Your website launched perfectly. Forms worked. Pages loaded fast. Everything was brilliant.
Then six months passed.
Now your contact form silently fails. A plugin update broke your checkout. Google penalises your site for security vulnerabilities you didn't know existed. And you've lost three months of enquiries because nobody told you the site was down.
This isn't dramatic—it's the reality for thousands of micro-businesses who treat their website like a finished project rather than a living asset.
The truth: A website without monthly maintenance is a ticking time bomb. But the good news? Prevention takes just 30 minutes a month, and this article gives you the exact 7-point checklist that keeps your site secure, functional, and generating leads.
In this guide:
Quick Start (30 Minutes)
The 5-Step Express Version:
- Create and confirm a fresh backup of your entire site (files + database) and verify you can access/download it.
- Apply all system, theme, and plugin updates sequentially (core platform first, then theme, then plugins/extensions).
- Test all critical lead generation elements—submit your contact form, test checkout, click booking links.
- Run a broken link scan using a free online tool or CMS plugin and fix all errors immediately.
- Check your basic page load speed via Google PageSpeed Insights to spot major slowdowns.
✅ Completed the quick version? Move on to How Do I Do a Simple Website Audit Yourself or continue below for the detailed walkthrough that explains why each step matters and how to handle problems.
Complete Step-by-Step Monthly Website Health Check
This is your preventative maintenance routine—the digital equivalent of servicing your car. Skip it, and small problems become expensive emergencies.
The 7-Point Monthly Maintenance Checklist Template
Step 1: Pre-Maintenance Safety Check—Backup Everything
Why this matters: Updates can break websites. Plugins conflict. Themes fail. A backup is your undo button.
What to do:
- Log into your hosting control panel or backup plugin (UpdraftPlus, BackupBuddy, VaultPress, or your host's built-in solution).
- Create a full backup that includes:
- All website files (theme, plugins, uploads)
- Complete database (content, settings, users)
- Verify the backup completed successfully—check the file size (should be several hundred MB minimum for most sites).
- Download a copy to your local computer or confirm it's stored in cloud storage (Dropbox, Google Drive).
- Test restoration access—know how to restore this backup if needed (most hosts have a one-click restore option).
Critical timing: Take this backup before you touch any updates. If something breaks in Step 2, you'll restore this exact version.
Pro tip: Set your backup solution to run automatically every week. This monthly check simply confirms the automation is working and you can access the files.
Step 2: Handle All Software Updates
Why this matters: Outdated software is the #1 cause of website hacks. Security patches are released constantly. Ignoring updates is like leaving your front door unlocked.
The safest update order:
- Core platform first (WordPress core, Wix system updates, Shopify platform)
- Theme second (your design template)
- Plugins/extensions last (one at a time if you're cautious)
What to do:
- Log into your CMS dashboard (e.g., WordPress admin at yoursite.com/wp-admin).
- Navigate to the Updates section (usually Dashboard → Updates).
- Read the update notes—look for any warnings about compatibility or major changes.
- Update your core platform first, then refresh the page.
- Update your theme.
- Update plugins/extensions one by one (or all at once if you're confident).
Where to find core/plugin updates in a typical CMS (e.g., WordPress)
Immediately after updating: Visit your live site in a new browser tab. Click through your main pages. Check your homepage, contact page, and any sales pages. If anything looks broken, stop and restore your backup immediately.
Common update problems:
- •White screen of death → Restore backup, then update plugins individually to identify the culprit
- •Layout breaks → Usually a theme conflict; restore backup and contact theme support
- •Functionality stops working → Restore backup and check plugin compatibility before updating
Step 3: Scan for and Repair Broken Links
Why this matters: Broken links damage your SEO rankings, frustrate visitors, and signal to Google that your site is poorly maintained. Every 404 error is a potential lost customer.
What to do:
- Use a free broken link checker:
- Online tools: Dead Link Checker, Dr. Link Check (paste your homepage URL)
- WordPress plugins: Broken Link Checker (scans automatically)
- Screaming Frog: Free for up to 500 URLs (desktop app)
- Run a full site scan (this takes 2-10 minutes depending on site size).
- Review the report and identify:
- Internal links pointing to deleted pages
- External links to sites that no longer exist
- Images that have been moved or deleted
- Fix each broken link by either:
- Updating the URL to the correct destination
- Removing the link entirely if it's no longer relevant
- Redirecting old URLs to new pages (301 redirects)
For detailed repair instructions, use our dedicated guide to fixing broken links.
Step 4: Test Key Functionality (Forms and E-commerce)
Why this matters: Your website exists to generate leads and sales. If your contact form breaks and you don't notice for three weeks, you've lost three weeks of enquiries. This happens constantly.
What to test:
- Contact forms:
- Submit a test enquiry using a real email address
- Confirm you receive the email within 2 minutes
- Check that the auto-reply (if you have one) sends correctly
- Verify the submission appears in your form plugin's database
- E-commerce checkout:
- Add a product to cart
- Proceed through checkout (use a test payment if possible)
- Confirm order confirmation emails send
- Booking systems:
- Click all booking links
- Verify calendar availability displays correctly
- Test the confirmation process
- Newsletter signup:
- Submit a test email
- Confirm it appears in your email marketing platform
Verification of a successful contact form submission (the "thank you" page)
If your contact form test fails, immediately troubleshoot why your contact form isn't sending. This is a critical failure that costs you money every day it remains broken.
