The WordPress maintenance checklist: 27 tasks for agencies
A maintenance plan is only worth something if it is written down. These are the 27 tasks we run across client sites, split by how often they need to happen.
Robin
Most agencies do maintenance well and document it badly. The work happens, but nobody can say exactly what was done last month, which makes it hard to defend your fee and impossible to hand over to a colleague. A written checklist fixes both problems.
This is the list we work from, grouped by frequency. Adapt the intervals to the risk profile of the site: a shop that takes payments daily deserves tighter checks than a five-page brochure site.
Daily, and ideally automated. 1. Confirm the site responds and returns a 200 status. 2. Confirm the TLS certificate is valid and not expiring within thirty days. 3. Confirm the nightly backup completed and is restorable, not just present. 4. Review new critical vulnerability reports for the plugins in your portfolio. 5. Check for unexpected new administrator accounts.
Weekly. 6. Apply plugin and theme updates, starting with security releases. 7. Check the update log for anything that failed or rolled back. 8. Run a malware and file integrity scan. 9. Review server-side PHP errors and fatal errors. 10. Check form submissions actually arrive, including the contact form and any lead form. 11. Empty spam comments and review pending ones. 12. Verify the search function and any critical interactive element still work.
Monthly. 13. Apply WordPress core updates after they have been out long enough to be safe. 14. Update PHP if the host offers a newer supported version and the site is compatible. 15. Test a real restore from backup, on a staging copy, not just in theory. 16. Review site speed on a real page, mobile and desktop. 17. Clean the database: revisions, expired transients, orphaned metadata. 18. Check for broken links and 404s in the logs. 19. Review user accounts and remove people who left. 20. Confirm no plugin has become abandoned or unmaintained. 21. Send the client report.
Quarterly. 22. Review licences and renewal dates for premium plugins and themes. 23. Review the plugin stack itself and remove anything that no longer earns its place. 24. Check the site against the current accessibility baseline for obvious regressions. 25. Review the privacy statement, cookie banner and processing agreements against what the site actually does.
Yearly. 26. Full security audit: file permissions, admin accounts, login protection, exposed endpoints, backup off-site copies. 27. A conversation with the client about what changed in their business and whether the site still matches it.
Two tasks on this list are the ones agencies skip most often, and they are the two that cost the most when skipped. Testing a real restore is the first. A backup you have never restored is a hope, not a safety net. Reviewing abandoned plugins is the second. Most WordPress breaches start with a plugin that stopped receiving updates two years ago and nobody noticed.
The reporting task at the end of each month is not administration. It is the part the client actually sees. Uptime, updates applied, vulnerabilities closed, backups verified: four numbers that justify the invoice without a single meeting.
You do not need to do all 27 tasks by hand. Uptime, TLS, backups, malware scanning, update logs and reporting can run automatically, which leaves your team with the judgement calls: which update is risky, which plugin should go, and what to tell the client.