WordPress doesn't need daily babysitting, but it does need a monthly pass. Update core, themes, and plugins, verify a fresh backup exists, clean up what's piling up in the database and uploads folder, and check Site Health for anything real. Do this once a month and you avoid the two things that actually break sites: a bad update breaking production, and years of cruft slowing everything down.
Everything below uses what's already in wp-admin. You don't need a maintenance plugin to do this well.
1. Update core, themes, and plugins
Open wp-admin → Dashboard → Updates once a month and work through anything waiting. Before you click update on anything major, especially a WooCommerce store or a site with custom code, take a fresh backup first and test the update on a staging copy before applying it to production. See Using WordPress staging for how to set one up, and Running a WooCommerce store if you're maintaining a store specifically.
Plugins and themes you're not using should be deleted, not deactivated. An inactive plugin still sits on disk as an unpatched attack surface if it has a known vulnerability. If you haven't touched a plugin in six months, decide whether you still need it.
2. Confirm backups are actually there
On most hosting accounts, backups run automatically in the background, but don't assume; once a month, actually confirm it: log into cPanel and check JetBackup 5 to see that recent backups exist and look complete. It catches the rare case where something upstream (a misconfigured plugin, a disk issue) quietly broke the backup chain.
Before you run updates in step 1, make sure a backup exists before you start if you're about to touch something significant. A scheduled backup from last night doesn't help if you update at 2pm and something goes wrong at 3pm.
3. Clean up the database and media library
WordPress accumulates cruft that never goes away on its own:
- Post revisions. Every autosave and manual save creates a revision row. A frequently-edited page can have dozens.
- Spam and trashed comments. These sit in the database indefinitely until someone empties them.
- Orphaned post meta and transients. Old plugins leave data behind after you delete them; expired transients rarely clean themselves up on schedule.
- Unused images. Every uploaded image, including ones no post references anymore, stays in your media library and counts against disk usage.
You can handle most of this from wp-admin → Tools and the built-in comment moderation screen without installing anything: empty spam and trash under Comments, and review drafts and revisions under each post's revision history. If your database has grown large, a plugin like WP-Optimize or Advanced Database Cleaner makes bulk cleanup faster, but it's not required for a small-to-medium site doing this monthly instead of yearly.
4. Check Site Health, but don't chase every warning
Open wp-admin → Tools → Site Health and read what's under Critical issues first, that's the list worth acting on. The Recommended improvements tab mixes real issues with warnings that don't apply to Flashcloud hosting, things like object cache or HTTPS notices that our stack already handles. Read WordPress Site Health warnings and which ones matter before spending time on a warning that isn't actually a problem on your account.
5. Review speed and plugin load
Once a month is a good cadence to sanity-check load times, not after someone complains. Confirm LiteSpeed Cache is still active under wp-admin → Plugins, since it's what connects your site to the server-side caching stack. If the site has picked up new plugins since your last pass, or a page builder addon, or a security suite, check whether any of them are dragging on load time. My WordPress site is slow walks through auditing heavy plugins, image weight, and theme bloat if this pass turns up something worth fixing.
6. Use the block editor for content work, reach for plugins only when needed
For routine content changes, new pages, edited copy, reordered sections, stick to the native block editor rather than reaching for a page builder or a "quick edit" plugin. It's faster, doesn't add another script to every page load, and doesn't create a dependency you'll have to maintain later. Save plugins for things the block editor can't do: security scanning or store functionality. Every plugin you add is one more thing that needs updating in step 1.
When to open a ticket
If an update breaks something and you can't tell why, or Site Health flags a critical issue you don't recognize, open a ticket from Support → New ticket in the portal. It goes to a real person, not a bot, and you can attach details through the secure share panel if credentials are involved.