Skip to content

What Should a Monthly Website Maintenance Checklist Include?

  Posted on 11 Oct, 2026
  Web Applications
What Should a Monthly Website Maintenance Checklist Include?

A monthly website maintenance checklist should include eight things: software updates, backups and a test restore, security, uptime and speed, forms and checkout tested end to end, broken links and Search Console issues, items about to expire, and a short written record of what was done. An owner can do the checking and testing without technical skill. Applying updates, restoring backups and fixing what the checks find need a developer.

The checklist below is written as questions so you can hand it to whoever looks after the site, whether that is an employee, a freelancer or an agency, and ask for a dated answer to each one. Entrant Technologies builds websites, web applications, mobile apps and custom software; our website and web application development services page lists the platforms we work with.

This article covers the monthly routine only. For contracts, support models and what a maintenance fee should cover, see software maintenance and support explained.

What software updates should be checked every month?

Every layer the site runs on should be compared with its official support dates, not just updated when a notice happens to appear. Ask these four questions:

  • Is the CMS core on the current release? For WordPress, the wordpress.org releases page lists 7.1.2, released September 22, 2026, as the latest version and states that only the most recent release in the 7.1 series is actively maintained (checked October 6, 2026).
  • Are all plugins, themes and extensions up to date, and have unused ones been removed?
  • Which language version does the server run, and when does its support end? As of October 6, 2026, php.net shows security support ending on December 31, 2026 for PHP 8.2, December 31, 2027 for PHP 8.3, December 31, 2028 for PHP 8.4 and December 31, 2029 for PHP 8.5. PHP 8.1 and older are no longer supported. WordPress itself recommends PHP 8.3 or greater.
  • If the site is custom built, is the framework version still receiving security fixes according to the framework's own release page?

A site still on PHP 8.2 in October 2026 has under three months of security fixes left, so the upgrade belongs on this month's list. An owner can ask for the version numbers and compare the dates. A developer should apply the updates, on a staging copy first and with a fresh backup taken beforehand.

How do you know the backups actually work?

You only know a backup works when someone has restored it. A backup report that says "completed" proves a file was written, not that the site can be rebuilt from it.

Ask for four answers each month: the date of the last successful backup of both the files and the database, where the copies are stored (it should be somewhere other than the web server itself), how many days of copies are kept, and the date of the last test restore. In a test restore, a developer loads the latest backup onto a separate staging copy, never onto the live site, and confirms that the pages load and that recent orders, enquiries or content are present. An owner can confirm the backup date in the hosting control panel; the restore is developer work.

What security checks belong in a monthly review?

Three checks belong in every monthly review: who has admin access, whether two-factor authentication is on, and what the latest security scan found.

Admin accounts

Read the full list of administrator users on the website, the hosting account and the domain registrar. Remove former staff and past agencies, and make sure each person has an individual login rather than a shared one. An owner can and should do this personally.

Two-factor authentication

Confirm it is switched on for every admin account that offers it, including the email mailbox that receives password resets for the others.

Scan results

Ask for the result of the most recent malware or vulnerability scan from your host or security plugin, and what was done about each finding. Reading the result is an owner task; cleaning up a finding is a developer task.

How do you check the site still works for visitors?

You check by using the site the way a customer would and by reading two or three reports. An owner or office manager can do all of the following:

  • Uptime: read the monitoring report for the month. How many outages were there, how long did each last, and does the alert reach a person who reads it?
  • Speed: compare the site's Core Web Vitals with Google's "good" thresholds: Largest Contentful Paint within 2.5 seconds, Interaction to Next Paint of 200 milliseconds or less, and Cumulative Layout Shift of 0.1 or less, measured at the 75th percentile of page loads (web.dev).
  • Forms: submit every form and confirm the message arrives in the right inbox, not the spam folder, and in the CRM if one is connected.
  • Checkout: place an order through to the confirmation email, then cancel or refund it.
  • Links and search: run a broken-link scan and read any new issues in Google Search Console, especially indexing errors and security notices.

Anything that fails goes to a developer with the page address, the time of the test and a screenshot.

What is about to expire?

Four kinds of item expire quietly and can take a working site offline: the domain, the SSL certificate, paid licences and the payment card behind them. Write down the next expiry date for each.

