business site stays secure, fast and working without turning into a full-time job. Use it as is, or hand it to whoever looks after your site.

Why regular maintenance matters for a business site

Most of the problems we fix on client sites didn’t start as emergencies. They started as a skipped update, a backup nobody tested, or a plugin that stopped being maintained two years ago. Small things pile up until one of them takes the site down on a busy day.

Updates are the clearest example. On September 17, 2026, WordPress 7.1.1 shipped as a maintenance and security release with 11 security fixes, and the WordPress team recommended updating immediately. The same announcement repeats a point many owners miss: only the most recent version of WordPress is actively supported. A site that’s a few versions behind isn’t just missing features; it’s missing fixes.

Maintenance also protects things that aren’t technical at all: your domain, your search traffic, and the leads coming through your contact form.

Before you start: backups, staging and a log

Three things make every task below safer and faster. Set them up once.

Backups you can actually restore

The WordPress documentation is clear that a full backup has two parts: the files (core, themes, plugins, uploads, wp-config.php) and the database, which lives separately on the database server. You need both to restore a typical site. It suggests backing up the database first and then the files, and restoring in the opposite order: files first, then the database.

A useful rule of thumb is 3-2-1: three copies of your data, on two different types of storage, with one copy offsite. The WordPress backup guide says much the same thing in plain terms: keep at least 3 to 5 recent backups, stored in different places, for example on the server, in cloud storage and on your own computer. A backup that only lives on the same server as the site disappears with the server.

The step most people skip is testing. The WordPress docs recommend checking automated backups with a manual one now and then to make sure the process actually works. The real test is restoring a backup to a staging site and clicking through it.

A staging site

A staging site is a private copy of your live site where you can try updates and changes first. Many hosts offer one click staging. If yours doesn’t, a local copy works for smaller sites. For stores and membership sites, staging is the difference between finding a broken checkout yourself and hearing about it from a customer.

A maintenance log

Keep a simple log, even a shared spreadsheet, with the date, what was done, versions before and after, and anything odd you noticed. When something breaks three weeks later, the log tells you what changed. It also shows clients or managers that the work is actually being done.

Weekly tasks

  • Confirm backups ran. Check the date of the latest backup and that it was copied offsite, not just that the plugin says “enabled”.
  • Review uptime alerts. An uptime monitor checks your site every few minutes and alerts you when it’s down. Look at any alerts from the week and note patterns, such as downtime at the same hour every night.
  • Check for security releases. Look at the Updates screen in the dashboard. Security releases for core or a plugin you use shouldn’t wait for the monthly round.
  • Test your main conversion path. Submit the contact form and confirm the email arrives. On a store, place a test order or at least add to cart and reach the payment step.
  • Clear spam. Empty spam comments and spam form entries so they don’t pile up in the database.

Monthly tasks

Update core, plugins and themes safely

WordPress gives you several layers of automatic updates, and it’s worth knowing what’s on by default:

  • Minor core releases (security and maintenance, such as 7.1.1 to 7.1.2) update automatically on existing sites by default.
  • Fresh installs created on WordPress 5.6 or later also receive major core updates by default. You can change this on the Updates screen, or with the WP_AUTO_UPDATE_CORE constant in wp-config.php.
  • Since WordPress 5.5, you can turn on auto-updates for each plugin and theme individually. WordPress runs these checks twice a day and emails the site owner after each attempt.
  • Since WordPress 6.6, if a plugin auto-update causes a fatal error on the front end, WordPress rolls the plugin back to the previous version and emails the admin.
// wp-config.php: allow only minor core updates automatically
define( 'WP_AUTO_UPDATE_CORE', 'minor' );

Auto-updates are a good choice for small, well-maintained plugins. For the plugins your business depends on (WooCommerce, payment gateways, page builders, membership plugins), a safer monthly routine is:

  1. Take a fresh backup.
  2. Read the changelog for anything marked as a major change or requiring a database update.
  3. Apply the updates on staging and test key pages, forms and checkout.
  4. Apply the same updates on the live site, then test again.
  5. Write the versions in your maintenance log.

Rollback protection only catches fatal errors. It won’t notice a broken layout or a payment button that stopped working, which is why testing still matters.

Check the Site Health screen

Go to Tools > Site Health. The Status tab groups results into critical issues, recommended improvements and passed tests. Critical items include background updates that aren’t working, a site that can’t reach WordPress.org, errors displayed to visitors, an outdated PHP version and plugins waiting for updates. The Info tab lists your WordPress, PHP and database versions, active and inactive plugins, and directory sizes. Fix anything critical and note the rest in your log.

Security scan and user audit

Run a malware and file integrity scan with your security plugin or your host’s scanner. Then go to Users and check every account with the Administrator, Editor or Shop Manager role:

  • Remove accounts for staff, agencies or freelancers who no longer work on the site.
  • Downgrade anyone who has more access than they need. WordPress roles exist exactly for this, and an Author doesn’t need to be an Administrator.
  • Make sure every admin uses a strong, unique password and two-factor authentication.

If you’ve added AI tools to your site, include their API keys and permissions in this review. Our guide to WordPress AI plugin security covers what to check.

Open Google Search Console once a month and check three reports:

  • Page indexing: look for important pages suddenly marked as not indexed, or a spike in 404 errors.
  • Security issues: Google lists hacked content or malware it has detected on your site here.
  • Manual actions: any penalty applied by a reviewer appears in this report.

Fix broken internal links you find, and add redirects for pages that moved or were deleted but still get traffic.

