Skip to content

WordPress launch checklist: what to check before a site goes live

A checklist for the days before a new or rebuilt WordPress site opens to the public. It covers content, settings, accounts, security, speed, search, forms and email, a store, and legal pages, in the order that catches the most with the least work.

By
WP Ministry
Updated

In short

  • Untick the box that asks search engines to stay away. Nothing on the front of the site shows that it is still ticked.
  • Send a real message through every form and receive it. A thank-you message proves nothing about the email.
  • Delete test users, and give every administrator a strong password and a second step at login.
  • Restore a backup once, to a private copy, before you rely on it.
  • On a store, test each payment method in its test mode before you open, then check that it is live without paying by card.
  • Set the administration email to an address your organization reads.

Use this checklist in the days before a new or rebuilt WordPress site opens to the public. Most of what goes wrong at a launch is something left the way it was during the build: a setting, a test account, a form that mails the developer. If the site replaces one on another host or platform, use the website migration checklist as well.

Content

  • Replace placeholder text and images. Search the site for "lorem" and for the theme's demo names, because visitors and search engines read demo pages as yours.
  • Delete sample posts, demo pages and test products. Anything published is public, wanted or not.
  • Give every page a title of its own. A page called "Home" or "New page" tells nobody what it is.
  • Open every link in the menus and the footer. Links made during the build can still point at the temporary address.
  • Look at each kind of page on a phone. A layout that holds on a wide screen can break on a narrow one.

Settings

  • Check the site title and tagline. They are under Settings, then General. Most themes show the title at the top of every page and in the browser's title bar.
  • Check the two addresses. "WordPress Address (URL)" and "Site Address (URL)" should hold the real domain, with https://. To change them, see how to change a WordPress URL.
  • Set "Administration Email Address" to one your organization reads. WordPress sends recovery mode and critical error notices there. A new address takes effect only once the link in the confirmation email is followed.
  • Choose the time zone by city. WordPress's documentation says to pick a city in your own time zone. The setting decides how dates and times are worked out and shown.
  • Untick "Anyone can register" unless the site takes sign-ups. Nobody should be able to make an account you did not plan for.
  • Settle the permalinks. Under Settings, then Permalinks, choose the structure, such as "Post name", before launch. WordPress's documentation says a post's address should be permanent and never change.
  • Untick "Discourage search engines from indexing this site". It is under Settings, then Reading. While it is ticked, WordPress adds a noindex tag to the site's pages and switches its sitemap off.

Accounts

  • Delete test users and spare logins. Go to Users and use the role links above the table. WordPress asks what to do with the posts an account owns. Attribute them to a real user, because the other choice deletes them.
  • Give each person the lowest role that lets them do their work. The WordPress security guide explains the roles.
  • Give every administrator a strong, unique password and a second step at login. See how to set up two-factor authentication in WordPress.

Security and upkeep

  • Apply the updates that are waiting. A site should not open with known holes. The method is in how to safely update WordPress.
  • Schedule backups that are kept off the server, and restore one. Restore it to a private copy, never over the live site. A backup that has not been restored is unproven. See WordPress backup plugins compared.
  • Open the site with http:// and see that it lands on https://. Then look for a browser warning on a few pages. If parts of a page are missing, see mixed content warnings.
  • Read Site Health. It is under Tools, then Site Health. Clear every critical issue. One of them is a site set to display errors to visitors, which is debugging left on from the build.

Speed

  • Switch on caching, then browse logged out. Use a private window, because that is what visitors get.
  • Shrink oversized images. A photo straight from a camera is far larger than a page needs.
  • Measure the home page and one page that matters. Write the numbers down. They are the baseline the WordPress maintenance checklist compares against each quarter.
  • Open the sitemap. WordPress's own is at /wp-sitemap.xml, unless an SEO plugin provides a different one. WordPress switches it off while search engines are discouraged.
  • Add the site to Google Search Console. You have to prove you own the site. Google starts collecting data as soon as the property is added.
  • Submit the sitemap there. Google calls a submitted sitemap a hint and not a guarantee. Its Sitemaps report shows when the file was read and any errors in it.
  • Check the home page from outside. The WordPress site health check shows, among other things, whether a page asks search engines not to list it.

Forms and email

  • Send a real message through every form and receive it. Send from an address outside your own domain. A form can show its thank-you message while the email goes nowhere. If nothing arrives, see WordPress not sending email.
  • Check where each form sends. It should not still be the developer's address.

A store, if there is one

  • Place a test order with each payment method in its test mode. WooCommerce's documentation says many payment gateways have a sandbox or testing mode, and that test payments belong on a staging site, not a live one. Do it before the site opens. Check that the order reaches "Processing", the status WooCommerce gives once payment is received, and that the order emails arrive. If the checkout fails, see WooCommerce checkout not working.
  • Switch each payment method from test mode to live. A store left in test mode takes no money.
  • Check the live connection without a card. Each gateway's settings should show a live connection with test mode off, and the provider's dashboard should show no notice on your account. Then watch the first real order reach "Processing".
  • Read your provider's rules before you pay with your own card. Stripe's testing documentation says its services agreement prohibits testing in live mode using real payment method details.
  • Delete the test orders. WooCommerce gives them no special status, so nothing stops one from being shipped or counted in your reports.
  • Publish a privacy policy, name it under Settings, then Privacy, and link it from the footer. WordPress's documentation says it is your responsibility to keep that page current and accurate.
  • Add the other pages your business needs. Terms, a refund policy on a store, a notice about cookies. Which ones the law requires depends on where you and your customers are, so ask a lawyer.

What people forget

  • The temporary address inside the content. Images and links can still point at the build's address, and they work until that copy is deleted.
  • The build copy itself. Delete it, or keep it behind a password.
  • A backup taken after the last change. The one from the middle of the build is not the site you launched.
  • The day after. Launch is where upkeep starts. Put the weekly round from the maintenance checklist in your calendar.

If you would rather hand that upkeep over, our WordPress maintenance service is a monthly care plan that keeps one WordPress site updated, backed up, monitored and scanned.

Common questions

Which checks matter most if I am short of time?

Three. Untick the search engine box, send a real message through every form, and restore a backup once. Each one fails silently.

How soon will the site show in Google?

Nobody can promise a date. Adding the site to Search Console and submitting a sitemap tells Google the pages exist, and Google describes a sitemap as a hint.

The site is already live. Is it too late for this?

No. Every item can be checked on a live site. Start with the search engine box, the forms and the backups.

Is there a good day to launch?

A day when someone will be around afterwards to watch the forms, the orders and the inbox.

More on this subject

Not sure what is wrong?

Tell us what you see. We reply with the cause and a fixed quote, and the diagnosis is free.