The monthly website maintenance checklist we actually run
Twelve checks. Several of them you can do yourself this afternoon.
A monthly maintenance routine should cover uptime, error logs, form and checkout submission, backups with a periodic restore test, dependency and security updates, certificate expiry, Core Web Vitals, search console coverage, analytics integrity, broken links, access review and a written change log.
Key takeaways
- Test a restore, not just the existence of a backup.
- Submit your own contact form monthly — silent form failures are extremely common.
- Check Search Console coverage for pages that dropped out of the index.
- Review who still has access; ex-staff and ex-agency accounts accumulate.
None of this is clever. It is a checklist, and the value is entirely in it being run on a schedule rather than remembered after an incident.
The checklist
- 01Uptime for the month, with any incidents and their causes noted.
- 02Error logs reviewed — a rising error rate usually precedes a visible failure.
- 03Submit the contact form yourself and confirm the email and the CRM record both arrive.
- 04Complete a test purchase if you sell online, including a COD order.
- 05Restore a backup into a scratch environment. Quarterly at minimum.
- 06Apply dependency and security updates, tested in staging first.
- 07Check certificate expiry for every domain and subdomain, including the ones nobody remembers.
- 08Core Web Vitals in Search Console, compared with last month.
- 09Search Console coverage — pages newly excluded or erroring.
- 10Analytics sanity check — is traffic being recorded, are conversions still firing.
- 11Broken links, internal and outbound.
- 12Access review — who has hosting, repository, CMS and analytics access, and should they still.
What to do with it
Write the result down each month, even when everything passes. A change log is what lets you answer 'what changed before this broke' — which is the first question in every incident and the one nobody can answer without notes.