Technology

    Website Maintenance: What to Do Monthly, Quarterly and Yearly

    14/08/2026
    8 min read
    Website Maintenance: What to Do Monthly, Quarterly and Yearly

    A website is not a delivered building. It is equipment in operation. It stays online twenty-four hours a day, exposed to changes you do not control, browser updates, search algorithm shifts, expiring certificates, libraries with newly disclosed flaws, prices that changed, a phone number that is now different.

    Maintenance does not have to be complicated. It has to be regular. This article gives three concrete lists, with intervals, that fit a small company without turning into an expensive contract.

    Why a neglected site rots

    An abandoned site does not stay frozen at its launch date. It gets worse, along independent paths.

    • Security. Flaws in libraries and systems are found constantly. A version that was safe in January may have a publicly known vulnerability by May. The things scanning the internet for those versions are bots, and they do not pick targets by size.
    • Trust. An expired certificate, a broken link, a form that stopped sending because the mailbox password changed. Each one is a visitor who gives up.
    • Search. Competitors publish, update and gain ground. Standing still loses position even when you do nothing wrong.
    • Truth. Outdated content is worse than missing content. Old prices, an old address, a service you no longer offer all create friction and rework.
    • Accumulation. Three years without updating dependencies is not three times one year of work. It is far more, because versions pile up mutually incompatible changes.

    The monthly routine in seven items

    Set aside thirty to sixty minutes a month. Pick a fixed day, the first Monday, say, and do not negotiate with it.

    1. Test the contact form end to end. Send a real message, from an external address, on a phone. Confirm it arrived in the right inbox, did not land in spam, and that the autoresponder fired. A broken form is the most expensive and most silent defect a site can have.
    2. Confirm the latest backup exists and restores. Seeing "backup complete" in a panel is not enough. Once a month, download the file and check it opens and is roughly the expected size. An untested backup is a hypothesis, as we discuss in backup and continuity when the site goes down.
    3. Apply security updates. System, dependencies, plugins. Always with a backup taken first and a visual check of the site afterwards.
    4. Look at Search Console. Go straight to Pages and to Experience. Look for pages that dropped out of the index, new crawl errors, and URLs flagged as problematic. Five minutes covers it.
    5. Look at three numbers in Analytics. Sessions, top landing pages, conversions. You are not doing analysis here: you are looking for a sharp drop. If something halved, there is a technical cause somewhere. What to watch is detailed in the metrics that matter in GA4.
    6. Check the certificate expiry and the domain renewal date. Thirty seconds in the browser padlock and in the registrar panel. A domain that expires through forgetfulness is one of the few mistakes that takes everything down at once, email included.
    7. Open the site on a phone and browse it as a visitor. Home, a service page, contact. No DevTools, no cleared cache, the way an actual person does it. You will find things no tool finds.

    The quarterly routine in five items

    Once every three months, two to four hours.

    1. Crawl for broken links. Internal and external. A site you cited went offline; a page you renamed became a 404. Use a free crawler and fix or remove every item on the list.
    2. Run a performance and accessibility audit. Lighthouse or PageSpeed on your three most important pages, mobile and desktop. Compare with the previous quarter. Drops usually have a concrete cause: a new unoptimised image, a third-party script someone added. Worth cross-reading with Core Web Vitals explained.
    3. Review time-sensitive content. Prices, packages, opening hours, team, phone, address, any text that says "this year". Go through the service pages and the footer with an auditor's eyes.
    4. Update lower-risk dependencies. Patch and minor versions, in a batch, with testing afterwards. Leaving it all for one push at year end is exactly what turns maintenance into a project.
    5. Review the technical SEO baseline. Sitemap generated and submitted, robots.txt correct, canonicals pointing at the right place, unique titles and descriptions on the main pages. The technical SEO checklist works as a script.

    The yearly routine in four items

    Once a year, block out a full day. This is not routine maintenance: it is a hands-on strategic review.

    1. Inventory accounts and access. List the domain registrar, hosting, repository, DNS, email, Analytics, Search Console, Business Profile, third-party tools. For each: whose name it is in, who has access, when it renews, what it costs. Remove access for people who left. That inventory is the most valuable document you will own on the day of a crisis.
    2. Update major dependencies and the language runtime. Versions that lost support stop receiving security fixes. This is the update nobody wants to do and that has to happen once a year, with a staging environment first.
    3. Review compliance. Does the privacy policy describe the tools the site actually uses today? Does the cookie banner block before consent? Do old lead records still need to exist? Starting point in LGPD for small websites.
    4. Compare the site with the current business. Is what the company sells today on the site? Is what is on the site still something you sell? What questions do clients ask that the site does not answer? That comparison is what reveals whether next year needs maintenance or a rebuild.

    Signs the site needs a rebuild, not maintenance

    Maintenance preserves what exists. At some point fixing costs more than rebuilding. The signs are reasonably objective:

    • Any simple text or image change requires a developer and takes days.
    • The site was built for desktop and the mobile version is a painful adaptation, while most traffic comes from phones.
    • The underlying technology lost support and updating it breaks the site.
    • Each performance fix buys very little, because the problem is structural.
    • The site describes a business that no longer exists, different services, different audience, different positioning.
    • You are embarrassed to send the link.

    Two or three of those together, and it is time to plan a redesign, ideally without losing what already ranks, which needs its own method, described in website redesign without losing your SEO.

    In-house or outsourced

    Split the list into two columns. One column is content and verification, testing the form, checking prices, looking at Search Console, browsing on a phone. Any organised person inside the company can do that, and will do it better than an outsider, because they know the business.

    The other column is technical, updating dependencies, touching the server, fixing performance, restoring a backup. That needs someone who knows what they are doing, because getting it wrong takes the site down.

    The model that usually works in a small company is mixed: the monthly routine stays with someone inside, and the quarterly and yearly technical work goes to whoever built the site, on an hours contract or a package. What matters is that the arrangement is explicit, who does what, how often, and who answers when the site falls over outside business hours.

    If you do hire maintenance, demand two things in the contract: a report of what was done each cycle, and access held in your name, not the supplier's.

    A simple tracking sheet

    No tooling required. A spreadsheet with six columns handles it, and it is worth more than any promise to remember.

    • Item, the task name, exactly as it appears in the lists above.
    • Frequency, monthly, quarterly, yearly.
    • Owner, a named person, never a department.
    • Last run, the date.
    • Result, OK, or what was found.
    • Action raised, what is outstanding and by when.

    Add a tab with the yearly account inventory: service, account holder, login, renewal date, cost. Keep it somewhere more than one person can reach, with passwords in a manager, never in the sheet itself.

    The gain from that sheet is not tidiness. It is that maintenance becomes a visible habit: when the "last run" column is three months stale, everyone can see it. Sites that break rarely break by surprise, they warn first, and the warning gets missed because nobody was in the habit of looking. Worth seeing how that plays out in real projects in our portfolio.

    If you want a defined maintenance routine and someone accountable for it, talk to ALB Seven.

    Liked the content? Share it with your friends!

    ALB Seven

    We transform your ideas into creative solutions. Custom design, websites and software for your business's digital growth.

    Company

    Services

    Portfolio & Content

    ©2026 ALB Seven. All rights reserved.