checklist · Engineering

WordPress Monthly Security Maintenance Checklist

Suggest edit

WordPress Monthly Security Maintenance Checklist

Purpose

Provide a reusable monthly security-maintenance check for WordPress websites where Blinto's maintenance scope includes ongoing security oversight.

This checklist does not mean every client receives the same maintenance scope. Contract/scope determines which controls Blinto owns.

Backup & Recovery

  • Automated backups are running as expected.
  • Recent backup/recovery point is available.
  • Backup failures are assigned/escalated.
  • Restore capability has not become unknown or inaccessible.

Updates & Vulnerabilities

  • WordPress core security/update status reviewed.
  • Plugin update/vulnerability status reviewed.
  • Theme update/vulnerability status reviewed.
  • Unsupported/abandoned components identified and escalated.
  • Critical/high-risk vulnerabilities are remediated or have an accountable action plan.
  • Virtual patching/WAF protections are functioning where used.

Malware & Security Monitoring

  • Malware/security scan status reviewed.
  • Security alerts reviewed for unresolved issues.
  • Suspicious administrator/user changes reviewed where monitoring supports it.
  • Uptime/security-monitoring status reviewed where in scope.
  • No unresolved suspected compromise remains without an owner.

Users & Access

  • Administrator/user list reviewed for obviously stale or unauthorized access.
  • Privileged access still matches current responsibility where known.
  • Departed team/vendor access has been removed where applicable.
  • Shared/compromised credential concern is escalated and credential changed when individual revocation is insufficient.

Site Health & Security Configuration

  • HTTPS/certificate status is healthy.
  • Security plugin/service is active and not reporting a critical configuration problem.
  • WAF/edge/security controls are active where applicable.
  • Remote maintenance/monitoring connection is healthy where used.
  • Unexpected security-tool deactivation or licensing failure is addressed.

Post-Update Verification

Where updates were performed:

  • Website loads normally.
  • Critical forms/commerce/login flows relevant to the site are checked as appropriate.
  • Material errors/regressions are assigned for resolution.

Reporting & Exceptions

  • Material security issue is communicated to the responsible delivery/client owner.
  • Client-controlled blockers are documented rather than marked complete.
  • Exceptions have an owner and next action/date.
  • Monthly maintenance completion is recorded in the applicable task/system.

Completion Record

Website:
Month:
Maintained by:
Date completed:
Issues found:
Actions / owners:
Client-controlled exceptions: