Updating WordPress is not optional. Plugins fix security issues, themes keep up with new core versions, and WordPress itself moves forward several times a year. But every update also changes code on a site your client depends on. For an agency that looks after dozens of sites, that adds up to hundreds of small risks every month.
This checklist is the routine we recommend for any agency that maintains client sites. It works whether you update by hand or with a tool.
Before you update
- Know what is being updated. Read the changelog of major plugin updates, especially page builders, WooCommerce and anything that touches checkout, forms or logins.
- Make a fresh backup of both files and database. A backup from last week is not a backup of today’s orders.
- Check that the site works right now. If something is already broken, you want to know that before the update, not after.
- Note which pages matter most. The homepage, the main menu pages, contact forms, the shop and checkout, and the login page are the usual suspects.
- Check premium plugin licences. Premium plugins without a valid licence often fail to update, or update only partially.
Test on a copy first
The safest place to find out what an update does is not the live site. Make a copy of the site (a staging copy) on the same server, run the updates there and look at the result before anything changes on the live site.
- Use a copy that matches the live site as closely as possible: same files, same database, same PHP version.
- Make sure the copy cannot be found by search engines or visitors.
- Apply the updates on the copy, one group at a time if you can, so you know which update caused a problem.
Check the result, page by page
This is the step that is most often skipped, because it is the most boring. Clicking through ten pages on a phone and a laptop for every site, every week, does not scale. But this is exactly where broken layouts, missing buttons and error messages show up.
- Compare key pages before and after the update, on desktop and on mobile.
- Look for layout shifts, missing images, broken menus and error notices.
- Test the flows that make money or leads: forms, search, cart and checkout.
- Check that you can still log in.
Only then go live
If the copy looks right, apply the same updates to the live site. Put the site in maintenance mode for the few minutes the update takes, and check the live site again afterwards. If the live site does not look right, roll back to the backup you just made.
If the copy does not look right, do not update the live site. Find out which update caused the problem, check for a fix, or wait for the next version. The live site stays as it was, and your client never notices.
After the update
- Remove the staging copy, so old copies of the site do not pile up on the server.
- Keep a short log: what was updated, when, and what you checked.
- Tell the client. A short monthly report in their own language builds trust and makes the value of maintenance visible.
The problem: this takes time
Done properly, this routine takes 15 to 30 minutes per site. For an agency with 40 client sites that update once a month, that is 10 to 20 hours of work every month, spent on work nobody sees when it goes well.
That is why most agencies cut corners. They update the live site directly, click around for a minute and hope for the best. Most of the time it works. When it does not, the client is often the one who finds out.
Want this checklist to run on its own?
Verploy tests every WordPress update on a copy of the site first, compares key pages on desktop and mobile, and only goes live when nothing looks off. It is launching soon, and agencies on the waitlist get first access to the founding spots: 40% off, for life.