Registered office
20 Wenlock Road
London N1 7GU
Registered office
20 Wenlock Road
London N1 7GU

Use this website maintenance checklist to manage updates, backups, forms, uptime, security, performance, SEO, analytics, content and supplier renewals.
Website maintenance keeps a business site secure, usable, measurable and recoverable after launch. A sensible routine combines monitored updates, tested backups, uptime and form checks, security review, performance work, content accuracy and clear ownership rather than waiting for a visitor to report a failure.
Reviewed: 9 September 2026
| Cadence | Review | Useful evidence |
|---|---|---|
| Continuous | Availability, certificate and security alerts | Owned incident or ticket |
| Weekly | Updates, backups, forms and key journeys | Change and test record |
| Monthly | Performance, links, search, analytics and users | Actions with owners |
| Quarterly | Restore test, content, dependencies and access | Dated review report |
| Annually | Domains, licences, hosting, privacy and roadmap | Renewal and ownership schedule |
Record who controls the domain, DNS, hosting, content management system, analytics, search tools, consent platform, repository and third-party services. Use named accounts, strong authentication and appropriate roles. Remove former staff, agencies and plugins that no longer need access.
Keep a protected recovery route outside the website itself. If the only administrator email uses the affected domain or the only credentials sit with one supplier, an incident becomes harder to resolve.
Protect the database, uploaded media, application files, environment configuration and any custom code needed to rebuild. Monitor backup jobs, keep copies across a suitable failure boundary and test a restore. A hosting snapshot may be useful, but confirm retention, independence and how it is recovered if the hosting account is unavailable.
Update the content management system, extensions, themes, server software and dependencies. Review release notes and security advisories, take or confirm a recovery point, use staging for higher-risk changes, and test the live customer journey afterwards.
WordPress recommends keeping plugins and themes current and advises having a rollback-capable backup before automatic updates. Its auto-update documentation also notes that update scheduling depends on WordPress cron, so notification and failure handling still matter.
Submit contact, quote, booking, signup and checkout forms using controlled test data. Verify confirmation, notification, CRM delivery and error handling. Check phone, email and primary calls to action on mobile as well as desktop.
A form can look correct while mail delivery or an integration fails. Monitor the complete route and maintain a fallback contact method.
Use an external check for important pages and transactions. Alert before TLS certificates and domains expire. Review redirects, DNS and CDN configuration after changes. ACA’s TLS certificate checker provides a point-in-time view of one public endpoint.
Check administrator accounts, failed sign-ins, file changes, security-agent status, unexpected redirects, new users and unnecessary extensions. Review security headers and cookie behaviour in the context of the site. Do not install several overlapping security plugins without understanding which product owns each control.
Use the security headers check as a first look. Results need context because a header suitable for one site can disrupt another.
Measure representative pages on mobile and desktop, monitor server response and watch image, script and database growth. Compare trends after releases rather than chasing one laboratory score. Define image sizes, remove unused code and avoid loading a third-party script on every page when only one workflow needs it.
ACA’s page speed snapshot gives an external measurement that can help identify a practical next investigation.
Check important internal and external links, outdated offers, staff details, opening hours, legal pages and service claims. Redirect retired URLs to a genuine replacement rather than the homepage. The broken link finder can sample a site, but a sample is not a complete crawl.
Confirm indexable pages retain titles, descriptions, canonical URLs, headings, internal links and structured data. Review sitemap coverage and search-console errors after releases or migrations. Update content when the service, evidence or user question changes—not merely to alter a date.
Google recommends people-first, sustainable improvements rather than quick fixes after ranking changes. Use the SEO essentials check for one-page evidence and the sitemap checker for the published URL inventory.
Check that agreed events still fire, referral data is credible and internal traffic or test transactions are handled consistently. Review tags and third-party scripts when marketing tools change. Analytics should answer business questions; collecting unused data adds complexity and privacy risk.
Maintain renewal dates, prices and owners for the domain, hosting, premium extensions, fonts, stock assets, email services and APIs. Record which features fail if a subscription ends. Keep licence terms and source files available for handover.
Record the check date, findings, changes, validation and unresolved risks. Assign a person and target date. A dashboard full of warnings is not maintenance until the business decides what to do.
ACA offers business website design and ongoing care for UK SMEs. The service scope should state who handles updates, content, hosting, recovery and urgent support.
Availability and security alerts may be continuous; updates, backups, forms, content and performance follow separate risk-based schedules. A single annual review is rarely enough for an active site.
No. They reduce delay but still need backups, monitoring, compatibility checks and post-update validation.
Show changes, update and backup results, incidents, performance or security exceptions, tests completed and open actions with owners.