Step 5: Review Security Logs and Spam Folders
Why this matters: Websites are under constant automated attack. Most attacks fail silently, but patterns of failed login attempts or suspicious activity can indicate a targeted breach attempt.
What to check:
- Security plugin logs (Wordfence, Sucuri, iThemes Security):
- Review failed login attempts (10+ from the same IP is suspicious)
- Check for blocked malicious traffic
- Look for file changes you didn't make
- Contact form spam folder:
- Clear out obvious spam submissions
- Check for legitimate enquiries caught by spam filters
- Adjust spam filter sensitivity if needed
- User accounts:
- Review the list of users with admin access
- Delete any accounts you don't recognise
- Confirm all admin accounts use strong passwords
Red flags that require immediate action:
- •50+ failed login attempts in 24 hours → Enable two-factor authentication immediately
- •Unknown admin users → Delete them and change all passwords
- •Files modified that you didn't touch → Run a malware scan
Step 6: Review Page Speed and Performance
Why this matters: Google uses page speed as a ranking factor. More importantly, 53% of mobile visitors abandon sites that take longer than 3 seconds to load. Slow sites lose money.
What to do:
- Visit Google PageSpeed Insights
- Enter your homepage URL and run the test
- Check your scores for both Mobile and Desktop
- Review the main issues flagged (usually images, render-blocking resources, or server response time)
- Set a baseline: Note your current scores (e.g., Mobile: 65, Desktop: 82)
Target scores:
- •Mobile: 50+ (acceptable), 70+ (good), 90+ (excellent)
- •Desktop: 70+ (acceptable), 85+ (good), 95+ (excellent)
If your scores dropped significantly since last month, something changed—usually a new plugin, unoptimised images, or increased traffic. For detailed fixes, see our comprehensive guide to improving site speed.
Quick wins that take 5 minutes:
- •Compress large images using TinyPNG before uploading
- •Enable caching (most hosts offer one-click caching)
- •Remove unused plugins
Step 7: Archive Old Files and Database Bloat
Why this matters: Content management systems save every draft, revision, and deleted item. Over months, this "digital clutter" slows your database and increases backup sizes unnecessarily.
What to clean:
- Post/page revisions:
- WordPress saves every edit as a revision (you might have 50+ versions of one page)
- Use a plugin like WP-Optimize to delete old revisions (keep the last 3-5)
- Trashed items:
- Permanently delete posts, pages, and media files sitting in your trash
- Spam comments:
- Empty your spam folder (no need to keep 5,000 spam comments)
- Unused media files:
- Delete images and PDFs you uploaded but never used
- Use a plugin like Media Cleaner to identify orphaned files
- Database optimisation:
- Run a database optimisation tool (WP-Optimize, WP Rocket) to clean transients and expired data
Caution: Don't delete anything you're unsure about. When in doubt, leave it. This step is about obvious bloat, not aggressive deletion.
For a strategic review of your content performance, see our guide on the content audit and update process.
🎉 Completed? By making this 30-minute routine a habit, you prevent 90% of website catastrophes. You've essentially given your site its monthly service check-up. You're now ready for How Do I Do a Simple Website Audit Yourself, which takes a higher-level strategic view of your site's overall health.
Troubleshooting
What's Next
You've established the critical habit of technical maintenance. Your site is now secure, functional, and stable for the next 30 days.
Immediate next step: How Do I Do a Simple Website Audit Yourself
Now that your technical foundation is solid, run a strategic audit to assess your site's overall health across SEO, content, user experience, and conversion optimisation. This prepares you for the 'Get Found' stage where you'll actively drive traffic.
Go deeper:
- •The Ultimate Small Business Website Audit Guide (2024 Action Checklist) – For a deeper, annual look at your site's strategic performance, use the Ultimate Website Audit Guide.
- •WordPress Website Audit: What to Check – If you are running a WordPress site, this audit provides specific checks for platform integrity.
Other Get Online Guides
Build your foundation:
- •Write Your Homepage in 1 Hour (Template)
- •Choose Your Website Platform
- •Privacy & Cookies: What You Actually Need (UK Guide)
Enhance functionality:
- •Setting Up Your Website for Ecommerce Basics
- •DIY Graphic Design with Canva
- •Template vs Custom Website
You've established the critical habit of technical maintenance. Now that your foundation is secure, the next step is strategic optimisation. NetNav can audit your entire site across all 9 pillars—including SEO, Conversion, and User Experience—in 60 seconds to see what else needs attention beyond basic upkeep. While you're manually checking links and forms each month, NetNav automatically monitors your site's health across technical performance, content quality, accessibility, and conversion optimisation, giving you a prioritised action plan for what to fix next.
Remember: This 30-minute monthly routine is the difference between a website that works and a website that costs you money. Set a calendar reminder for the first Monday of every month, follow this checklist, and you'll prevent 90% of the emergencies that send other business owners into panic mode.
Your website is maintained. Your leads are protected. Your business is secure.