Maintenance

What WordPress Maintenance Includes (and What Most Plans Skip)

What real WordPress maintenance includes: safe updates, tested backups, security checks, speed, accessibility and a measured plan to reduce technical debt.

WordPress maintenance is the ongoing work that keeps a site secure, fast, working and cheap to change. Real maintenance includes tested updates, backups you know you can restore, security and uptime monitoring, speed and accessibility checks, and a plan to remove old code before it causes problems. Many plans only cover the first item, and that gap is where most expensive surprises come from.

This guide lists what a complete maintenance plan should include, how often each task should happen, and the questions to ask before you hire someone.

Why maintenance matters more than it used to

A typical business site runs WordPress core, a theme, 20 to 40 plugins, a PHP version on the server, and a database. Each of these parts gets updates on its own schedule. Each update can fix a security hole, and each update can also break something.

On top of that, every part has a support window. PHP versions stop getting security fixes on a published schedule (see the PHP supported versions page). Plugins get abandoned. Themes stop being updated. A site that “works fine” today can be several years behind without anyone noticing.

We think of this as technical debt: work you skipped in the past that you will pay for later, with interest. Good maintenance does not just keep things running. It measures that debt and pays it down on purpose. We explain how in our guide to measuring WordPress technical debt.

The core tasks of WordPress maintenance

Here is what we believe every maintenance plan should cover. If a provider leaves any of these out, ask why.

1. Updates done safely

Updates are the most visible task, and the one most often done badly. A safe update process looks like this:

  1. Take a fresh backup.
  2. Apply updates to a staging copy of the site first.
  3. Run checks: key pages load, forms submit, checkout works, no new PHP errors.
  4. Apply the same updates to the live site.
  5. Check the live site again and keep the backup ready.

WordPress has supported automatic updates for plugins and themes since version 5.5. Auto-updates are useful for low-risk items. But for the plugins that run your business, such as forms, payments, memberships or anything with custom code, we test first. We cover the full process in how to update WordPress safely with staging and automated tests.

2. Backups you have actually restored

Almost every plan says “daily backups.” Fewer plans test them. A backup you have never restored is a guess, not a backup.

A complete backup setup includes:

  • Files and database together, taken at the same time so they match.
  • Off-site storage, not only on the same server as the site.
  • Retention, so you can go back weeks, not just one day. Some problems, like malware, are found long after they start.
  • Restore tests on a regular schedule, to a separate environment, with a check that the restored site works.

The WordPress documentation has a good overview of what to back up and why.

3. Security monitoring and hardening

Security work splits into two parts: watching for problems and making them less likely.

Monitoring includes:

  • Scanning for known vulnerable plugin and theme versions.
  • Checking core files against official checksums. WP-CLI, the WordPress command line tool, has a verify-checksums command for this.
  • Watching for new admin accounts, changed files and unusual login activity.
  • Checking whether the domain shows up on blocklists.

Hardening includes removing stale admin accounts, enforcing strong passwords and two-factor login, limiting file editing from the dashboard, and closing endpoints the site does not need. We keep a full list in our WordPress security hardening checklist.

4. Uptime and error monitoring

Someone should know the site is down before your customers do. Uptime checks every few minutes, with alerts to a real person, are standard.

Less common, but just as important, is error monitoring. PHP warnings and fatal errors in the logs often show up weeks before something visibly breaks. We read error logs as part of every maintenance cycle, not only when something goes wrong.

5. Server and PHP version checks

Your site depends on software outside WordPress: PHP, the database server (MySQL or MariaDB), and the web server. Each one has an end-of-life date, after which it no longer gets security fixes.

Maintenance should track these versions against the official WordPress requirements and plan upgrades before support ends, not after. A PHP upgrade is a project of its own, because old plugins and custom code can fail on newer versions. Our guide on upgrading PHP safely walks through it.

6. Speed checks

Sites get slower over time. New plugins add scripts. Images get uploaded at full size. The database grows. Maintenance should catch this before it hurts sales or search rankings.

We track Google’s Core Web Vitals, which measure loading speed (LCP), responsiveness (INP) and visual stability (CLS). We also watch page weight and slow database queries. Google explains these metrics at web.dev, and we go deeper in our Core Web Vitals guide for WordPress.

7. Database care

The WordPress database collects clutter: post revisions, expired temporary data, leftover tables from deleted plugins, and settings that load on every page even when they are not needed. A bloated database slows down every request.

Maintenance should check database size and the amount of data loaded on each page, and clean it up when needed. We describe that process in cleaning up a bloated WordPress database.

8. Accessibility checks

Every update to a theme, page builder or plugin can change your markup. A form that worked with a screen reader last month may not work today. Maintenance should include automated accessibility scans against WCAG 2.2 (the current standard from the W3C), plus a manual check of key pages and forms after major changes.

