Post-launch maintenance checklist
Launch is a milestone, not a finish line. A website that isn't maintained slowly degrades—broken links accumulate, plugins go unpatched, content goes stale. This is the ongoing routine that keeps a site healthy long after the launch-day excitement fades.
Weekly or biweekly
- Check uptime-monitoring alerts and confirm nothing has gone unnoticed
- Skim analytics for anything unusual—a sudden traffic drop, a spike in errors, a form that stopped converting
- Review and respond to any spam or moderation queues (comments, form submissions)
Monthly
- Apply available software, plugin and theme updates, ideally testing on staging first for anything significant
- Check for new broken internal or outbound links
- Review Search Console for new crawl errors, manual actions or security issues
- Re-run a performance check on key pages and compare against the last check (see the performance checklist)
- Confirm backups actually completed successfully—don't assume the schedule ran without checking
Quarterly
- Test restoring a backup to confirm it genuinely works, not just that it exists
- Review top-performing and worst-performing pages in analytics and Search Console
- Audit older content for accuracy—outdated prices, dead links to other sites, superseded information
- Re-check SSL/TLS certificate status and security header configuration
- Review who has admin access and remove anyone who no longer needs it
- Re-check SPF/DKIM/DMARC records are still correct, especially if any email tools changed (see the email deliverability checklist)
Annually (or after any major change)
- Do a full re-run of the SEO, accessibility and security checklists, since standards and the site itself both evolve
- Reassess whether the site's structure and navigation still reflect current priorities
- Review legal pages (privacy policy, terms) for continued accuracy
- Re-evaluate hosting capacity against current and projected traffic
- Audit dependencies (plugins, libraries, integrations) and remove anything no longer maintained by its provider or no longer actually used
Cost & vendor review
- Hosting, tool and service subscriptions tied to the site are reviewed periodically—it's common for a trial or a one-off project tool to keep billing long after it's stopped being used
- Each recurring cost is matched to a genuine, current need, not kept on purely out of inertia
- Vendor contracts and renewal dates are tracked somewhere visible, so a renewal or a price change isn't discovered as a surprise on the invoice
- Alternatives are periodically considered for any tool that's become notably more expensive or less useful than when it was first chosen
Capacity & scaling
- Hosting resource usage is checked periodically, not only noticed once the site is already struggling under load
- Any known upcoming traffic spike (a sale, a press mention, a seasonal peak) is planned for in advance rather than discovered mid-event
- Database and media storage growth is tracked so a slow, creeping resource problem doesn't become a sudden outage
Documentation & handover
- Login credentials, DNS access, hosting details and key vendor contacts are documented somewhere the whole responsible team can reach—not only in one person's head
- Any custom configuration, non-obvious workaround, or reason something was built a particular way is written down for whoever maintains the site next
- If responsibility for the site changes hands, a proper handover happens rather than an informal, incomplete one
- A simple written runbook exists for the most common maintenance tasks (deploying an update, restoring a backup, rotating a credential), so they don't depend entirely on one person's memory under pressure
Content freshness
- Older, high-traffic pages are periodically reviewed and updated rather than left untouched indefinitely
- Genuinely outdated pages are either refreshed, consolidated, or retired with a proper redirect—not just left live and stale
- New content additions still follow the standards in the content checklist, not a rushed shortcut version
💡 Put maintenance tasks on an actual recurring calendar reminder rather than relying on memory. The sites that quietly decay are almost never the ones with a written schedule—they're the ones where maintenance was always going to happen "soon."
See the security checklist for backup and update specifics, and analytics & tracking for what to actually look at when reviewing performance data.