On this page
- Why sites break when nobody owns them
- Before you start: the one-page site register
- Weekly checks (15–20 minutes)
- Monthly updates and backups (1–2 hours)
- Quarterly security and access review (half a day)
- Compliance: privacy notices and consent
- Performance and SEO health (monthly, 30 minutes)
- The runbook at a glance
- DIY vs a support plan
- Where to go from here
A good website maintenance checklist splits the work into three rhythms: quick weekly checks that catch outages and broken forms, monthly updates and backup reviews, and a quarterly look at security, access and compliance. Below is the runbook we would hand to a Kenyan SME owner or office manager, with who should do each task and what "done" looks like, so you can run it yourself or hold your developer to it.
Print it, stick it in a shared Google Sheet, or paste it into the scope of your support contract. The point is that somebody owns each line.
Why sites break when nobody owns them
Websites rarely die in one dramatic moment. They decay. The designer who built the site moves on, the staff member who had the admin password leaves, and the hosting renewal email goes to an address nobody reads. Meanwhile the software underneath keeps changing: WordPress, its plugins, PHP on the server and the browsers your customers use all move forward whether you do or not.
The result is a familiar list of problems we see when a business calls for help:
- The contact form has not delivered a single enquiry for four months, and nobody noticed because nobody was testing it.
- The domain expired over a public holiday and the site and email went down together.
- An old plugin with a known hole let someone inject spam pages that now show up on Google under your business name.
- The M-Pesa callback stopped reaching the site after a server change, so orders are paid but never marked as paid.
- The only backup is the one the host keeps, on the same server that just failed.
Every one of those is preventable with fifteen minutes a week and an hour or two a month. The runbook below is built around that.
Before you start: the one-page site register
You cannot maintain what you cannot log into. Before the first weekly check, write down the following in one secure place (a password manager is ideal; a locked document is the minimum):
| Item | What to record |
|---|---|
| Domain | Registrar, account login, renewal date, who pays |
| Hosting | Provider, control panel login, plan, renewal date |
| Website admin | Admin URL, named user accounts (no shared "admin" login) |
| Where business email is hosted and who manages it | |
| Integrations | M-Pesa Daraja app or payment gateway, Google accounts, WhatsApp number |
| Backups | Where copies are stored, how often, date of the last test restore |
| People | Developer or agency contact, who in the business approves changes |
If your developer holds all of this and you hold none of it, fix that first. Our guide on who owns your domain, code and content explains what you should have in your own name.
Weekly checks (15–20 minutes)
Pick a fixed slot, say Monday morning before the phones get busy. These checks are deliberately simple so a non-technical person can do them.
- Open the site on your phone, on mobile data. Not office Wi-Fi. Load the home page, a service page and the contact page. If it crawls on Safaricom 4G in Nairobi, it is worse for a customer on patchy 3G in Kitui.
- Submit your own contact form. Confirm the enquiry arrives in the inbox and is not sitting in spam. Do the same with any booking or quote form.
- Tap the WhatsApp and call buttons. Check they open the right number. Numbers change more often than people remember.
- If you sell online, place a small test order. Pay a low amount via M-Pesa and confirm the order status updates and the confirmation SMS or email goes out. Refund or cancel it afterwards.
- Glance at uptime alerts. A free uptime monitor will email you when the site goes down. If you got alerts last week, note when and for how long.
- Scan for anything odd. New admin users you did not create, strange pop-ups, pages you do not recognise, or a sudden flood of spam comments.
Log the date and result in one line. "6 Oct: all OK" is a perfectly good entry. The log matters more than the format, because it tells you when something started going wrong.
Monthly updates and backups (1–2 hours)
This is where most of the security value lives. Outdated software is the most common way small business sites get compromised.
Updates
- Take a fresh backup before touching anything.
- Update plugins and themes first, then the core software (WordPress or your framework), unless your developer advises a different order for your setup.
- After each batch, recheck the pages that matter: home, contact form, checkout, booking calendar, member login.
- Remove plugins and themes you are not using. Deactivated is not the same as removed; inactive code can still be attacked.
- Check that the server's PHP version is still supported. Your host's control panel will show it.
For the step-by-step version, including staging sites and rolling back a bad update, read how to update WordPress plugins safely.
Backups
- Confirm automatic backups actually ran. Look at the dates, not just the setting.
- Make sure at least one copy is stored away from your hosting server.
- Check the backup includes both the files and the database. A file-only backup of a WordPress or e-commerce site is half a backup.
Our website backup strategy guide covers how many copies to keep and where.
Content and renewals
- Update prices, opening hours, staff names and anything seasonal (school term dates, holiday hours, promotions that have ended).
- Look ahead 60 days for domain, hosting and SSL renewals. Put the dates in a shared calendar with two people invited.
- Reply to or clear out pending form submissions and comments.
