“Maintenance” means very different things depending on who’s selling it — for some providers it’s just running the auto-update button once a month. Here’s what an actual, complete WordPress maintenance routine covers, broken down by how often each task needs to happen.
Daily
- Backups. A full backup — files and database — taken automatically, stored off-server, with enough history that you can roll back further than “yesterday” if a problem goes unnoticed for a few days.
- Uptime monitoring. Something needs to notice within minutes if your site goes down, not whenever a customer happens to mention it.
- Malware and file-change scanning. Automated scans that flag unexpected changes to core files, unfamiliar code injected into themes or plugins, or known malware signatures.
Weekly
- Core, theme, and plugin updates. Checked at minimum weekly — security releases sooner, ideally within 24–48 hours.
- Broken link and 404 checks. Especially after any update, since a plugin change can quietly break a shortcode, form, or page element without throwing an obvious error.
- Comment and form spam review, if your site accepts either.
Monthly
- Performance review. Page load times, image sizes, and database bloat (post revisions, transients, and spam comments accumulate quietly and slow sites down over time).
- User account audit. Review every account with administrator access. Remove anyone who no longer needs it, and confirm you actually recognize every account on the list — an unfamiliar admin user is one of the clearest signs of a compromise that’s already happened.
- SSL certificate check. Most are auto-renewing now, but an expired certificate still happens more often than you’d expect, and it’s a jarring warning page for any visitor who hits it.
- A written summary report. What was updated, what was caught, what’s outstanding — so “maintenance” is something you can actually see happening, not just something you’re told is happening.
Quarterly (or after any major change)
- Restore test. A backup you’ve never actually tried to restore from is a backup you’re merely hoping works. Test it.
- Full security posture review. Login protection, two-factor authentication on admin accounts, file permissions, and whether any installed plugins have gone abandoned by their developers (a plugin that hasn’t been updated in years is a growing liability even if it’s never had a known vulnerability yet).
The most-skipped step on this list: a backup you’ve never tried to restore is an assumption, not a safety net. Set a calendar reminder to actually test a restore at least once a quarter.
The honest version of this list
None of this is exotic. It’s all well-documented, standard practice. The reason sites still fall behind on it isn’t that the checklist is a secret — it’s that consistently executing it, on schedule, for months and years in a row, is a real ongoing job that competes with everything else on your plate. That’s the actual product being sold by a WordPress care plan: not knowledge you don’t have, but a routine you don’t have to personally keep running.
Keep Your WordPress Site Protected
Daily backups, security monitoring, and updates — handled for you, starting at $59/mo.
See Our Care Plans