Quarterly tasks

Check your PHP version

PHP is the language WordPress runs on, and each PHP branch gets two years of active support followed by two years of security fixes only, according to php.net. As of early October 2026, the supported branches are:

PHP branch Active support until Security support until
8.2 31 Dec 2024 31 Dec 2026
8.3 31 Dec 2025 31 Dec 2027
8.4 31 Dec 2026 31 Dec 2028
8.5 31 Dec 2027 31 Dec 2029

WordPress recommends PHP 8.3 or greater. WordPress 7.0 raised the minimum supported version to PHP 7.4, but 7.4, 8.0 and 8.1 have all reached end of life and no longer receive security fixes. If your site is on PHP 8.2, plan the move now, because its security support ends on December 31, 2026. Test the new PHP version on staging first, since old plugins are the usual source of trouble. Your host’s control panel usually lets you switch versions per site.

Remove unused plugins and themes

Deactivated plugins and themes still sit on the server, and their code can still be reached. The Site Health documentation recommends removing inactive themes you don’t plan to use. Delete inactive plugins too, and keep one default WordPress theme as a fallback. While you’re there, check each active plugin’s page on WordPress.org for the last updated date and the “tested up to” version. A plugin that hasn’t been updated in a long time deserves a replacement plan.

Clean up the database

Over time the database collects post revisions, trashed items, spam, expired transients and tables left behind by deleted plugins. After a backup, clean these up with a trusted tool or plugin. You can also limit revisions in wp-config.php. The trash empties itself after 30 days by default, controlled by EMPTY_TRASH_DAYS.

// wp-config.php: keep the last 10 revisions per post
define( 'WP_POST_REVISIONS', 10 );

Performance check

Run your home page, a key landing page and a product or service page through PageSpeed Insights, and check the Core Web Vitals report in Search Console. Compare with last quarter’s numbers in your log. A sudden drop usually points to a new plugin, a heavy image or a third-party script. For Arabic sites in particular, fonts and caching make a big difference; our guide to speeding up Arabic WordPress sites goes through each step.

Do a full restore test

Pick a recent backup and restore it to staging from scratch. Time how long it takes and note any missing pieces. If you can’t restore it, you don’t really have a backup.

Yearly tasks

  • Domain renewal. Check the expiry date, turn on auto-renew, and make sure the registrar has a working email and payment card. Lock the domain against transfers.
  • Hosting renewal. Check the renewal date and price, and whether your plan still fits your traffic and storage.
  • SSL certificate. Certificates are getting shorter. Under the CA/Browser Forum rules, public TLS certificates issued from March 15, 2026 can be valid for at most 200 days, dropping to 100 days from March 15, 2027. Let’s Encrypt also stopped sending expiry reminder emails on June 4, 2025. Confirm that automatic renewal works, and add certificate expiry to your uptime monitoring rather than relying on reminders.
  • Access review. Update passwords and two-factor settings for hosting, the domain registrar, DNS, email and payment gateways, not just WordPress.
  • Stack review. Ask whether your theme, page builder and key plugins are still actively developed, and whether the site still matches how your business works today.
  • Legal and content review. Update the privacy policy, terms, contact details and prices across the site.

WordPress maintenance checklist at a glance

Task How often Where
Confirm backups ran and copied offsite Weekly Backup plugin or hosting panel
Review uptime alerts Weekly Uptime monitor
Apply security releases Weekly or as released Dashboard > Updates
Test forms and checkout Weekly Live site
Update core, plugins and themes Monthly Staging, then live
Review Site Health Monthly Tools > Site Health
Security scan and user audit Monthly Security plugin, Users screen
Search Console, 404s and broken links Monthly Google Search Console
PHP version check Quarterly Site Health Info, hosting panel
Remove unused plugins and themes Quarterly Plugins and Themes screens
Database cleanup Quarterly Database tool, after a backup
Performance check Quarterly PageSpeed Insights, Search Console
Full restore test Quarterly Staging site
Domain, hosting and SSL renewals Yearly Registrar, host, monitoring
Access and stack review Yearly All accounts
Update the maintenance log Every task Shared document

When an update breaks something

Even with staging, something will eventually go wrong. Stay calm and work in order:

  1. Check your maintenance log to see what changed last.
  2. If you can reach the dashboard, deactivate the plugin you just updated.
  3. If you can’t, rename that plugin’s folder over FTP or the hosting file manager.
  4. If the site is still down, restore the backup you took before the update.

For the specific errors, such as the white screen, a 500 error or a database connection error, our guide to fixing common WordPress errors walks through each one.

Frequently asked questions

How long does WordPress maintenance take each month?

For a small business site with a sensible number of plugins, the weekly checks take minutes once they’re a habit, and the monthly round takes longer because of testing. A store with many plugins and custom code needs more time, mostly for testing on staging.

Should I turn on auto-updates for everything?

Not for everything. Auto-updates suit minor core releases and small, well-maintained plugins. For WooCommerce, payment gateways, page builders and anything with custom code around it, update manually after testing on staging.

Is my host’s backup enough?

Treat it as one copy, not your whole plan. Host backups are often stored on the same infrastructure as your site, and restoring may depend on their support team. Keep your own offsite copy and test it.

What happens if I skip maintenance for a few months?

Usually nothing visible at first, which is the problem. Then several updates arrive at once, some of them conflict, and you’re dealing with security fixes, a PHP upgrade and plugin changes together. Small regular steps are much easier than one big catch-up.

A final word

Maintenance is boring when it’s done well, and that’s the point. A short weekly routine, a careful monthly update day and a few bigger checks each quarter and year keep a business site out of trouble. If you’d rather not handle it yourself, our SiteCare plan takes care of backups, updates, monitoring and fixes for you. Not sure what your site needs? Book a free consultation and we’ll go through it together.

References