Skip to content

Monthly WordPress maintenance report template

A report to copy and send a client each month. It covers what was updated, the backups, uptime, security, the changes they asked for, what needs their decision and what comes next. Every figure in it comes from a record you can point to.

By
WP Ministry
Published

In short

  • Open with one paragraph a client can stop after. Most will.
  • Take each figure from its source, such as Site Health, the backup tool's log and the monitor, and name that source.
  • Never print a number you did not measure. Write "not measured" in its place.
  • Report what went wrong in the same plain way as what went right.
  • Leave out speed scores with no explanation, counts of "attacks blocked" and anything that only fills the page.
  • Give decisions their own section, so a request for an answer is not buried.

This template is for an agency or a freelancer who looks after a client's WordPress site and reports on it once a month. Copy it, fill in each stand-in in square brackets from your own records, and delete any section that covers work you do not do.

A client reads a report to learn three things: that the work was done, whether anything went wrong, and whether they need to do something. The template puts those first.

Before you use it

  • Decide where each figure comes from. For every line in the template, know which screen, log or tool you will read it from.
  • Keep a log during the month. One line per action, with the date: what was updated, what the client asked for and how long it took. A report written from memory has gaps.
  • Pick a day and keep to it. If your care plan proposal promised a report by a certain day, that is the day.
  • Report on what you do. If you do not monitor uptime, take that section out.

The template

text
WEBSITE MAINTENANCE REPORT

Client:       [CLIENT NAME]
Website:      [SITE ADDRESS]
Period:       [MONTH AND YEAR]
Prepared by:  [YOUR NAME OR AGENCY NAME]

1. THE MONTH IN ONE PARAGRAPH

[TWO TO FOUR SENTENCES: WHAT WAS DONE, WHETHER ANYTHING WENT
WRONG, AND WHETHER YOU NEED AN ANSWER FROM THE CLIENT]

2. WHAT WAS UPDATED

WordPress: [OLD VERSION] to [NEW VERSION] on [DATE]
Theme:     [THEME NAME], [OLD VERSION] to [NEW VERSION] on [DATE]
Plugins:
- [PLUGIN NAME], [OLD VERSION] to [NEW VERSION] on [DATE]
- [PLUGIN NAME], [OLD VERSION] to [NEW VERSION] on [DATE]
Held back: [PLUGIN NAME], [REASON], [WHEN WE LOOK AGAIN]
Checked after each round: [PAGES AND FUNCTIONS LOOKED AT]

3. BACKUPS

Backups taken:     [NUMBER], by [BACKUP TOOL]
Newest backup:     [DATE], database and files
Stored at:         [BACKUP LOCATION]
Last test restore: [DATE], [RESULT]

4. UPTIME

Monitor:  [MONITORING SERVICE], one check every [CHECK INTERVAL]
Uptime:   [FIGURE AS THE MONITOR REPORTS IT]
Outages:  [DATE], [DURATION], [CAUSE IF KNOWN], [WHAT WAS DONE]

5. SECURITY

Checked: [WHAT WAS CHECKED, AND WHEN]
Found:   [WHAT WAS FOUND]
Done:    [WHAT WAS DONE ABOUT IT]

6. CHANGES YOU ASKED FOR

- [DATE], [REQUEST], [TIME SPENT]
- [DATE], [REQUEST], [TIME SPENT]
Allowance used: [MINUTES USED] of [ALLOWANCE MINUTES] minutes

7. DECISIONS WE NEED FROM YOU

- [DECISION], [WHY IT MATTERS], [ANSWER NEEDED BY]

8. PLANNED FOR NEXT MONTH

- [PLANNED WORK]

How to fill it in

The rule for every section is the same: do not print a number you did not measure. Where you have no record, write "not measured" or "not recorded this month", and fix the record for next time.

The month in one paragraph. Write it last. Say what was done, name anything that went wrong, and say whether section 7 holds a question. A client who reads nothing else should still know where the site stands.

