The risk sits in plugins, not core. Patchstack’s State of WordPress Security in 2026 report counted 11,334 new vulnerabilities in the WordPress ecosystem during 2025. 91% were in plugins and 9% in themes; WordPress core had six, all low priority. Nearly half (46%) had no fix from the developer by the time they were disclosed, and for the heavily exploited flaws the median time from disclosure to mass exploitation was about five hours. A site with thirty plugins is really thirty small software suppliers, and the monthly checklist is how you keep track of all of them.
Updates need a test run. Since WordPress 5.5, administrators can switch on automatic updates plugin by plugin and theme by theme, and by default WordPress checks for them twice a day. That is the right setting for small, well-maintained plugins and for security releases you cannot wait a month for. It is the wrong setting for a page builder, a shop or a membership plugin, where an update can change layouts or checkout behaviour. Those belong on staging first: refresh staging from production, update there, click through the journeys that earn money, then repeat on the live site.
Only the latest version is supported. WordPress 7.1 “Mary Lou” was released on 19 August 2026 and 7.1.2, a security release, followed on 22 September 2026. WordPress.org officially supports only the latest version. Security fixes are backported to older branches as a courtesy, currently as far back as 4.7, but backports are not a plan. The PHP underneath matters as much: WordPress.org recommends PHP 8.3 or greater, and PHP 8.2 stops receiving security fixes on 31 December 2026.
A backup you have not restored is a hope. Backup jobs fail quietly, storage fills up, and some tools back up the files but not the database. The monthly run checks the backup log and takes a fresh copy before anything is updated. The quarterly run goes further and restores the offsite copy to a test environment, because that is the only way to know it works.
Performance drifts between redesigns. A new slider, a chat widget or a batch of uncompressed photos can undo last year’s speed work without anyone noticing. Google’s Core Web Vitals give a fixed yardstick: at the 75th percentile of real visits, a good page has Largest Contentful Paint within 2.5 seconds, Interaction to Next Paint within 200 milliseconds and Cumulative Layout Shift of 0.1 or less. Checking the same templates every month turns a slow decline into a line item you can fix while it is small.
Agencies need proof as well as work. If you look after client sites, the client is paying for something they never see. Run one checklist per site from the same template, and the month ends with a short report the client approves: what was updated, what was fixed, what needs a decision. That record also settles the “did anyone update the plugins?” question when something goes wrong. With a portfolio of sites, stagger the schedules across the month so each maintainer handles a few sites a day rather than all of them in the first week.