Home / Blog / WordPress Maintenance Checklist: Weekly to Yearly Tasks

WordPress Maintenance Checklist: Weekly to Yearly Tasks

A WordPress maintenance checklist is a repeating schedule of small jobs that keep a site safe, fast and visible in Google. Weekly, you take a backup and apply updates safely. Monthly, you test a restore, scan for malware, clean the database and check Search Console.…

WordPress Maintenance Checklist: Weekly to Yearly Tasks

A WordPress maintenance checklist is a repeating schedule of small jobs that keep a site safe, fast and visible in Google. Weekly, you take a backup and apply updates safely. Monthly, you test a restore, scan for malware, clean the database and check Search Console. Quarterly, you audit users, plugins and broken links. Yearly, you confirm your PHP version is still supported and renew licenses and your domain.

That’s the whole answer in one paragraph. The rest of this post is the detail, including the order I do things in and the one rule I never break: backup first, then update, never the other way round.

I’m Mizanur, and my team at Skyranko looks after WordPress sites. Everything below is the routine I’d give any owner who wants to do it themselves.

What Changes Your WordPress Maintenance Schedule?

Not every site needs the same rhythm. Four things decide how often you do each task:

  1. What the site does. A five-page brochure site can live on a monthly routine. A WooCommerce store or membership site that takes orders every day needs daily backups and weekly checks.
  2. How often content changes. A blog that publishes three times a week produces more database bloat, more revisions and more chances for broken links than a site that changes twice a year.
  3. What your host already does. Many managed WordPress hosts run backups, core updates and malware scans for you. Check what’s included before you duplicate it.
  4. How many plugins you run. Every plugin is another thing to update, another thing that can conflict, and another door for attackers. Twelve plugins is a different job from forty.

If your site is a busy store, move every task below up one level. Weekly becomes daily, monthly becomes weekly.

Weekly WordPress Maintenance Tasks

These take me about 20 to 30 minutes on a typical small site, by my own estimate. They’re the ones that prevent real damage.

Take a Fresh Backup Before Anything Else

A WordPress backup has two parts: the files and the database. The official WordPress guide on backups says to back up the database “regularly, and always before an upgrade,” and suggests weekly for smaller sites and daily for busy ones.

Store copies in more than one place. The same guide recommends keeping three to five recent backups, with copies on the server, in cloud storage and on your own computer, which makes sense the first time you watch a hosting account get suspended and realize every backup was sitting inside it. One place is not enough.

Apply Updates the Safe Way

Here’s the routine I follow for core, plugin and theme updates:

  • If you have a staging site, apply updates there first, click through the key pages and forms, then repeat on the live site.
  • If you don’t have staging, update one plugin at a time on the live site, right after a backup, and check the homepage and checkout or contact form after each one.
  • If an update is a major version (say 4.x to 5.0 of a page builder or WooCommerce), read the changelog first and wait a week unless it’s a security fix.
  • If an update fixes a security hole, don’t wait. Apply it the same day.

WordPress can auto-update plugins and themes, and minor core releases update themselves by default. I turn auto-updates on for small, well-maintained plugins and leave them off for the big ones that touch the whole site, such as page builders and ecommerce plugins.

Check That the Site Is Up

Look at your uptime monitor’s weekly report. No monitor yet? Set one up this week, either through your host’s built-in monitoring or a free external service that pings the homepage every few minutes and emails you when it stops answering. You want to hear about downtime from a tool, not a customer.

Monthly WordPress Maintenance Tasks

In my experience, monthly is where most owners drop the ball, because nothing is on fire, the site loads fine, and an hour spent on restores and scans feels like an hour stolen from the actual business. It isn’t optional.

Test a Restore, Not Just the Backup

A backup you’ve never restored is a hope. Once a month, restore your latest backup to a staging site or a local copy and check that pages, images and forms work. The WordPress backup guide also recommends taking a manual backup now and then to confirm your automatic process is actually working.

My estimate: 30 to 45 minutes the first time, 15 once you’ve done it a few times.

Run a Security Scan

Run a malware scan with a security plugin such as Wordfence, or an outside scanner such as Sucuri SiteCheck. Then open Search Console and check the Security issues report. Google flags hacked content there, sometimes before you notice anything on the site.

If a scan finds spam pages or strange redirects, stop the checklist and deal with that first. I cover those two problems in WordPress SEO spam and WordPress hacked redirect.

Clean the Database

Over time the database collects old post revisions, spam and trashed comments, and expired transients. A cleanup plugin can clear these in a few clicks. Always take a backup right before, because a cleanup can’t be undone.

On busy blogs I also limit how many revisions WordPress keeps. Adding define( 'WP_POST_REVISIONS', 10 ); to wp-config.php caps it at ten per post.

Check Search Console

Open the Page indexing report and look for new “Not found (404)” or “Server error (5xx)” pages. Then glance at the Performance report for any sudden drop in clicks. A drop right after an update often points straight at the plugin that caused it.

Quarterly WordPress Maintenance Tasks

Audit Users and Roles

Go to Users and read the list. Remove anyone who no longer works with you, such as old freelancers, former staff and agencies you’ve stopped paying. Then check roles. Most people only need Editor or Author, not Administrator.

When I take over a site, I also look for Administrator accounts nobody recognizes. An unknown admin is one of the clearest signs of a compromise. Ten seconds to spot.

Review Every Plugin and Theme

For each plugin, ask three questions. Do I still use it? Was it updated in the last year? Is there a lighter way to do the same job? Delete what fails instead of just deactivating it, because a deactivated plugin still sits on the server with all its files, and an outdated one can still be attacked even when it’s switched off.