Quarterly security and access review (half a day)
Once a quarter, step back from the routine and ask who can get into what. Kenyan businesses often have high staff turnover in admin roles, and old accounts are an easy way in.
| Check | What "good" looks like |
|---|---|
| User accounts | Every admin login belongs to a named, current person. Former staff and old agencies are removed. |
| Passwords and 2FA | Admin, hosting, domain and email accounts use unique passwords and two-factor authentication. |
| Roles | People who only edit blog posts are not full administrators. |
| API keys | M-Pesa, payment gateway and email-sending keys are known, stored securely and rotated if someone with access has left. |
| Test restore | A backup has actually been restored to a test location this quarter and the site worked. |
| Security scan | A malware scan is clean and Google Search Console shows no security issues. |
| SSL | The padlock shows on every page, and http addresses redirect to https. |
If the scan or Search Console flags a problem, do not try to "just delete the bad file". Follow an ordered incident process, like the one in what to do first when your website is hacked.
Compliance: privacy notices and consent
Your website almost certainly collects personal data: names and phone numbers from forms, emails from newsletter sign-ups, delivery addresses from orders, IP addresses in analytics. Kenya's Data Protection Act, 2019 applies to that data, and the Office of the Data Protection Commissioner (ODPC) oversees it.
Maintenance is not legal advice, but there are practical things to check each quarter:
- Does your privacy notice still match reality? If you added a WhatsApp chat widget, a Meta pixel or a new booking tool since the notice was written, it is out of date.
- Are your forms asking only for what you need? A quote form rarely needs an ID number or date of birth.
- Is consent clear where you rely on it? Newsletter and marketing sign-ups should be an unticked box or a clear opt-in, not buried in the small print.
- Where do form submissions end up? If they sit forever in the website database and in three staff inboxes, decide how long you actually need them.
- Have registration requirements changed? Whether your business must register with the ODPC as a data controller or processor depends on rules the ODPC publishes. Check the current position at odpc.go.ke rather than relying on what someone told you last year.
For a fuller walk-through, see what the Data Protection Act means for website owners. If you are unsure whether something applies to you, ask the ODPC or a lawyer; this checklist only flags the questions.
Performance and SEO health (monthly, 30 minutes)
A site can be perfectly secure and still be quietly losing customers. Add these to your monthly session:
- Google Search Console. Check the Pages report for a jump in "not indexed" pages and the Performance report for a sudden fall in clicks. Our Search Console setup guide shows where to look.
- Broken links. Run a free link checker or click through the main menu. Broken links annoy visitors and waste search engine crawling.
- Speed. Test two or three key pages with Google's PageSpeed Insights. Large uncompressed images uploaded since last month are the usual culprit.
- Google Business Profile. Hours, phone number and website link still correct; new reviews answered.
- Enquiry trend. Compare this month's enquiries to last month's. A drop with no obvious reason often points to a broken form or tracking, not a sudden lack of demand.
The runbook at a glance
Copy this into whatever you use to track tasks. The "Owner" column is the important one; fill it with a real name.
| Frequency | Task | Owner | Time |
|---|---|---|---|
| Weekly | Mobile load test, test forms, WhatsApp/call buttons, test order, uptime alerts | Office admin | 15–20 min |
| Monthly | Backup, updates, remove unused plugins, content refresh, renewal look-ahead | Developer or trained staff | 1–2 hrs |
| Monthly | Search Console, speed test, broken links, Business Profile, enquiry trend | Marketing lead | 30 min |
| Quarterly | User and API key review, 2FA, test restore, malware scan, SSL | Developer, approved by owner | 2–4 hrs |
| Quarterly | Privacy notice, forms, consent wording, data retention, ODPC position | Owner or compliance lead | 1 hr |
| Yearly | Domain and hosting renewal, review of support contract, design and content refresh | Owner | Half a day |
DIY vs a support plan
There is no shame in doing this yourself. Plenty of small sites are maintained perfectly well by an owner who sets aside Friday afternoon once a month. The question is which tasks carry enough risk that a mistake costs more than the help would.
Reasonable to do yourself
- Weekly checks and test orders
- Content and price updates
- Minor plugin updates on a simple brochure site, with a backup taken first
- Search Console and Business Profile reviews
Worth paying someone for
- Major version upgrades of WordPress, PHP or your e-commerce platform
- Anything touching M-Pesa, card payments or customer accounts
- Test restores and malware clean-ups
- Custom-built sites and systems, where there is no "update" button and changes need a developer who knows the code
A simple decision rule: if a mistake would stop you taking orders or bookings for more than a day, that task belongs with someone who does it every week, not someone who does it once a quarter.
What to ask before signing a support plan
- Which items on this checklist are included, and which are extra?
- How fast do you respond if the site goes down, and does that include weekends and public holidays?
- Where are backups stored, how often, and when did you last test a restore of my site?
- Will I keep my own admin, hosting and domain logins?
- Do you send a monthly report of what was done?
- What happens to my backups and access if I end the contract?
Our guide to software maintenance agreements goes deeper on contract wording if you are signing something more formal.
Where to go from here
Start with the site register this week, then run your first weekly check on Monday. Within a month you will know whether you can keep this up in-house or whether some of it should move to a professional. If you want us to take on the monthly and quarterly work, or to look over a site that has not been touched in a while, our website support and maintenance service covers exactly this list, and you keep every login in your own name.