Essential WordPress Maintenance Tasks You Shouldn’t Ignore
Managing a WordPress website can take time a lot of time out of your day to keep it maintained and healthy. Are you doing any of these 12 important things for your WordPress website?
Oops! We could not locate your form.
Managing a WordPress website can take time a lot of time out of your day to keep it maintained and healthy. Are you doing any of these 12 important things for your WordPress website?
Update: This post was first written in October 2017, but it receives regular refreshes to keep it current and useful.
A website requires some regular TLC to keep it ticking. As expectations for website performance continue to grow and evolve, it is important to keep your website in line with these.
Here are 12 important things to do to keep your WordPress website running smoothly.
WordPress is a constantly evolving CMS platform. This is due to its open-source nature and the huge community constantly working on improving it. Which includes adding new features, ensuring bugs are fixed, keeping it secure, and much more.
Keeping your website updated with the most recent version of WordPress Core gives you access to all of these improvements, security patches, bug fixes, and features.
Leaving your website sat on an old version can lead to security vulnerabilities, deprecated functionality, and plugin incompatibility issues.
All updates should be preceded by a backup, and ideally tested on a staging site first (a private clone of your site on a separate server). This is to ensure the update doesn’t break anything or cause any clashes with plugins.
Did you know there are over 60,000 plugins available for WordPress in the official directory alone, with tens of thousands more across premium marketplaces?
Not all are created equally, and some don’t receive regular updates and patching. This can leave them open to vulnerabilities and hacks. Always measure up the necessity of a plugin. Ensure it is trusted and well-maintained before adding it to your website.
Other more reliable plugins get regular updates and patches, and it’s very important to keep these up-to-date. This will keep you protected from the risks of out-of-date versions leaving you vulnerable to hackers, who might have found exploits in these older outdated versions. The patches and updates are there to improve security, close vulnerabilities, and improve performance.
It’s strongly recommended to check frequently for any new plugin releases. Check their compatibility with your other plugins as well as the latest stable release of WordPress. Don’t forget to also check any plugins that are not installed through the WordPress Plugin Directory, as you may not receive notifications on your site for these.
Also monitor for plugin vulnerabilities that may have been found, as this will let you know if they need urgent updates to patch. There are a number of security tools and services that can help with this.
We use Patchstack as part of our stack to do this.
Keeping on top of this will reduce the chances of letting in the bad guys, and fix any bugs with the plugins.
As with WordPress Core, a backup of your site should be done first. Ideally all plugin updates should first be tested in a staging environment to ensure updating on your live site won’t cause any problems.
Page speed and conversion rate remain closely linked. A commonly cited figure suggests each additional second of load time can reduce conversions by around 7%, and separate research has found bounce probability can climb by 30%+ as load time increases from 1 to 3 seconds. Different studies land on slightly different numbers depending on industry and methodology, but they all point the same direction – speed costs you sales, not just user experience points.
We live in busy times. People don’t have the time or patience to be waiting for a slow page to load, and will just go elsewhere if it takes too long. Fast-loading pages also provide a far better user experience.
As such, it’s important to do everything we can to reduce page load times, by optimising how your website loads.
See for yourself by entering your website into the following page speed test tools: Google Page Speed, GT Metrix, Pingdom.
One thing to keep in mind is not to become too concerned if your score is not 100. In some cases depending on what 3rd party scripts are loading it may not be possible.
Optimisation is an ongoing task and should be regularly reviewed. Even small changes or additions can impact performance. Every little improvement can add up to significant gains.
Applicable to both mobile and desktop experience, the page experience update which incorporated Core Web Vitals by Google is one of the many signals Google uses to decide which pages appear in the SERP.
You should aim for a passing score for Core Web Vitals, which can be seen with Lighthouse, Google’s Page Speed Insights, and GTMetrix. The 3 areas covered by Core Web Vitals are:
These are in addition to the existing page experience signals, which are:
As with page load optimisation, this should be reviewed regularly and you can monitor the Core Web Vitals report in Google Search Console.
You probably spend lots of time finding the right images for your blog posts and pages. You hopefully spend time resizing them ready for posting, so you’re not uploading needlessly large image files.
However, your fantastic images could still be an issue. Having lots of images, large images, or videos can massively slow down your website if not further optimised. This could be deterring visitors from viewing all of your content because pages take too long to load.
Use an image compression tool to compress your images when you upload them. This can drastically reduce the toll they have on page speed. They can reduce the image file sizes without sacrificing the quality of your existing images and everything you upload moving forward.
Also consider serving next-generation image formats like WebP or AVIF, which are far less weighty and preserve quality. Virtually all browsers now support WebP.
Make sure anyone uploading images to your website is preparing them first, by ensuring they are the correct size and ratio. Make this part of a process that also includes proper image optimisation for SEO and it will save you a lot of work in the long run.
Have you run your own test on your important enquiry forms, or tested the sales order process? When was the last sale or lead? Are users still getting that email when they download your guide or sign up to your newsletter? Is your stockist search still working correctly?
With the multitude of devices that can access your website, along with required updates to run, some things can break!
We recommend as a minimum that you regularly test your main website features and functionality. For example:









In the past few years security threats have risen drastically with websites being attacked and hijacked all around the world.
Don’t think you have to be a big brand name to get attacked.
Your website could provide the bad guys with the ability to run scripts and malicious code for them without you even knowing!
So it’s a good idea to protect yourself by choosing a good host that has a secure infrastructure and protection, by using a WAF (Web Application Firewall), as well as running regular scans for infectious files (yes, it is starting to sound like your old windows computer with Norton Antivirus or McAfee.)
Some great 3rd party security solutions and firewall providers we recommend are:
You can quickly check if your site is currently protected or if it has been hacked, using Sucuri’s free SiteCheck tool (this is not comprehensive, but can be useful for flagging issues).
If your website is not protected by an SSL certificate, it will be flagged as NOT SECURE by Google Chrome and other browsers. If you still see HTTP rather than HTTPS in the address bar on your website, that’s the clearest sign something’s missing.
Chrome and Edge dropped the padlock icon back in 2023 which used to be another indicator of whether a website was secured by SSL, and they replaced it with a neutral settings icon, partly because research found most users misread the padlock as a general trust signal for the site rather than what it actually meant (an encrypted connection). So don’t rely on “is there a padlock” as your check anymore. Instead, look for the Not Secure warning text itself, or clicking the settings icon at the left of the address bar (whatever it looks like in your browser) still lets you view the certificate details directly if you want to double check.

