BlogWordPress
WordPress Maintenance Checklist: Weekly, Monthly and Quarterly Tasks
Rustam7 min read
A WordPress site needs a quick look every week, a proper update-and-test session every month, a deeper check every quarter, and a short review once a year. Weekly is about spotting problems: security notices, failed backups, downtime. Monthly is where updates, testing and speed checks happen. Quarterly is for restore tests, PHP versions and user accounts.
This is the routine I follow on the sites I look after. It isn't the only way to do it, but every task is on here because skipping it has a predictable cost.
Why plugins deserve most of your attention
Patchstack's State of WordPress Security in 2026 report counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025, and 91% of them were in plugins. Themes made up 9%. WordPress core had only six, all low priority.
Two other findings in the same report shape how I schedule updates. Patchstack found that 46% of vulnerabilities were not fixed by the developer by the time they were publicly disclosed. And for heavily exploited vulnerabilities, the median time from disclosure to mass exploitation was five hours.
In practice that means two things. Most of your risk sits in the plugin list, so keep it short. And a security fix for a plugin you use can't always wait for your monthly session.
Weekly tasks (15 to 20 minutes)
Weekly is mostly about looking, not changing.
Start with security notices. Check whether any plugin or theme you run has a disclosed vulnerability. A security plugin, Patchstack, or your host's dashboard will flag these. If a fix is out for a serious issue, I apply that single update straight away (after a backup) instead of waiting for the monthly batch.
Then confirm the backups actually ran. Don't trust the green tick on the plugin dashboard. Open the backup destination (Google Drive, Dropbox, your host's backup area) and check that this week's files exist and aren't suspiciously small.
Check uptime alerts and the hosting dashboard. Look for downtime, unusual CPU or bandwidth spikes, and disk space creeping towards the limit. Disk space is the one that quietly stops backups from running.
Finally, submit your main forms. Contact forms are the thing that breaks silently. If the form sends to an inbox, make sure the test email actually lands and isn't in spam.
Monthly tasks (1 to 2 hours)
This is the main maintenance session. Do it on a fixed day so it actually happens.
Back up first, then update on staging
Take a full backup (files and database) before you touch anything. Then run updates on a staging copy, not the live site. Most decent hosts offer one-click staging. If yours doesn't, that's worth fixing.
Update in a sensible order: WordPress core first, then the page builder and its add-ons, then everything else, then the theme. Read the changelogs for anything with a major version jump. "Database update required" or "minimum PHP version raised" in a changelog means slow down.
Test what matters, not every page
After updating staging, check the homepage, one page of each template type (blog post, service page, product), the header and footer on mobile, every form, and checkout if you have one. If all of that works, push the same updates to live and repeat a quicker version of the check there.
If something goes wrong on live anyway, my guide to recovering when a WordPress update breaks your site walks through it step by step.
Plugin audit
Look at the plugin list with fresh eyes. Deactivated plugins should be deleted, not left sitting there. Look for plugins with no update in a year or more, and two plugins doing the same job (it happens a lot with caching and SEO plugins). Every plugin you remove is one less thing to update and one less thing to be exposed.
Speed and errors
Run your key pages through PageSpeed Insights or Lighthouse and compare with last month. You're looking for a sudden drop, not a perfect score. Check Google Search Console for new crawl errors, 404s and Core Web Vitals warnings, and scan for broken links.
Spam and database clean-up
Empty spam comments, clear old post revisions if there are thousands, and delete expired transients. Most optimisation plugins do this in one click. Do it after the backup, never before.
Quarterly tasks (2 to 3 hours)
Test a restore
This is the task almost everyone skips, and it's the one that matters most. Restore a recent backup to a staging site and check that it loads properly. Until you've done that, you don't really know if your backups work.
Check the PHP version
WordPress.org currently recommends PHP 8.3 or greater and notes that older versions have reached end of life. Check what your host is running. If you're behind, test the newer version on staging first, because old plugins and themes are what usually break.
Review user accounts
Remove admins who no longer need access: the old developer, the agency you stopped using, the intern from last year. Downgrade anyone who only writes content to Editor or Author. Make sure every remaining admin uses a strong unique password and, ideally, two-factor login.
Content and SEO review
Check that opening hours, prices, team pages and contact details are still true. Look in Search Console for pages that dropped in clicks. Outdated content isn't a security issue, but it costs you enquiries.
Yearly tasks
Once a year, check the renewal dates for the domain, SSL (if it isn't automatic), hosting and premium licences. An expired licence often means no updates, and on an Elementor or Crocoblock site that becomes a security problem quickly. I cover that in more detail in maintaining an Elementor website.
It's also worth checking that the domain is registered in the business's name and that you can log into the registrar yourself.
How often should WordPress plugins be updated?
My short answer: security fixes as soon as possible, everything else in a monthly batch on staging.
Waiting a few days on a big feature release is reasonable, because early bugs tend to surface quickly. Waiting on a security patch is not, given Patchstack's five-hour median for heavily exploited flaws.
Since WordPress 6.6, failed plugin auto-updates can roll back on their own. The merge proposal explains that WordPress checks the homepage for a PHP fatal error after an auto-update and restores the previous version if it finds one. That's a useful safety net, but it only catches fatal errors that show up on that check. A broken form, a layout bug or a checkout problem on another page won't trigger it. I treat auto-updates as acceptable for small, well-maintained plugins and keep page builders, WooCommerce and anything business-critical on manual, tested updates.
The checklist, ready to copy
Weekly: security notices checked and urgent fixes applied · backups confirmed at the destination · uptime and hosting dashboard checked · main forms tested.
Monthly: full backup · updates on staging in order (core, builder and add-ons, other plugins, theme) · key pages, forms and checkout tested · updates pushed live and spot-checked · unused plugins removed · speed and Search Console checked · spam and database cleaned.
Quarterly: backup restore tested on staging · PHP version checked · user accounts reviewed · content and contact details reviewed.
Yearly: domain, hosting, SSL and licence renewals checked · domain ownership confirmed.
If you'd rather not do this yourself
Done properly, this routine takes a few hours a month, and most of them land on a day when you'd rather be working on the business. That's what my website maintenance plans cover: updates every month, fixes and changes handled weekly, backups, security monitoring and speed work. I don't publish fixed prices yet because sites vary so much, so send me your site address and I'll suggest a plan that fits it.
FAQ
What does WordPress maintenance include?
At a minimum: core, theme and plugin updates, backups stored off the server, security monitoring, uptime monitoring and checks that forms and key pages still work after updates. Better plans add staging, restore tests, speed work and content edits.
How long does WordPress maintenance take each month?
For a typical small business site, the routine above takes roughly one to two hours a month for updates and testing, plus 15 to 20 minutes a week for checks. Sites with WooCommerce or many plugins take longer.
Should I turn on WordPress auto-updates?
For minor plugins that rarely cause trouble, auto-updates are reasonable, especially since WordPress 6.6 can roll back a plugin auto-update that causes a fatal error. Keep your page builder, WooCommerce and other critical plugins on manual updates tested on staging first.
What is the most important WordPress maintenance task?
Testing that your backups restore. Updates and security scans reduce the chance of a problem, but a working backup is what gets you out of one.