Do the same for themes. Keep your active theme and one default WordPress theme as a fallback, and delete the rest.

Find and Fix Broken Links

Crawl the site with a link checker. Screaming Frog’s SEO Spider crawls up to 500 URLs for free, which covers most small business sites. Fix internal links that return 404 and update or remove dead outbound ones. Search Console’s Not found list helps here too.

Yearly WordPress Maintenance Tasks

Confirm Your PHP Version Is Still Supported

This is the task almost everyone forgets. WordPress’s requirements page recommends PHP 8.3 or greater, and warns that older versions still work but have reached end of life and may expose your site to security problems.

As of September 2026, PHP’s supported versions page lists 8.2 through 8.5 as supported. PHP 8.2 gets security fixes only until 31 December 2026, and 8.3 is also in its security-only phase, until 31 December 2027. Anything below 8.2 gets no fixes at all.

  • If you’re on PHP 8.1 or older, upgrade now. Test on staging first, because old plugins break on new PHP.
  • If you’re on PHP 8.2, plan the move before the end of 2026.
  • If you’re on 8.3 or newer, you’re fine for now. Check again next year.

Your host’s control panel usually has a PHP version switcher. Take a backup before you touch it.

Renew Licenses, Domain and SSL

List every paid plugin and theme license, your domain renewal date and your SSL certificate. An expired premium plugin license usually means no more updates, which quietly turns into a security risk. An expired domain takes the whole site down.

Review Hosting and Performance

Once a year, check your hosting plan against your traffic and run key pages through PageSpeed Insights. If the site has grown, or your pages fail Core Web Vitals, the plan you bought three years ago may no longer fit. Costs for all of this are their own topic, and I break them down in WordPress website maintenance cost.

The Copyable WordPress Maintenance Checklist

FrequencyTaskDone when
WeeklyFull backup (files + database), stored off-serverBackup file exists in two places
WeeklyCore, plugin and theme updates, backup firstAll updates applied, key pages checked
WeeklyUptime report reviewedNo unexplained downtime
MonthlyRestore test on staging or localRestored copy loads and forms work
MonthlyMalware scan + Search Console Security issuesScan clean, no issues reported
MonthlyDatabase cleanup (after a backup)Revisions, spam, transients cleared
MonthlySearch Console Page indexing + PerformanceNo new 404/5xx spikes, no unexplained drop
QuarterlyUsers and roles auditNo unused or unknown admins
QuarterlyPlugin and theme reviewUnused ones deleted, not just deactivated
QuarterlyBroken link crawlInternal 404s fixed
YearlyPHP version checkOn a supported PHP version
YearlyLicenses, domain, SSL renewalsAll renewal dates noted or paid
YearlyHosting and speed reviewPlan still fits traffic

Plain-text version you can paste into a notes app:

WEEKLY
[ ] Backup files + database, copy stored off-server
[ ] Update core, plugins, themes (backup first, staging if you have it)
[ ] Check uptime report

MONTHLY
[ ] Restore latest backup to staging/local and test it
[ ] Malware scan + Search Console > Security issues
[ ] Database cleanup (backup first)
[ ] Search Console > Page indexing + Performance

QUARTERLY
[ ] Remove unused users, check admin roles
[ ] Delete unused plugins and themes
[ ] Crawl for broken links, fix internal 404s

YEARLY
[ ] Confirm PHP version is supported (php.net)
[ ] Renew licenses, domain, SSL
[ ] Review hosting plan and page speed

What If Something Breaks During Maintenance?

It will, eventually. Here’s the branch I follow:

  • White screen or critical error after an update: WordPress usually emails the admin a recovery mode link. Use it to deactivate the plugin that broke, or restore the backup you took ten minutes ago.
  • Site works but a feature is broken: Roll back that one plugin to its previous version, then report the bug to the developer.
  • Scan finds malware: Don’t just delete the flagged file. Hacks usually leave more than one back door, so restore from a clean backup or get a proper cleanup.
  • You can’t log in at all: Check with your host before trying anything else. They can see server logs you can’t.

When Should You Hand WordPress Maintenance to Someone Else?

Doing it yourself works well for a small site with a handful of plugins and an owner who likes a routine. I’d hand it off when the site takes orders or bookings, when downtime costs real money, when nobody on the team is comfortable with staging and restores, or when the site has already been hacked once.

That’s the work my team does under WordPress maintenance, including hacked-site repair. Whether you hire us, someone else or keep it in-house, keep this checklist. It tells you exactly what a good care plan should cover.

Frequently Asked Questions

How Often Should WordPress Be Updated?

Check for updates weekly and apply security fixes the same day they’re released. Minor core releases install automatically by default. For big plugins such as page builders or WooCommerce, test major versions on staging first.

Do I Need a Staging Site for WordPress Maintenance?

It’s not required, but I strongly recommend one for any site that makes money. Many hosts include a one-click staging copy. Without staging, update one plugin at a time right after a fresh backup, and check key pages between updates.

Is a Host Backup Enough on Its Own?

Usually not. Host backups often sit on the same infrastructure as the site and may be kept for only a short time. Keep your own copy in cloud storage or on your computer, and test a restore at least once a month.

Which PHP Version Should My WordPress Site Use?

WordPress recommends PHP 8.3 or greater. As of September 2026, php.net supports 8.2 through 8.5, but 8.2’s security support ends on 31 December 2026. If your host offers 8.3 or 8.4 and your plugins work on it in staging, move up.

Last updated: September 2026 by Mizanur Rahman

Put this guide to work.

Want help applying it? Start with a free audit of your site. We’ll show you what to fix first.

Get a free SEO audit