9. Plugin and theme review

This is the task most plans skip. Every few months, someone should look at each plugin and ask:

  • Is it still maintained? When was its last release?
  • Is it still needed, or did a past project leave it behind?
  • Does it overlap with another plugin?
  • Is there a lighter or better-supported option?

Removing one abandoned plugin can do more for security and speed than a year of routine updates.

10. Reporting

You should get a plain report each month. It should say what was updated, what was found, what was fixed, and what needs a decision from you. If you cannot tell what you are paying for, the plan is not working for you.

How often each task should happen

Schedules vary by site, but this is a reasonable starting point for a business site.

TaskFrequency
Security updatesWithin days of release
Routine plugin, theme and core updatesWeekly or every two weeks
BackupsDaily, more often for busy stores
Backup restore testMonthly or quarterly
Uptime monitoringEvery few minutes
Error log reviewWeekly
Speed and Core Web Vitals checkMonthly
Accessibility scanMonthly, and after major changes
Plugin and theme reviewQuarterly
PHP and server version reviewQuarterly
Technical debt score updateQuarterly

Online stores, membership sites and sites with many custom features need more frequent checks than a simple brochure site.

What “basic” maintenance plans usually leave out

Many low-cost plans run bulk updates on a schedule and send a report. That is better than nothing. But it often leaves out the parts that prevent real damage:

  • No staging test. Updates go straight to the live site.
  • No restore test. Backups exist, but nobody knows if they work.
  • No error log review. Problems build up silently.
  • No custom code coverage. If your site has custom plugins or theme code, nobody checks them after updates.
  • No plan for old parts. Abandoned plugins and old PHP stay in place until they fail.

That last point is the expensive one. When nobody plans upgrades, they happen as emergencies, usually at the worst time.

Maintenance and technical debt

Routine maintenance keeps the site where it is. Reducing technical debt makes it better over time. We treat both as part of the same job.

We measure debt in six areas:

  • Outdated or abandoned plugins and themes.
  • PHP, database and server versions past their support window.
  • Custom code with no automated tests.
  • Speed: Core Web Vitals, page weight and slow queries.
  • Accessibility errors against WCAG 2.2.
  • Security exposure: stale admin accounts, leaked keys, open endpoints and missing hardening.

Each area gets a number. Each quarter, the number should go down. That gives you a simple way to see whether your maintenance is improving the site or just keeping it alive. If the scores are high, a one-time technical debt audit is a good place to start before choosing a maintenance plan.

Questions to ask a maintenance provider

Before you sign up, ask these questions. Clear answers are a good sign.

  1. Do you test updates on staging before applying them to the live site?
  2. How often do you test restoring a backup?
  3. Where are backups stored, and how long are they kept?
  4. Do you read PHP error logs? How often?
  5. What happens if an update breaks the site? How fast do you respond?
  6. Do you check custom code and custom plugins after updates?
  7. Do you track PHP and server versions and plan upgrades?
  8. Do you check accessibility and speed, or only updates?
  9. What does the monthly report include?
  10. Who has admin access to my site, and how is it secured?

Can you do maintenance yourself?

Yes, for a simple site with a few well-known plugins. You will need a staging site, a backup tool you have tested, and a regular slot in your calendar. Start with the update process above and the security checklist.

It gets harder when the site has custom code, a store, a membership system, or many integrations. Then each update carries more risk, and you need someone who can read error logs, debug a conflict and roll back quickly.

Getting help with WordPress maintenance

If you want maintenance that tests updates before they go live, restores backups on a schedule and lowers your technical debt over time, take a look at our WordPress maintenance service. We start with an assessment of your site and give you a fixed quote. You can contact us to get started.

Frequently asked questions

What does WordPress maintenance include?
Real maintenance covers tested updates for core, plugins and themes, backups you have restored at least once, security monitoring, uptime checks, speed and accessibility checks, and a plan to replace outdated parts of the site before they break.
How often should a WordPress site be maintained?
Security updates should be applied within days of release. Most sites also need a weekly update cycle, monthly checks on speed and errors, and a quarterly review of plugins, PHP version and technical debt.
Is clicking Update All in the dashboard enough?
No. Updating without a backup, a staging test and a check afterward is how many sites break. Updates are only one part of maintenance, and they need a safe process around them.
Can I just turn on WordPress auto-updates?
Auto-updates help for minor core releases and low-risk plugins. For plugins that handle payments, forms, memberships or custom code, we recommend testing updates on staging first.

Is your WordPress site hacked, slow or at legal risk?

Tell us what you're dealing with. We'll reply within one business day.