The 14-Point WordPress Site Health Checklist
Free resource · save it or print it for your next maintenance pass Free checklist
Most hacked, slow, or broken WordPress sites weren't hacked slowly. They failed on a handful of boring, preventable things that got ignored because the site was fine yesterday. Run this checklist once a month and the scary stuff mostly stops being a surprise.
Security (run first. This is what actually gets you hurt)
- 1. Is your WordPress and every plugin or theme up to date? Outdated core is the #1 hack vector on small sites.
- 2. Are you using strong, unique login credentials? "admin" plus a reused password is how sites get locked.
- 3. Is two factor or login protection on? Even basic 2FA stops most brute force attacks.
- 4. Do you have a current backup stored off server? If you can't restore, a hack isn't an incident. It's the end.
- 5. Are you running fewer plugins? Every plugin is a door. Only keep the ones that earn their place.
- 6. Is your file or upload folder locked down against script execution? One line in the right place stops most infection paths.
Speed (this is what makes visitors leave)
- 7. Are your images compressed and properly sized? Huge unoptimized images are the #1 speed killer.
- 8. Is caching enabled? A cached page loads in a fraction of the time.
- 9. Do your mobile pages load in under about 3 seconds? That's the patience most visitors actually have.
- 10. Are you using a CDN or external caching layer? Serve static files from the edge, not your weak VPS.
Reliability (this is what keeps customers trusting you)
- 11. Are broken links and broken images hunted down? A 404 on a sales page quietly kills conversions.
- 12. Are your forms and checkout flows test passing? A broken form is lost money you'll never know about.
- 13. Are you keeping search and Google from indexing junk? Staging, test pages, and old drafts pollute your rankings.
- 14. Is your site actively monitored, not just checked on? Downtime you don't know about is worse than downtime.
The honest problem with this list: it's a lot of small tasks, and small tasks are exactly what busy owners let slide until something breaks. That's the real gap. Not knowing, but keeping up.
Run it without adding it to your todo list
This checklist is useful precisely because it's boring. The kind of thing that should happen in the background, not every month from a Post-it. That's what Godseye is for. Point it at your WordPress site and it can check your security, look for broken links, flag outdated plugins, review speed and backups, and tell you in plain English what actually needs attention. No dashboard, no code, just a chat message when you want it.
Get a site health read in plain English
Connect your WordPress site on Telegram and ask it to run your security and health checks. Free to start.
Start free
See the bot