WordPress maintenance checklist: weekly, monthly, quarterly and yearly tasks

By CompatNav · Published · Last reviewed · 3 min read

Short answer

Weekly: backups checked, updates reviewed, the site and its forms tried. Monthly: a restore test, Site Health, error log, plugins no longer maintained. Quarterly: the PHP version and its end-of-life date, a compatibility check for the next PHP version, users and access. Yearly: a full audit and a PHP upgrade plan. The PHP tasks are the ones most checklists leave out, and the ones that break sites when a host moves them.

Every week

Weekly

  • Backups ran, and the latest one has a sensible size (a tiny backup is often a failed one)
  • Updates reviewed: WordPress, plugins, theme (on or off automatically?)
  • Updates applied, on staging first for big ones
  • Site opened as a visitor: home page, a few key pages, the checkout or contact form sent once
  • Logged in to the dashboard: no new warnings at the top

To keep it on paper, print this page: the website’s menus are left out.

Every month

Monthly

  • A backup restored somewhere safe (a staging copy or a local site): a backup you never restored is a guess
  • Tools → Site Health read: critical issues and recommended improvements
  • The PHP error log read, or the WordPress debug log if you keep one: new fatal errors and warnings first
  • Plugins and themes without an update for a long time noted: they are the ones that break on the next PHP version
  • Disk space and database size noted, so growth doesn’t surprise you

To keep it on paper, print this page: the website’s menus are left out.

Site Health groups its findings by severity: “critical issues recommended improvements and passed tests” (wordpress.org). The critical ones go on this month’s list.

Every quarter

This is where most checklists stop, and where PHP upgrades catch agencies out.

Quarterly

  • Each site’s PHP version noted (Tools → Site Health → Info → Server), with its security end date
  • Plugins and theme checked for the next PHP version, while there’s no deadline
  • What will break sent to the plugin authors, or replacements planned
  • Users and access reviewed: old administrator accounts removed, passwords of former staff changed
  • Licences of premium plugins and themes checked: an expired licence means no updates

To keep it on paper, print this page: the website’s menus are left out.

The PHP dates are fixed in advance. php.net’s current table: PHP 8.2 gets security fixes until 31 December 2026, 8.3 until 31 December 2027, 8.4 until 31 December 2028, 8.5 until 31 December 2029 (php.net). A quarterly look tells you which client sites need a plan this year. Which version to aim for is covered in the best PHP version for WordPress.

Every year

Yearly

  • A full audit, as for a new client: the WordPress website audit checklist
  • A PHP upgrade planned and done for every site whose version ends within the year
  • The maintenance plan itself reviewed: hours spent, what took time, what to charge next year

To keep it on paper, print this page: the website’s menus are left out.

Keep a record

Write down, each time, what you checked, what you updated and what you found. It costs a minute per site, and it becomes the client’s monthly report: what to put in a WordPress maintenance report shows a structure clients actually read.

Key takeaways

  • Weekly: check that backups ran, review and apply updates, open the site and try the forms.
  • Monthly: restore a backup somewhere safe, read Site Health and the error log, look for plugins without updates.
  • Quarterly: note each site’s PHP version and its end-of-life date, and check plugins and theme for the next PHP version.
  • Yearly: a full audit, and a PHP upgrade plan for every site before its version runs out of security fixes.
  • Write down what you did each time: it becomes the client’s monthly report.

Frequently asked questions

How often should a WordPress site be maintained?

Updates and backups weekly, health checks monthly, PHP and access reviews quarterly, a full audit yearly. A busy shop or membership site needs the weekly tasks more often.

Should PHP updates be part of a maintenance plan?

Yes. PHP versions get security fixes for a fixed time (php.net lists the dates), and hosts move sites when a version ends. Checking for the next version every quarter means the move is planned, not an emergency.

Can I automate the checklist?

Partly: WordPress can update plugins automatically, WP-CLI can list updates for many sites, and a code check can run on a schedule. Trying the site and reading the results still needs a person.

Check your own site before you upgrade

CompatNav is a free WordPress plugin. It reads the code of your plugins and themes on your own server and tells you, in plain words, what will break and what will only show notices on the PHP version you choose. It never changes your code. It can’t see problems that only appear while code runs with real data, so a quick check of your site after the upgrade still matters.

Get CompatNav on wordpress.org How it works

Sources

About the code examples: each output is the real output of the code shown, run with the official PHP builds, without a php.ini, with all errors reported and displayed. Only the file path was replaced by a neutral server path.