A business website needs routine care after launch. Content changes, software updates, expiring accounts, staff turnover, provider changes, and new security issues can make a previously healthy site unreliable. A maintenance checklist establishes ownership and creates evidence that important controls are working.
Confirm ownership and access
- Verify the business controls the domain, hosting, DNS, email provider, analytics, search tools, source code, and important integrations.
- Remove accounts for people who no longer need access.
- Use individual administrator accounts, strong passwords, and multi-factor authentication where available.
- Record emergency contacts and the approved way to share credentials.
Review software and configuration
Inventory the application, runtime, database, dependencies, plugins, themes, server services, and external APIs. Apply supported updates through a controlled process with backups and validation. Remove unused components and confirm that private configuration files are not publicly accessible.
Test important visitor journeys
Submit contact and quote forms using representative devices. Confirm server-side validation, consent behavior, confirmation pages, database records, internal delivery, and visitor email. Check navigation, search, downloads, account flows, payment or scheduling integrations, and helpful error pages.
Verify backup and recovery
Check recent backup completion, retention, protected storage, and the credentials needed to restore. Schedule test restoration into an isolated environment. A successful backup message does not prove that files, database, configuration, and dependencies can be recovered together.
Review security and monitoring
Check failed login trends, unexpected accounts, file changes, malware alerts, exposed services, TLS, security headers, logs, rate limits, and provider notices. Confirm that alerts reach an attended channel and that the recipient knows what action to take.
Maintain content and search quality
Update service information, staff-approved business details, policies, contact methods, and dated guidance. Find broken links, missing images, duplicate titles, incorrect canonical URLs, redirect chains, and sitemap errors. Keep drafts and unverified claims unpublished.
Measure performance and conversions
Review key pages on mobile and desktop. Watch server response, media size, layout stability, interaction delay, and third-party code. Validate configured analytics and lead events without collecting unnecessary personal data. Compare trends only when enough real data exists.
Record work and next actions
Keep a change log with date, owner, affected system, backup, validation, and rollback notes. Track unresolved risks separately from routine requests. Review the support scope periodically so application, hosting, domain, email, and security responsibilities never become assumptions.