Home › Resources › Website Maintenance Checklist
Resources · Checklist

A Website Maintenance Checklist You Can Run Yourself

Five minutes a week and an hour a month will catch most of what goes wrong on a website. This is the checklist we would hand a client who wanted to do it themselves.

The short answer: weekly, confirm the last backup completed and send a test message through your main contact form. Monthly, take a backup, apply updates, then test the visitor path end to end on a phone. Quarterly, restore a backup somewhere safe, review speed, and check your domain, hosting and certificate renewal dates. Yearly, ask whether the site still fits the business, and confirm who holds the domain and hosting logins.

This list is deliberately unglamorous. Most website failures are not dramatic — a form quietly stops sending, a payment method breaks, a page drops out of search. None of those announce themselves. They are found by looking.

Run it yourself and you will catch most of them. If you would rather not, this is also the exact skeleton of every maintenance plan we offer.

Weekly checks (about 10 minutes)

  • Confirm the last backup actually completed. Not that a job is scheduled — that the most recent run finished successfully.
  • Open the site. Home page, plus one page you have not looked at recently. Slow loading and broken layout are easiest to spot early.
  • Send yourself a test message through your main contact form. You will know within a minute whether it still sends.
  • Glance at the store or booking path if you have one — add something to the cart, start a booking, then stop before paying.

Monthly checks (about an hour)

  • Take a fresh backup before you change anything. This is the rule that makes every other step safe.
  • Apply software, plugin and theme updates. Then load the site and click through the pages that matter most.
  • Test the checkout or booking path end to end on a phone, including at least one real order or test payment if your platform supports it.
  • Check a few forms beyond the main one — newsletter, quote request, download gate.
  • Look at the site on a phone over a normal connection, not office wifi. Mobile is where most visitors meet you first.
  • Remove admin users who no longer need access, and check that nobody has added one you do not recognise.
  • Open your analytics for five minutes. A sudden drop in a single page is easier to explain now than in three months.

Quarterly checks (do these properly)

  • Test that a backup can actually be restored. Restore it somewhere safe — a staging copy or a subdirectory. A backup that has never been restored is an assumption, not a safety net.
  • Review speed with a mainstream page speed tool, and check whether your Core Web Vitals are passing on mobile.
  • Check renewal dates for the domain, hosting and SSL certificate. Expiry is the most avoidable outage there is.
  • Review the software you are no longer using. Unused plugins and extensions are update work that keeps generating risk with no benefit.
  • Read the last three months of records and ask what changed. Patterns matter more than single incidents.
  • Confirm your contact details on the domain and hosting accounts are still an email you can access. This is the detail that turns a small problem into an unsolvable one.

Yearly checks

  • Ask whether the site still fits the business. Services change; navigation and content often do not keep up.
  • Check that key pages are usable with a keyboard, and readable with a screen reader or a screen zoomed to 200%.
  • Confirm who holds the domain and hosting logins — in your name, with your email as the recovery contact.
  • Walk the visitor path as a stranger would. Search for what you sell, land on the page you would land on, and see whether the next step is obvious.

The three findings worth acting on today

Most checklist findings can wait a week. Three cannot, because they cost money while they wait and leave no trace:

What you foundWhy it cannot wait
A form has stopped sendingThe page still loads and still shows a thank-you message, so nobody notices. Enquiries are being lost as you read this.
A backup cannot be restoredThe moment you discover this is usually the moment you needed it.
Key pages are missing from searchTraffic falls slowly, and recovery takes longer the longer it runs. Something may be blocking indexing.

For the first two, the fix is usually small. For the third, it is worth checking what changed before reindexing anything. If the site is down or compromised, use emergency support rather than a checklist.

Keep a short record

The step almost everyone skips, and the one that pays off. After each session, write one line: the date, what you updated, what broke, what you tested.

Six months of that turns maintenance from “it seems fine” into something you can look back at — and when a client, a partner or an insurer asks what has been maintained, you have an answer with dates in it.

When doing it yourself stops making sense

DIY is the right answer more often than providers like to admit. It stops being the right answer when:

  • The site takes payments or books work, so an hour of downtime has a price.
  • Nobody in the business would notice a silent failure for weeks.
  • The last two times something broke, it was found by a customer.
  • Updates are being applied without a backup or a test, because there is no time.
  • You have more than one site, or more than one platform, to keep track of.

If none of those apply, keep the checklist and save the money. If several apply, the honest comparison is doing it yourself, a freelancer, a team, or AI tools — and the difference between them is usually accountability, not skill.

Where to go next

Website Maintenance Checklist FAQ

How long does this checklist take each month?

The weekly checks take about ten minutes. The monthly block takes roughly an hour if you apply updates properly and test the visitor path. The quarterly block takes longer, mostly because a restore test takes time to do carefully.

Can I run this checklist if I am not technical?

Yes. Every item is a click or a check, not a code change. The only part that needs care is applying updates, and the rule there is simple: take a backup first, then test after.

What if I find something on the checklist?

Fix it if you can. If it is a broken form, a page missing from search, or a failed restore, those are the three worth acting on quickly rather than noting for later — they all cost money silently while they wait.

Is doing this myself enough, or do I still need a maintenance plan?

For a small brochure site that rarely changes and where being offline for a day costs little, running this checklist yourself is a reasonable decision. A plan makes more sense when the site takes payments, generates leads, or when nobody would notice a failure until it had been running for weeks.

How often should updates actually be applied?

Monthly is a workable rhythm for most sites, with security patches handled sooner if a serious vulnerability is disclosed. Daily updating creates more risk of unverified change than it removes, unless you have staging and testing in place.

Do I need to keep a record of what I checked?

Yes, and it is the step people skip. A short dated note — what was updated, what broke, what was tested — turns “it seems fine” into something you can actually look back at when traffic or orders change.

Would You Rather Not Run This List?

Send the site URL and what you are seeing. We will review it and tell you whether ongoing care is worth it for your site — including when the answer is no.

Describe Your Website Issue Compare Maintenance Plans

Something down right now? Request Emergency Support.