A WordPress website needs attention after launch. Content changes, software updates and account access can affect whether visitors can use the site and whether you can recover it when something goes wrong. A short, repeatable maintenance routine is more useful than an occasional hurried cleanup.
WH4SA supplies hosting and the software preparation described for BUILD or SELL / E-COMMERCE. That does not make customer website maintenance an automatic part of hosting. Decide who checks the site, performs updates and responds to problems, especially when a designer, business owner and hosting provider have different responsibilities.
1. Record the site and its responsible people
Keep an inventory of the domain, hosting account, WordPress administrator access, active theme, plugins and external services. Record where paid licences and renewal notices are managed. Store passwords securely rather than in an unprotected spreadsheet or email chain.
Name the person responsible for routine maintenance and the person who approves changes. Note which features matter most, such as quote forms, checkout or member access. That gives you a consistent test list and a useful starting point when something stops working. The inventory should describe the real site, not an outdated handover document from its launch.
2. Check backups before you need a restore
A WordPress recovery copy normally needs both files and the database. Confirm what the backup tool includes, how old the latest copy is and where it is stored. Keep an appropriate copy outside the same hosting account and protect it because it may contain customer or account information.
Learn the recovery process before an emergency. If practical, test a restore to a safe location without replacing the live site. Do not assume a “backup complete” message proves that every required item can be recovered. WordPress's backup lesson is a useful starting reference; available hosting backup and restore options should be checked separately.
For a South African business website, recovery planning should cover both site files and data, with an appropriate copy outside the same account.
3. Update core, plugins and themes deliberately
Review available WordPress, plugin and theme updates. Read relevant release notes and compatibility information, particularly for components central to forms, checkout or page layout. Keep a current recovery copy before making significant changes.
Use a staging or other safe testing environment where available. Do not stack many unrelated changes together if that makes a failure difficult to trace. After the update, check the important visitor tasks rather than only the dashboard. WordPress documents core updates and plugin/theme automatic updates; automatic updating still needs monitoring and recovery planning.
4. Review users and passwords
Check who can sign in and what each account can do. Remove or reduce access that is no longer needed, following an appropriate handover process for the person's content. Avoid sharing one administrator login across several people when individual accounts would make responsibilities clearer.
Use unique passwords and suitable additional authentication where supported. Review unexpected administrator accounts or unexplained changes promptly. Do not respond to a suspected compromise by simply changing one password and assuming everything is resolved; preserve useful information and seek help with the scope of the issue.
5. Test forms and customer communication
Submit each important form using realistic test information and confirm that the expected recipient receives the message. Check validation, confirmation text and reply handling. A form can look normal while delivery fails because of a configuration or service change.
Test from outside the administrator session and consider mobile use. If the site operates a store, also check order notifications and the appropriate payment test workflow. Keep test data identifiable and avoid accidentally contacting real customers. Record failures with the date, page and observed behaviour so the person investigating has something concrete to work with.
The maintenance job is not finished when an update reports success. Verify the task that matters to your business.
6. Check links, navigation and important content
Follow the main menu and primary calls to action. Look for broken internal links, outdated downloads, missing images and links that lead to the wrong destination. Review external links that your customers depend on rather than assuming they remain unchanged forever.
Read the contact information, service details and prices your business publishes. Remove outdated promotions or explain their current status. A technically healthy site can still fail customers when its business information is wrong. Give content checks a place in the maintenance routine instead of treating maintenance as software updates alone.
7. Review HTTPS and security signals
Open the real domain and check for certificate warnings or mixed-content issues. Visit more than the homepage: an embedded image, script or old link may behave differently elsewhere. Confirm that the intended domain variants resolve as planned.
Review relevant security notices and logs available to you, without assuming every automated alert means a compromise. Investigate patterns and unexpected changes. A valid certificate protects the connection for its covered names; it does not prove that every plugin or account is secure. Use the cPanel tools for hosting-level certificate and account information where appropriate.
8. Check performance with ordinary customer tasks
Try important pages on a phone and a normal connection. Notice oversized images, unnecessary video, layout shifts or a page that takes unusually long to respond. Compare against the site's own normal behaviour instead of inventing a target score that may not fit the business.
Make one measured change at a time. Compress or resize unnecessary large images, review expensive features and avoid adding several optimisation plugins that overlap. Caching settings can affect forms and stores, so use the documentation for the actual tools. A faster-looking homepage is not an improvement if checkout becomes unreliable.
9. Remove unused software and tidy carefully
Review plugins and themes that are no longer required. Before deleting anything, confirm it is not providing an essential function or acting as a required parent theme. Remove abandoned experiments through the appropriate interface, and keep records of important configuration or licences.
Housekeeping may also involve spam, old revisions or temporary files, but do not delete database tables or uploads simply because they look unfamiliar. Keep a backup and understand the consequence. An aggressive cleaner can remove information another component needs. Use the WordPress plugin documentation for supported management steps.
WH4SA’s hosting role and customer website maintenance are different responsibilities. Assign someone to own the website checks.
10. Keep a schedule and a change record
Choose a review frequency based on how often the website changes and how important its functions are to the business. A store receiving orders needs a different level of attention from an occasional portfolio update. Security updates and active failures should not wait merely because the next routine review is later.
Record what changed, who changed it, the backup used and the checks performed afterwards. This makes recovery and troubleshooting easier. Include planned renewals and contact details for separately purchased services. Review the WordPress hosting responsibility boundary so hosting administration and customer website work are not confused.
A checklist to use after every significant change
- Confirm the site loads while logged out.
- Test navigation, forms and the most important conversion path.
- Review mobile layouts and meaningful images.
- Verify backups and record the change.
- Check for new warnings or errors.
- Confirm that another responsible person can find the recovery information.
Maintenance is successful when the website remains usable, accurate and recoverable. Keep the routine small enough to perform consistently, then expand it where the site's complexity or risk requires more attention.