What was updated. The Updates screen, under Dashboard, lists what is waiting for WordPress, the plugins and the themes. When nothing is, it reads "Your plugins are all up to date." and "Your themes are all up to date."

For the version numbers, use Site Health, under Tools. Its Info tab gives the WordPress version, the active theme's version and the version of every active plugin, and it can copy all of that to the clipboard. Copy it before a round of updates and again after, and keep both. The differences between the two are your "from" and "to" columns.

If an update was held back or undone, say which and why. The method behind this section is in how to safely update WordPress.

Backups. Read the count and the newest date from the backup tool's own log or list of backups, or from the hosting panel if the host takes them. Do not multiply days by a schedule: a schedule that stopped on the ninth still says "daily". WordPress's documentation says a full restore needs both the database and the files, so confirm the newest backup holds both before you write that it does.

The test restore is the line clients skip and the one that matters most. Give the date you last restored a backup to a private copy of the site and what you saw. If you have never done it, write "not yet tested" and put it in section 8. The WordPress maintenance checklist describes the test, and WordPress backup plugins compared covers the tools.

Uptime. Copy the figure from the monitor, and name the monitor and how often it checks. A monitor that requests the site every five minutes can miss a two-minute outage, and the client should be able to tell what the figure rests on. List each outage with its date and length, and its cause if you know it. If there were none, write "none recorded".

Security. Three lines: what was checked, what was found, what was done. Two checks are inside WordPress. The Status tab of Site Health sorts its results into critical issues, recommended improvements and passed tests. The Users screen has links above its table that filter by role, so you can confirm that every administrator is someone you can name. Add the result of your scanner, by name. "Nothing that needed action" is a complete finding.

Changes you asked for. One line per request, from your log, with the time each took and the total against the allowance.

Decisions we need from you. One decision per line, with the reason and a date: a plugin that is no longer maintained, a license about to expire, a PHP version to change. If there are none, write "None this month" and keep the heading, so the client learns where to look.

Planned for next month. Only what you will do. It becomes the first thing you check when you write the next report.

What to leave out

  • Page-speed scores with no explanation. A PageSpeed Insights score comes from a simulated load of one page on a single device, and Google's own documentation lists reasons it varies between runs. A bare number invites a client to worry about a change of a few points. Include a speed figure only if you say which page was tested, what was measured and what you did about it.
  • Counts of "attacks blocked". A security plugin's dashboard counts the requests it turned away under its own rules. That is not a measure of risk: it does not say how many of those requests could have done harm, and a larger count next month does not mean the site was in more danger. Report what was checked and what was found.
  • Numbers you did not measure. No estimated uptime, no assumed backup count, no rounded-up hours.
  • Filler. Screenshots of dashboards, a list of every check that passed, a paragraph that is the same every month. Each one makes the line that matters harder to find.

If you would rather not write these yourself, a monthly report is part of every plan in our WordPress maintenance service, and agencies with three or more client sites can have it sent under their own brand by asking on the contact page.

Common questions

How long should the report be?

One page, two at most. The first paragraph and the decisions are what a client acts on. The rest is the record that backs them up.

What do I write when nothing happened?

That, in as few lines as it takes: no WordPress release, the plugins that were updated, the backups that ran, no outages recorded. A quiet month is what the client is paying for, and a short report says so better than a padded one.

Should I report an outage or a mistake of my own?

Yes, in the same plain way as everything else: the date, how long it lasted, what was done, and what you changed so it is less likely again. A client who learns of a problem from your report has reason to believe the rest of it.

Can a tool write the report for me?

A tool can collect the figures. Check each one against its source once, so you know what it counts. The first paragraph and the decisions need a person who knows the site.

More on this subject

White label for your agency

White label is from $22 a month per site. The Essential plan under your agency's brand, with branding included. Three sites or more. Tell us how many sites you look after.