A website maintenance checklist helps you manage the changes that happen after launch, even when nobody plans a redesign. Software updates, new content, tracking scripts and expired information create Digital Drift.
Left unchecked, that drift can weaken security, performance, accessibility and trust. If you leave those changes unowned, your site can drift into broken journeys, security exposure and avoidable support work.
A maintenance schedule makes ownership clear. Adapt the frequency to the site’s risk, complexity and publishing activity rather than treating every task as a rigid calendar rule.
Monthly website maintenance
Check critical journeys
- Submit every contact and enquiry form.
- Test sign-in, search, booking and checkout journeys where applicable.
- Confirm confirmation messages and emails arrive.
- Check key calls to action and phone or email links.
Review security and backups
- Apply security updates promptly through a tested process.
- Review security alerts, failed logins and unexpected account changes.
- Confirm automated backups completed and are stored away from the live server.
- Check that domain, SSL and other renewal dates are monitored.
Watch performance and availability
- Review uptime and server errors.
- Test representative pages with PageSpeed Insights or another consistent tool.
- Investigate material changes in Core Web Vitals, page weight or response time.
- Check mobile layouts and common browsers.
Keep content accurate
- Correct outdated contact details, opening hours, services and team information.
- Fix broken internal and external links.
- Review time-sensitive notices and promotions.
- Confirm privacy and consent information still matches the tools in use.
Quarterly website maintenance
Update the platform safely
You should take a fresh backup and use a staging environment for changes that could affect the site. You should update WordPress core, themes and plugins, then test the critical journeys again. You should remove unused extensions and accounts rather than leaving them dormant.
Automatic updates can be appropriate for low-risk components, but they still need monitoring and a recovery plan.
Review performance and Digital Drag
- Audit large images, video, fonts and third-party scripts.
- Remove duplicate or unused assets.
- Review caching and database health.
- Compare page weight against a defined performance budget.
Check accessibility
Run automated tests, then use the site with a keyboard and screen reader. You should check focus visibility, headings, form labels, errors, colour contrast, zoom and reflow. Informative images need meaningful alt text; decorative images should use empty alt text (`alt=””`).
You can use WCAG 2.1 Level AA as the technical baseline. An automated score does not prove conformance or legal compliance.
Review search and analytics
You should check indexing, crawl errors, titles, descriptions and internal links. You should look for sudden traffic or conversion changes, but investigate the cause before attributing them to maintenance or search rankings.
Annual website maintenance
Complete a broader review of:
- user access, roles and authentication;
- disaster recovery and a tested backup restore;
- hosting capacity, support, DNS and data location;
- content accuracy, duplication and gaps;
- privacy, cookies and data retention with appropriate legal advice;
- accessibility with disabled-user testing where possible;
- navigation, mobile usability and conversion journeys;
- integrations, licences and renewal ownership.
This is also the point to decide whether targeted maintenance can solve current problems or whether the site’s structure now needs deeper design work.
Prepare for incidents, not only routine work
Maintenance should include a written response for common failures. You should record who can take the site offline, contact the host, restore a backup and communicate with affected users. You should keep supplier and domain details somewhere available even when the website or usual collaboration tool is unavailable.
You should test restoration rather than assuming a successful backup notification proves recovery. A useful exercise checks that files, database, configuration and required secrets can be restored to a clean environment. You should record the time taken, any missing dependencies and the date of the next test.
Security incidents may involve personal data. The <a href=”https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/” target=”_blank” rel=”noopener noreferrer”>ICO personal data breach guidance</a> explains assessment and reporting responsibilities. You should obtain appropriate legal or security advice for a real incident rather than relying on a general checklist.
Keep evidence for every maintenance cycle
For each task, record the date, owner, affected area, result and any follow-up. Link changes to a ticket or release note where possible. This creates an audit trail for diagnosing a regression and helps a future maintainer understand why a plugin, integration or configuration exists.
You can use a small representative page set for repeated tests: the home page, a content page, a high-traffic landing page and each critical transaction. Consistent samples make trends easier to see while occasional broader audits catch issues outside the set.
Maintenance is complete only when the change has been tested. After updates, check public pages without an administrator session, verify caches and test on a narrow screen. You should confirm monitoring resumes and that temporary debug settings or staging credentials have not reached production.
Turn the website maintenance checklist into a process
Turn the website maintenance checklist into a working record of who owns each task, when it was completed, what changed and how recovery would work. You should keep credentials in an approved password manager, not in the maintenance document.
You should review the website maintenance checklist when the site, team or risk profile changes. Agnikii DriftGuard is the product that protects updates, security, backups, monitoring and launch-day performance. You can explore sustainable website maintenance if your team needs ongoing support.