  • Domain: confirm the expiry date, that auto-renew is on, and that the contact email on the account is one somebody reads. For generic domains such as .com, ICANN's Expired Registration Recovery Policy requires registrars to send at least two renewal reminders, about one month and about one week before expiry. Country-code domains such as .uk or .au follow their own registry's rules.
  • SSL certificate: note the expiry date. Let's Encrypt certificates are valid for 90 days by default (Let's Encrypt FAQ), so they depend on automatic renewal, and that renewal can fail without anyone noticing.
  • Licences: paid plugins, themes, fonts and connected subscriptions. A lapsed licence often means updates stop arriving.
  • Cards on file: the expiry date of the card saved with the registrar, the host and each subscription.

Which items can an owner do, and which need a developer?

An owner can do every item that involves looking, testing or asking; a developer is needed for every item that changes the site or its server.

What an owner can do

Review admin accounts, confirm two-factor authentication, read backup dates, uptime reports and scan results, test forms and checkout, and check expiry dates and saved cards.

What needs a developer

Applying core, plugin, theme, framework and language updates, running the test restore, fixing broken links and Search Console errors that come from templates or redirects, improving speed, and cleaning up after a security finding.

What record should be kept?

One dated page per month: what was checked, the versions before and after each update, what was found, what was fixed and what is still open. Keep it somewhere the owner controls, not only in the developer's ticket system.

What are the common mistakes with monthly maintenance?

The most common mistake is treating maintenance as "click update" and nothing else. Updates applied straight to the live site with no backup and no staging test are the usual cause of a site breaking on maintenance day.

Other mistakes follow the same pattern of assuming instead of checking: trusting auto-renew and automatic updates without confirming they ran, keeping the only backups on the same server as the site, seeing a form's "thank you" message and not checking that the email arrived, sharing one admin login between several people, and keeping no record, so nobody can say what changed before a problem started.

What should you do next?

Send these questions to the person responsible for the site and ask for dated answers by a fixed day each month. In the first month, also ask for a one-page inventory: the registrar, the host, the CMS or framework and its version, the language version, every paid licence, and everyone with admin access.

If nobody can answer a question, that is your first finding. A missing answer about backups or domain ownership matters more than any pending plugin update.

Quick answers

What should a monthly website maintenance checklist include?

It should include software updates, backups with a test restore, a security review, uptime and speed, forms and checkout tested end to end, broken links and Search Console issues, expiry dates, and a written record of what was done.

Can a business owner do website maintenance without a developer?

An owner can do the checks: reviewing admin accounts, reading backup and uptime reports, testing forms and checkout, and tracking expiry dates. Applying updates, restoring backups and fixing faults should be done by a developer on a staging copy first.

Which PHP versions are still supported?

As of October 6, 2026, php.net lists PHP 8.2, 8.3, 8.4 and 8.5 as supported. PHP 8.2 receives security fixes only until December 31, 2026, and PHP 8.1 and older receive none.

How often should a website backup be test restored?

A test restore should be part of the monthly routine. A developer restores the latest backup to a separate staging copy, not the live site, and confirms that pages load and recent data is present.

Why test a contact form if it shows a thank-you message?

The thank-you message only shows that the page accepted the submission. The test is complete when the message arrives in the correct inbox, outside the spam folder, and in the CRM if one is connected.

Conclusion

A monthly website maintenance checklist is a set of questions with dated answers: are the updates within support, do the backups restore, who has access, does the site work for a customer, and what expires next. The owner can ask and test; a developer makes the changes; one page records the result.

If you have no one to hand the list to, or the answers you get back are incomplete, you can contact Entrant Technologies and we will take a look.

Entrant Technologies
Post written by
Entrant Technologies is one of the leading web, software, iPhone & Android app development company which deliver robust results for great brands worldwide. We deliver software solutions that meet the customers and business expectations.
View all posts by Entrant Technologies →
Latest Blogs
 
A monthly website maintenance checklist should include eight things: software updates, backups and a test restore, security, uptime and speed, forms and checkout tested end to end, broken links and Se ...
on 11 Oct, 2026 Read More
 
If your browser says "Your connection is not private" or "Not secure" on a website that worked yesterday, the first thing to suspect is an expired SSL (TLS) certificate. Your content and data are stil ...
on 11 Oct, 2026 Read More
 
You add subscriptions to an online store by installing a subscription app or extension on your platform (or building a custom billing module), connecting it to a payment provider that stores cards wit ...
on 11 Oct, 2026 Read More