Issue 16
An hour a month is enough (if it's the right hour)
Not every site needs a care plan, but every site needs a routine. The failures that take WordPress sites down are never sophisticated: an untested backup, a plugin abandoned two years ago, an admin account belonging to someone who left. The monthly hour that catches them, and the checklist pack.
A fixed monthly routine — same checks, same order, every month — catches almost everything that quietly breaks a WordPress site, in under an hour.
Last issue was for the freelancers, about the documents that run a WordPress business. This one is the other side of the same coin: what to do if you're the one looking after your own site and you're not ready to pay someone monthly to do it.
Which is a completely reasonable position, by the way. Plenty of sites don't need a care plan. But every site needs a routine — because the failures that actually take WordPress sites down are almost never sophisticated. They're something obvious that nobody looked at for fourteen months.
The three I see most often, in order:
- A backup that was never restored. A backup you haven't tested is a belief, not a backup. Half the ones I'm handed turn out to be missing the database, or the uploads folder, or three months old.
- A plugin abandoned by its author. Still installed, still active, no update since 2023. That's not a maintenance issue, that's an unpatched door.
- An admin account belonging to someone who left. The developer from two agencies ago still has full access, and nobody ever removed it.
None of those need skill to find. They need somebody to look, on a schedule.
This week's fix: the monthly hour
Put a recurring event in your calendar — same day each month — and do these, in this order:
- Restore a backup somewhere safe (staging, or local). Not "check the backup ran". Actually restore it. Do this one first, because everything after it is safer once you know you can go back.
- Check the plugin list for abandonment. Anything with no update in over a year, or marked untested with your WordPress version, needs a decision: replace, or accept the risk knowingly.
- Review users. Remove anyone who's left. Demote anyone who doesn't need admin. This takes ninety seconds and closes more risk than most security plugins.
- Update, in the right order. Staging first if you have it, then plugins one batch at a time rather than "update all", then check the pages that actually matter — homepage, contact form, checkout — before you walk away.
- Check what search engines see. A quick look for broken links, 404s from changed URLs, and that no-one accidentally left "discourage search engines" ticked after a redesign.
That's the hour. The order matters more than the speed — the reason people get burned is updating before they can roll back.
If you'd rather tick boxes than remember
I've written the routine up properly as the WordPress Site Owner's Checklist Pack — £19, one-time. Five fillable PDFs, tickable on screen or printable, or handed to a VA:
- Website launch checklist — redirects, forms, analytics, backups and the mistakes that quietly break new sites.
- Monthly maintenance checklist — the routine above, condensed to under an hour.
- Security hardening checklist — logins, users, file permissions, plugins, monitoring.
- SEO audit checklist — the expanded version of the free SEO quick-wins list: technical checks, on-page basics, internal linking, content hygiene.
- Plugin update safety checklist — staging, ordering, rollback, and what to verify afterwards.
Every item says what to check, where to find it in WordPress and what "good" looks like — and where something is genuinely developer territory, it says so rather than pretending otherwise. It's built from the same process behind the professional care plans, for a fraction of one month of one. 14-day no-questions refund.
This issue lives in the archive, organised by topic. And the plugins page shows the repeatable workflows alongside the service work.
How we can work together
Reply and tell me how long it's been since anyone tested restoring your backup. I promise not to judge the answer.
How we can work together
If you want a second pair of eyes on your WordPress stack, use the archive as a starting point, then take the next step that fits your stage.
Reply and tell me how long it's been since anyone tested restoring your backup. I promise not to judge the answer.
