Website care · 3 min

A maintenance checklist for a small business website

A straightforward checklist for enquiries, updates, backups, access, performance and content.

A website proof inspected with maintenance, link and backup tools

← Back to the blog

Website maintenance is not a single monthly button. It is a short, repeatable routine that keeps important journeys working, makes failures visible and preserves a route back when a change goes wrong. The exact schedule should reflect how often the site changes and how costly an outage would be.

Test the actions customers depend on

Start with the paths that matter to the business: send an enquiry, complete a booking or test the first stage of checkout without creating a real charge. Check the confirmation and the internal notification. Review the site on a phone as well as a larger screen, because a layout can look healthy to an administrator while being unusable to a customer.

Apply updates with a recovery path

Review the platform, theme, plugin and dependency updates relevant to the site. Read significant release notes, take or verify a backup, apply changes in a controlled order and repeat the important journey tests afterwards. Urgent security work may need faster handling, but speed should not remove the ability to recover.

Verify backups rather than assuming they exist

A backup is useful only if it contains the necessary files and data, is stored somewhere appropriate and can be restored. Periodically inspect the backup history and perform a restore test in an isolated location. Record what was restored and how long the process took so recovery does not begin with guesswork during an incident.

Review domains, certificates and outside services

Confirm who owns the domain and hosting accounts, where renewal notices go and whether payment details are current. Check certificate status and the integrations the site relies on, such as email delivery, analytics, booking or payment services. Maintain a simple register of providers and responsible contacts rather than leaving this knowledge in one person’s memory.

Remove access that is no longer needed

Review administrator accounts, shared credentials, API keys and third-party access. Remove former staff and suppliers, use individual accounts where possible and keep recovery methods current. Access reviews are also a good time to confirm that the business, not only its developer, can reach the domain, hosting and essential service accounts.

Watch for slow decline

Look for unusually slow pages, oversized new images, broken links, outdated opening hours and content that no longer matches the offer. Maintenance should distinguish a small repair from an improvement project: correct factual and operational problems promptly, then scope larger design or content changes deliberately.

Keep a brief maintenance record

Note what was checked, what changed, the result of the tests and any follow-up work. A concise record prevents repeated investigation and gives the owner a clear view of the site’s condition. The routine should reduce dependence and surprises, not create maintenance theatre.