A yearly WordPress health checklist

Up Speed

Up Speed

Running your site
A yearly WordPress health checklist

Weekly maintenance handles updates and backups. There is another set of tasks that nothing prompts you to do, so they never get done: expiring things, forgotten accounts, plugins nobody has opened in three years.

Block out an afternoon. Work down this list in order. Take a backup before you start and confirm you can restore it.

Access and accounts

Start here, because it is the quickest and it is where the largest quiet risk sits.

  • Read your user list. Go to Users in WordPress and look at every administrator. Remove former staff, former developers, and that agency you stopped working with. Old admin accounts are a common way in.
  • Check the roles. People often get administrator when they only needed editor. Downgrade anyone who does not need full access.
  • Rotate the important passwords. Your admin account, your hosting login, your database password if you can. Into a password manager, not a spreadsheet.
  • Confirm two-factor is on for every account that can change the site. On Up Speed, two-factor login sits on the Professional plan.
  • Check who owns the domain and hosting. Log into both yourself. If you cannot, that is this year's most important finding.

The things that expire

Every one of these fails on a date, silently, and takes your site with it.

  • Domain renewal. Check the expiry date, confirm auto-renew is on, confirm the card on file has not expired. Domains lapse over dead credit cards constantly.
  • SSL certificate. Check the expiry and that renewal is automatic. An expired certificate throws a browser warning that stops traffic dead.
  • Premium plugin and theme licences. An expired licence means no more updates, which turns a paid security plugin into an unpatched liability.
  • Renewal notice email addresses. If registrar and host notices go to a former employee, none of the above will warn you.

The fix: put every one of these dates in a shared calendar with a month's notice. It is the highest-value thirty minutes on this list.

Software you are still carrying

Once a year, take stock of what is actually running.

  • Check your PHP version. Sites routinely run PHP versions that stopped receiving security patches years ago. Your host can tell you, and upgrading is usually straightforward if you test first.
  • Go through every plugin and ask what breaks if it is gone. If you cannot answer, that is your answer. Delete rather than deactivate, so it stops being something to update.
  • Look for abandoned plugins. If the last update was over a year ago, it is a risk regardless of whether it works. Find a maintained replacement.
  • Check your theme. If it is a custom theme built by someone you no longer work with, find out whether anyone can still safely modify it. Discovering the answer during an emergency is worse.

Prove the safety net works

This is the task people skip every single year, and it is the one that matters most.

Actually restore a backup. Not check that backups exist, restore one, somewhere safe. A backup nobody has ever restored is an assumption, and untested backups fail at the exact moment you are depending on them.

While you are there, confirm three things: where the backups are stored (off-site, not on the same server as your site), how far back they go, and how long a restore takes. Malware often sits undetected for weeks, so if your retention is seven days, every restore point you have may already be infected.

The fix: once a year, restore a backup and click through the result. If it does not work, you have found that out on a calm Tuesday instead of during an outage.

The state of the site itself

  • Run a speed test on your homepage and on the page that makes you money. Compare against last year if you noted it. Note it this year if you did not.
  • Clean the database. Old post revisions, spam comments, trashed posts, orphaned metadata from plugins you deleted. Then optimise the tables.
  • Check for broken links. Sites accumulate them as other people's pages move and disappear.
  • Look at Search Console for crawl errors and security warnings you have not noticed.
  • Test your forms. Submit every one and confirm the email actually arrives. Silently broken contact forms are extremely common and cost real enquiries.
  • Search for your site on Google and check the results look right. Injected spam pages show up here before they show up anywhere else.

The problem with a yearly list

A year is a long time for a site to go without attention on the items above. The reason this is a yearly checklist rather than a monthly one is not that the work is only worth doing annually. It is that nobody has time to do it more often.

Which is the honest argument for handing the routine part over. On every Up Speed plan, updates are tested before they go live and rolled back if one fails, scheduled off-site backups run with one-click restore and are tested quarterly rather than annually, malware scanning and 24/7 uptime monitoring run continuously, and database cleanup happens as routine rather than as an annual event. You get a plain-English monthly report of what was done, and if something breaks we fix it rather than emailing you about it.

The access and ownership items stay yours, because they should. Everything else on this list is what the Starter plan turns from a yearly afternoon into background work. If you want to know what shape your site is in first, the free site audit needs no credit card.

Share this post

Start with a free WordPress site audit.

Send us your site and we will check its speed, security, backups, and update status, then write up what we found. A real person does the review.

  • No credit card required

  • No contracts, cancel anytime