Don’t have an SSL? Then the first thing to do would be speak to your current website host, as they may have suitable solutions to offer which will be compatible with their setup.
Alternatively, depending on the level of cover you require, you can obtain them from many 3rd party companies such as:
As you may be aware, WordPress has many premium paid plugins.
The companies and developers that release these plugins spend further time and resources ensuring compatibility and security threats are overcome, by releasing regular updates.
To benefit from these updates a regular payment is required (normally an annual or monthly payment). Ensure you keep on top of this as if payments lapse, so will the plugin, and outdated plugins can be problematic for functionality and security.
Websites go down, they get problems and sometimes the quickest method of recovery to minimise any further downtime is to restore a website backup.
Some example cases of a website going down could be from:
We recommend:
Time and time again we hear that WordPress backups are safe, stored on the server. But what happens if the server fails?

You should store your backups on a different server to the one your website lives on.
At Impact we use Updraft Plus (a backup plugin) to schedule routine website backups, and then transfer the backups to a third party storage platform like Amazon S3.
Here are a few of the great tools that you can use to backup and restore your website:
Speak to your website host as it may be an option they can provide with less hassle.
As newer versions of PHP are released, older versions lose support and become less secure. Web hosts have to deploy the latest versions to their servers to maintain a secure service with optimised performance. This can have a knock-on effect on hosted sites if their codebase isn’t compatible with the PHP version of the server.
Worth flagging directly given how quickly this list moves: PHP 8.1 reached end-of-life on 31 December 2025, and PHP 8.2 is next in line, reaching end-of-life on 31 December 2026. As of now, only PHP 8.2 through 8.5 are still receiving any security support at all, anything on PHP 8.1 or earlier is running unpatched. If your site hasn’t been checked against this recently, it’s worth doing now rather than waiting for your host to flag it.
For security, make sure your website is on a server with a supported version of PHP. Your website host should manage this.
For older sites, in particular, this may initially require a bit of development work first, to polish the codebase and ensure its compatibility. This will save anything breaking when it is moved to the latest PHP version.
PHP tends to get all the attention, but your database (MySQL or MariaDB, running underneath WordPress) needs the same treatment and is easy to overlook. WordPress’s own community has flagged that a large share of sites are running database versions that have already reached end-of-life and are no longer receiving security updates, the same risk profile as an outdated PHP version, just with far less attention paid to it.
As a rough guide for where things stand, MySQL 8.0 reaches end-of-life in April 2026, and on the MariaDB side, versions are cycling through end-of-life fairly regularly as each release reaches the end of its support window. Current WordPress hosting guidance recommends MySQL 8.0+ or MariaDB 10.6+ as the safe baseline, rather than treating the old bare-minimum figures as good enough.
In practice, this is usually your hosting provider’s or website developer’s job to manage rather than something you touch directly, but they may need to contact you about any audits or work needed to bring your site’s code up to scratch, so any PHP or database updates don’t cause compatibility issues. If your hosting or development partner doesn’t keep you informed on these things, it’s worth asking the question rather than assuming it’s being kept current. If you’re on shared or older hosting, the database version can quietly lag behind for years without anyone noticing until it becomes a real vulnerability.
On occasion when completing the tasks set out above, things may not go to plan or require further investigation or development. It can also be very time-consuming to stay on top of everything in-house.
If this is the case, who do you have on hand to assist you with additional support?
We recommend having a WordPress Support & Maintenance company on hand for those sticky issues, and to take the weight off your shoulders, so you can focus on the other projects you’re probably managing at the same time.
If in doubt, give Impact a shout! If you struggle to get help or don’t have the time to keep on top of updates and maintenance then feel free to give Impact a shout on 020 3355 8747 (9 am – 5 pm Mon – Fri) or drop us a message.
The Impact Media team help our clients save multiple hours per week by:
See how both Tollring and Automation Logic witnessed immediate performance improvements and the benefits of an experienced support agency partner on our case studies page.
WordPress Core is the out of the box version of the WordPress CMS that you install when building a WordPress website. It encompasses all of the files that make up the base or core version of WordPress.
WordPress releases regular updates for the CMS to maintain security and performance, along with new features.
If you don’t update WordPress, your website can become vulnerable on multiple fronts. Most important are security vulnerabilities which leave your site open to hacks, malware and data breaches. You will also likely experience bugs and compatibility issues, which impact the functionality and performance of your website.
Simply put, you should update with each new release, including all major, maintenance, and security and maintenance releases.
However, all updates should be tested on a staging version of your site, backups should be made, and you should review compatibility with your plugins to ensure there will be no conflicts or issues that stem from compatibility issues.

If you’d like to learn more about our WordPress & WooCommerce Support & Maintenance plans, drop us an email or give James a call.
Our plans provide a holistic solution to your website’s performance, reliability and security, and are inclusive of premium tools and services.