A website can look normal while quietly losing leads. A form notification stops arriving. A booking embed expires. A phone number is wrong on one location page. A plugin update breaks the mobile menu. Maintenance should detect those failures before another redesign is discussed.

The cadence below is a starting risk model, not a universal service contract. A brochure site with one contact form and a high-volume ecommerce store should not receive identical maintenance. Increase frequency when a failure affects revenue, safety, privacy, or a regulated workflow.

First, create an ownership register

List the domain registrar, DNS provider, hosting account, content platform, source repository, analytics property, Search Console property, email sender, form destination, booking system, payment provider, consent tool, fonts, plugins, and third-party embeds. Record the business owner, technical owner, billing owner, renewal date, and recovery method for each.

Do not store passwords inside the checklist. Use an approved password manager and make sure the business—not only a former contractor—controls recovery. Enable multifactor authentication where supported. Confirm that emergency access does not depend on one employee's personal email.

This register answers the question that turns a minor outage into a crisis: who can change the system right now?

Weekly or continuous checks

  • Uptime and certificates: monitor public availability and HTTPS errors.
  • Primary conversion paths: submit the contact or quote form, place a test booking where practical, tap the phone link on mobile, and verify the confirmation state.
  • Lead delivery: confirm the submission reached the correct inbox, CRM, calendar, payment system, or notification channel.
  • Critical pages: check Home, the primary service or product, Contact, Booking, and Checkout on a real phone.
  • Security and platform alerts: review urgent notices from hosting, the CMS, plugins, payment providers, and domain services.

Use a synthetic submission clearly labeled as a test and remove it from sales metrics. A green form success message is not proof that the lead reached the team.

Monthly checks

  1. Apply supported updates. Review release notes and compatibility, back up first, update in a controlled order, then retest critical paths. WordPress publishes separate guidance for core updates and plugin and theme auto-updates.
  2. Verify backups. Confirm recent database, media, configuration, and code backups exist where relevant. WordPress's backup guidance explains why both database and files matter.
  3. Review analytics health. Check that real-time or recent visits are recorded, key events still fire, internal traffic is handled consistently, and sudden drops have an explanation.
  4. Inspect Search Console. Look for indexing, security, manual-action, structured-data, and crawl warnings; compare queries and landing pages without reacting to every small fluctuation.
  5. Check broken destinations. Test prominent internal links, downloads, map links, social profiles, booking links, and third-party embeds.
  6. Review business facts. Verify hours, service areas, prices, staff, licenses where published, and current offers.

Quarterly content, SEO, and accessibility audit

Inventory indexable pages with their purpose, primary audience, last review date, organic entrances, important internal links, and intended action. Flag pages that repeat another URL, have no owner, or no longer represent the offer.

Review the path from informational articles to commercial pages. Google recommends a logical structure and linking important pages from relevant pages with concise anchor text. Use the Google sitelinks guidance as a simple internal-linking standard.

Test keyboard navigation, visible focus, headings, labels, error messages, alternative text, zoom, and color contrast on representative pages. Accessibility is an ongoing quality practice, especially after content and component changes. The W3C WCAG overview organizes the underlying requirements.

Measure important templates with field and lab data. Current Core Web Vitals cover loading performance, interaction responsiveness, and visual stability; web.dev explains the metrics and thresholds. Diagnose a regression by template and resource rather than chasing one score.

Annual business and recovery review

  • Verify domain, hosting, platform, plugin, app, and email renewals and remove unused subscriptions.
  • Review administrative users, agency access, API keys, integrations, forwarding addresses, and former staff accounts.
  • Run a documented restore exercise for systems where downtime or data loss would materially harm the business.
  • Review privacy, terms, cookie or consent behavior, accessibility statements, warranties, returns, and regulated disclosures with appropriate professionals.
  • Compare the current site architecture with the real service mix and customer questions.
  • Confirm the source files, design assets, copy, photography, analytics, and domain remain accessible to the business.

An annual review is also the right time to decide whether the platform still fits. Do not migrate merely because another builder is fashionable. Migrate when ownership, editing, performance, integrations, security support, or total operating cost creates a documented constraint.

Use a small change-management process

  1. Write the reason for the change and the pages or workflows at risk.
  2. Capture the current state and the metric or behavior that should improve.
  3. Back up or preserve the version that can be restored.
  4. Test in a staging or preview environment when the stack supports it.
  5. Check mobile, keyboard, forms, analytics, metadata, and links after release.
  6. Record the result and who approved it.

For URL or platform changes, follow the website redesign SEO migration checklist. Maintenance should reduce accidental migrations, not create them.

Track evidence, not checkmarks

A useful maintenance record includes the date, owner, URL or system, test performed, result, evidence, severity, next action, and completion date. Attach a form submission ID, screenshot, monitoring event, or release reference when appropriate.

Separate operational metrics from marketing outcomes. Uptime, lead-delivery success, update status, backup age, and unresolved critical defects describe reliability. Qualified leads, bookings, revenue, organic entrances, and conversion rate describe business performance. Both matter, but one should not disguise the other.

Questions to ask a maintenance provider

  • Which systems and pages are included, and which are excluded?
  • How frequently are forms and lead delivery tested?
  • Who owns backups and when was restoration last tested?
  • How are urgent vulnerabilities and outages handled?
  • Are content, SEO, accessibility, and conversion reviews included or separate?
  • What evidence is delivered after each maintenance cycle?
  • What happens to access, files, and subscriptions when the relationship ends?

When planning a new build, include the maintenance model in the first-year price. The small business website cost guide lists the ownership costs that are commonly omitted, and the service-business platform comparison shows how maintenance responsibility changes the decision. Zendory's website build options state the hosting term and platform accommodation separately.