Website maintenance is the routine work that keeps a site available, secure, accurate and useful. It includes more than software updates. A maintained website also has working forms, restorable backups, current business information, monitored renewals and a clear response plan when something fails.
The right maintenance schedule depends on the site. A small brochure site changes slowly; an online shop may change every day and can lose orders if it fails. The process should be proportionate to the commercial impact.
Start with an asset and responsibility list
Record the systems on which the website depends:
- domain registrar and renewal date;
- DNS provider;
- web host or website-builder account;
- business email provider;
- content management system, theme, plugins or apps;
- payment, booking and form services;
- analytics and Google Search Console;
- backup locations;
- licences and subscriptions;
- people and suppliers with administrative access.
Assign a named owner for each maintenance task. “The agency handles it” is not enough unless the contract states what the agency checks, how often, how incidents are reported and what is excluded.
A practical maintenance schedule
| Frequency | Checks |
|---|---|
| Continuous or daily | Uptime alerts, security alerts, failed payments or bookings, and form-delivery problems where these are commercially important |
| Weekly | Review backup success, important forms, orders, bookings, comments or spam, and urgent software updates |
| Monthly | Apply controlled updates, inspect performance and Search Console alerts, test key user journeys and review administrator access |
| Quarterly | Test a restore, review content accuracy, check licences and renewals, audit broken links and assess mobile usability |
| Annually | Review hosting and supplier arrangements, domain ownership, privacy information, disaster recovery, accessibility and the site's continuing business purpose |
Adjust the schedule to the site's rate of change and risk. A high-volume shop may need more frequent backups and release testing. A static site may need fewer content updates, but its domain, hosting, forms and software still require oversight.
Backups: success means you can restore
A useful backup process answers five questions:
- What is being backed up?
- How often?
- Where are copies stored?
- How long are they retained?
- How is restoration tested?
For a database-driven site, back up both files and the database. Keep more than one recovery point so that a recent corrupted or compromised copy does not replace every usable version. Store at least one copy outside the live hosting account and protect backup access with strong authentication.
Test restoration to a safe environment. The test should confirm that pages, images, forms, accounts and essential functions work, not merely that an archive can be downloaded.
Apply updates in a controlled way
Updates fix vulnerabilities and compatibility problems, but an update can also expose a conflict. Use a repeatable process:
- Read the release and compatibility information for significant updates.
- Take or confirm a current backup.
- Test high-risk changes on staging where the site justifies it.
- Apply updates in a controlled order.
- Clear caches if needed.
- Test the home page, navigation, forms, search, checkout or booking journey.
- Record what changed and any issue found.
Do not leave unsupported themes, plugins or server software in place indefinitely. Remove unused software rather than simply deactivating it when it is no longer required.
Monitor security without relying on one plugin
- Use long, unique passwords and multi-factor authentication for important accounts.
- Give each person an individual account and the lowest role they need.
- Review administrator access regularly.
- Protect the domain, hosting and email accounts as carefully as the CMS.
- Keep software supported and updated.
- Monitor unexpected file changes, login activity and security alerts where practical.
- Keep backups inaccessible to ordinary website accounts.
- Prepare contact and recovery information before an incident occurs.
A security scanner can detect some known problems. It cannot guarantee that a site is safe, and it cannot replace account security, patching, reliable hosting and recovery planning.
Test the functions that create business value
A website can appear online while its most important function has failed. Test real journeys:
- submit each contact form and confirm delivery;
- make a safe test booking;
- complete a low-value or sandbox payment where appropriate;
- check confirmation emails and error messages;
- call telephone links from a mobile device;
- test directions, opening hours and location information;
- verify that newsletter or CRM integrations receive the correct data.
Use a monitored recipient address for tests. Do not assume a form works because the website displays a success message.
Maintain performance and mobile usability
Over time, large images, tracking scripts, fonts, plugins and embedded services can make a site slower. Review the pages that matter most rather than chasing one synthetic score.
Check:
- real-user Core Web Vitals data where sufficient data exists;
- page weight and oversized media;
- third-party scripts and tags that are no longer used;
- layout shifts caused by images, adverts or embeds without reserved dimensions;
- mobile menus, tables, forms and sticky elements;
- server errors, timeouts and resource limits.
Performance is one part of the user experience. Do not remove useful content or accessibility features merely to improve a laboratory score.
Keep content accurate
Review content when the business changes, not only on a fixed calendar. Priority items include:
- prices and service descriptions;
- opening hours, addresses and telephone numbers;
- staff and qualification information;
- delivery, returns and cancellation terms;
- privacy notices and cookie information;
- platform screenshots and technical instructions;
- outbound links and cited sources;
- claims such as “latest”, “best” or “2026”.
Show a meaningful last-reviewed date only when someone has actually reviewed the page. Automatically changing dates without checking the content reduces trust.
Review search and indexing
Use Google Search Console to monitor whether important pages can be crawled and indexed, and whether the site has security, manual-action or structured-data issues. A sitemap helps discovery but does not guarantee indexing.
After a redesign, migration or large content update, pay particular attention to:
- 404 errors and broken internal links;
- redirect chains and incorrect redirects;
- accidental
noindexdirectives; - canonical tags pointing to the wrong URL;
- important pages becoming isolated from navigation;
- changes in queries, impressions and qualified enquiries.
Renewals and ownership
Record renewal dates for the domain, hosting, email, platform, theme, plugins, apps and certificates that are not automatically managed. Use payment methods and recovery addresses that the business can maintain when staff or suppliers change.
At least one authorised business representative should be able to access:
- the domain registrar;
- DNS;
- hosting;
- the website administrator;
- backups;
- analytics and Search Console;
- paid software and licences.
Prepare for failure
Create a short incident plan before it is needed. It should state:
- how to confirm that the problem is real;
- who can place the site in maintenance mode or take it offline safely;
- who contacts the host, developer, payment provider or insurer;
- where clean backups and access records are stored;
- how customers will be informed if an important service is unavailable;
- when a personal-data incident may need specialist or regulatory advice;
- how the recovered site will be checked before reopening.
Do not begin by deleting evidence or repeatedly changing the live site. Preserve logs and record actions where a compromise is suspected.
DIY maintenance or a support plan?
DIY maintenance may suit a simple site when someone in the business understands the platform, has time to test changes and can recover the site. Paid support is more sensible when downtime affects sales, the site contains complex integrations or no one internally can perform a restore.
A maintenance agreement should define:
- the sites and services covered;
- the update and backup process;
- monitoring and response times;
- what counts as included work;
- emergency rates and out-of-hours support;
- reporting;
- ownership and handover if the agreement ends.
Monthly maintenance checklist
- Confirm that recent backups completed and remain accessible.
- Review and apply required updates using the agreed process.
- Test the main enquiry, booking or purchase journey.
- Check important pages on a mobile device.
- Review security, uptime and Search Console alerts.
- Remove obsolete administrator access.
- Check expiring domains, licences and subscriptions.
- Record work completed and unresolved risks.
Sources and further guidance
- National Cyber Security Centre: small organisations guide to cyber security (checked 21 July 2026).
- NCSC: Small Business Guide to Response and Recovery (checked 21 July 2026).
- WordPress Advanced Administration Handbook: backups (checked 21 July 2026).
- Google Search Central: get started with Search Console (checked 21 July 2026).
- ICO guidance for small organisations (checked 21 July 2026).
Keep the decision under your control
Retain the relevant accounts, source material, supplier terms and recovery information. Recheck changing prices, interfaces and rules before acting.