Close-up of server racks and networking equipment in a data centre
Back to Articles
Maintenance & Support2026-05-19

HowOftenShouldYouUpdateYourWebsite?AMaintenanceChecklist

A website that launched perfectly two years ago and hasn't been touched since is quietly losing to Google, to hackers, and to your competitors.

Website MaintenanceSecurityChecklist

A realistic website maintenance schedule is the difference between a site that keeps performing and one that quietly rots in place. A website that launched perfectly two years ago and hasn't been touched since is not neutral — it's actively losing ground, every week, to Google's evolving standards, to plugin vulnerabilities nobody patched, and to competitors who are still shipping updates. Maintenance isn't a nice-to-have subscription; it's what keeps the investment you already made from depreciating. Here's the cadence that actually holds up, broken down by how often each task genuinely needs doing.

Key Takeaways

  • Backups and uptime/security monitoring need to run weekly at minimum, and backups should be tested, not just generated.
  • CMS and plugin updates on a monthly cycle catch most issues before they compound into security or compatibility problems.
  • Quarterly reviews should cover content freshness and a Core Web Vitals check-in, since both decay gradually and silently.
  • An annual deep audit — security, browser/device compatibility, competitor comparison — catches what routine monthly maintenance misses.
  • Neglect rarely causes one dramatic failure; it accumulates as security risk, slow performance decay, and stale content losing rankings.

The website maintenance schedule, broken down by frequency

Weekly: backups and uptime/security monitoring

Backups need to run at least weekly — daily if the site takes orders or updates content frequently — and, critically, need to be tested occasionally, not just generated and forgotten. A backup nobody has restored from is a backup you don't actually know works. Alongside backups, automated uptime monitoring and security scanning should be running continuously, flagging downtime or suspicious activity within minutes rather than when a customer emails to say the site is down.

Store off-site copies, not just on the same server — a compromised or failed server can take local backups down with it. Most managed hosts and platform-level backup tools handle this automatically, but it's worth confirming rather than assuming, especially on older sites that predate whatever backup policy is currently in place.

Monthly: plugin/CMS updates, broken-link checks, performance audit

CMS core updates and plugin updates should be applied monthly at minimum — security patches specifically shouldn't wait for a monthly cycle, but routine version updates on a monthly cadence catch most issues before they compound. This is also the right frequency for a broken-link sweep (both internal links and outbound links to third-party sites that may have moved or disappeared) and a quick performance check to catch any regression before it becomes a habit.

Update on a staging copy first if the site is business-critical — a plugin update that conflicts with another plugin is a genuinely common way sites break, and finding that out on a staging environment costs nothing compared to finding out on the live checkout. This one habit prevents the majority of update-related outages we get called in to fix.

Quarterly: content freshness review and Core Web Vitals check-in

Every quarter, review your highest-traffic pages for content that's gone stale — outdated pricing, old testimonials, statistics that need refreshing, seasonal messaging that's no longer relevant. Google increasingly rewards content that shows signs of active maintenance over pages that haven't changed in years.

This is also the natural checkpoint to review Core Web Vitals performance rather than waiting for a visible slowdown; our deeper breakdown of Core Web Vitals and what they actually mean for rankings covers what to look for in that quarterly check and which metrics are worth acting on versus ignoring.

Annually: full security audit, compatibility check, competitor comparison

Once a year, go deeper than the routine monthly patching: a full security audit covering user permissions, exposed admin paths, and any plugins or integrations that are no longer maintained by their developer and should be replaced. Pair that with a browser and device compatibility pass — new OS versions and browser updates occasionally break things that worked fine twelve months ago — and an honest look at what competitors have shipped in the past year. A site that hasn't moved while competitors modernised is a slower kind of losing, but it's still losing.

This is also the right point to review who actually has admin access. Former employees, old agency logins, and forgotten API keys are a genuine security exposure that pure software patching won't catch — it needs a human to go through the user list and revoke what's no longer needed.

Watch out

Unpatched CMS and plugin vulnerabilities are one of the most common ways small business websites get compromised — not through some sophisticated targeted attack, but through automated bots scanning the internet for known, unpatched vulnerabilities in outdated software.

The real cost of skipping maintenance

The cost of neglect rarely shows up as one dramatic event — it accumulates. Security risk climbs steadily as unpatched vulnerabilities pile up, each one a known entry point that automated attack bots are actively scanning for. Performance decays gradually too: an uncompressed image added here, an unremoved tracking script added there, until page speed has crept down without any single change being the obvious cause. And content quietly stops ranking as competitors publish fresher material and Google's standards for what counts as helpful, current content keep shifting underneath a site that hasn't changed since launch.

None of these show up as a red alert on day one. They show up eighteen months later as an unexplained traffic decline, a support ticket about a broken checkout, or — worse — a defaced or blacklisted site that Google has already flagged as unsafe. By the time neglect becomes visible, it's usually more expensive to fix than it would have been to prevent.

Building a schedule that actually gets followed

The maintenance schedules that survive contact with reality are the ones that don't depend on someone remembering to do it manually. Automate what can be automated — backups, uptime alerts, security scanning — and put the tasks that need human judgement (content review, competitor checks) on a calendar with an owner assigned, not a vague intention to 'get to it eventually'.

If it's been a while since your site had any of this attention, it's worth checking whether maintenance alone will fix things or whether you're actually looking at a deeper problem — our piece on 12 signs your website needs a redesign helps draw that line. And if you're budgeting for either path, our guide to how much a website costs in 2026 breaks down maintenance costs alongside build costs so you're planning for the whole lifecycle, not just launch day.

We run this exact cadence — weekly, monthly, quarterly, annual — for clients under our website maintenance and support services, so nobody on the client side has to remember it themselves. If your site hasn't had a proper look in over a year, get in touch and we'll run a free audit against this checklist before you commit to anything.

Keep Reading

Ready to start?

Want results like these?
Let's build yours next.