How to monitor a WordPress site, and how often to check each part
WordPress site monitoring means checking, automatically and on a schedule, that a site is up, secure, fast, backed up and still taking enquiries, and hearing about it when it is not. Check uptime every minute, security daily, speed weekly and restores monthly. If you run several sites, manage multiple WordPress sites from one dashboard so every check reports to one place.

The short answer
WordPress site monitoring means checking a site automatically for the things that go wrong, and alerting a person only when something needs them. Watch these, at these intervals:
- Every minute: uptime and response time, from more than one location; sign-ins and new administrators as they happen.
- Daily: vulnerabilities, malware and changed files, backups, SSL certificate and domain expiry.
- Weekly: pending updates, speed and Core Web Vitals, forms and checkout.
- Monthly: a test restore, users and roles, Site Health.
WordPress's own Site Health covers configuration, but it cannot tell you when the site is down. For that you need checks from outside the site.
What is WordPress site monitoring?
WordPress site monitoring, or WordPress website monitoring, is the ongoing check that a site is up, secure, fast, backed up and still doing its job. It differs from a one-off audit in two ways: it runs on a schedule without anyone remembering to do it, and it tells you when a check fails instead of waiting for you to look.
Good monitoring looks at a site from two sides. From outside, it sees what visitors see: is the site answering, is the certificate valid, how fast does the page load. From inside, it sees what only WordPress knows: which plugins are installed and whether they have known holes, who signed in, whether last night's backup finished. You need both, because a site can look fine from outside while something is wrong inside, and the other way round.
What WordPress monitors on its own
WordPress includes a few monitoring tools. They help, but they all have the same blind spot.
- Site Health (since 5.2). Under Tools > Site Health, the Status tab lists critical issues and recommended improvements, such as an outdated PHP version, background updates that do not work or a failing loopback request. The Info tab lists your WordPress version, server, database, plugins and file permissions. Since 5.4, a dashboard widget shows the result and a weekly background check runs on its own. Site Health does not email anyone.
- Recovery mode (since 5.2). When a plugin or theme causes a fatal error, visitors see a "technical difficulties" message and WordPress emails the admin address a link that opens wp-admin with the faulty code paused. The link expires after a day by default.
- The debug log. With
WP_DEBUGandWP_DEBUG_LOGturned on, PHP errors are written towp-content/debug.log. WordPress's own documentation advises against running debug tools on live sites, so use it while you investigate, then turn it off.
The blind spot: all of this runs inside the site. If the server is down, the database is unreachable or the domain has lapsed, WordPress cannot send an alert. Its scheduler, WP-Cron, also only runs when someone visits a page, so on a quiet site scheduled checks can run late. That is why monitoring has to include checks from outside.
What to monitor on a WordPress site, check by check
1. Uptime and response time
Check that the site answers every one to five minutes, and alert when it does not. Check from more than one location, because a network problem between one monitor and your host looks exactly like an outage. Response time matters too: a site that takes eight seconds to answer is failing visitors before it fails completely. Our guide on how to monitor WordPress uptime covers intervals, locations and setup in detail.
2. SSL certificates
Certificate monitoring used to be a once-a-year concern. Not any more. The CA/Browser Forum, which sets the rules for public certificates, passed ballot SC-081v3 in April 2025. Certificates issued since 15 March 2026 last at most 200 days; from 15 March 2027 the limit drops to 100 days, and from 15 March 2029 to 47 days. Automatic renewal handles most of this, but every renewal is another chance for something to fail quietly. Check expiry daily and alert at least 14 days ahead.
3. Domain expiry
A lapsed domain takes the website and its email down together. Under ICANN's rules, registrars must send reminders about a month and a week before expiry, and after expiry they disrupt the domain's DNS before deleting it. For most generic domains there is then a 30-day redemption period, during which you can usually get the domain back for a fee. Reminders go to the registrant's email address, which on client sites is often an old one. Monitor expiry dates yourself.
4. Security: vulnerabilities, malware and sign-ins
The numbers explain why this check is daily. Patchstack's State of WordPress Security in 2026 report counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025, 42 percent more than in 2024. 91 percent were in plugins, 9 percent in themes, and only 6 were in WordPress core. Almost half had no fix from the developer in time for public disclosure, and for heavily exploited vulnerabilities the median time to the first attack was five hours.
So the useful security checks are: every installed plugin, theme and WordPress version matched against a vulnerability database daily; malware and changed core or plugin files; and sign-ins, including password guessing and new administrator accounts. Free security plugins help, with a catch worth knowing: Wordfence's free version gets new firewall rules and malware signatures 30 days after premium users. Also verify the site in Google Search Console, which emails verified owners when Google suspects the site has been hacked.
5. Updates waiting
Pending updates are the most common way into a WordPress site, so review them at least weekly and apply security releases quickly. If you let WordPress update on its own, read our guide to WordPress automatic updates for what it covers and what it misses.
6. Backups and restore tests
Check daily that the last backup finished and was stored away from the server. Once a month, restore a backup somewhere safe to prove it works. A backup that has never been restored is a hope, not a plan. Our WordPress backup guide covers what to include and how often.
7. Performance and Core Web Vitals
Google's Core Web Vitals measure loading (Largest Contentful Paint), responsiveness (Interaction to Next Paint, which replaced First Input Delay in March 2024) and visual stability (Cumulative Layout Shift). A page is "good" when LCP is within 2.5 seconds, INP is 200 milliseconds or less and CLS is 0.1 or less, measured at the 75th percentile of real visits. Real-visitor data comes from the Chrome UX Report, shown in PageSpeed Insights and Search Console; lab tools such as Lighthouse are useful for testing changes but cannot measure INP. Check weekly and after every round of updates, because a plugin update is the usual cause of a sudden slowdown. When a page fails, our guide on how to improve Core Web Vitals on WordPress covers the fixes.
8. Forms and checkout
A broken contact form still says "thank you". The failure is silent: the email never arrives and nobody notices until a client asks why enquiries stopped. Send a test submission weekly, or watch the enquiries themselves and treat a quiet week on a busy site as a warning. Our post on a WordPress contact form that has quietly stopped lists the usual causes. On WooCommerce, run a test order through checkout after updates.
9. Users, roles and Site Health
Once a month, look for administrator accounts you do not recognize, people who have left and accounts nobody has used in months. Our guide to WordPress user roles explains which role each person should have, and an audit log shows what they did with it. Open Site Health at the same time and fix any critical issues.
A WordPress monitoring schedule you can copy
Here is the whole routine in one table, with a free way to start on each check.
| Check | How often | Alert when | Free way to start |
|---|---|---|---|
| Uptime and response time | Every 1 to 5 minutes | Several locations agree it is down | Jetpack Monitor or another uptime checker |
| Sign-ins and new administrators | As they happen | An unknown admin appears or guessing succeeds | A security plugin |
| Vulnerabilities in plugins and themes | Daily | An installed version has a known hole | A security plugin or vulnerability service |
| Malware and changed files | Daily | Core or plugin files change unexpectedly | Wordfence free scan |
| Backups | Daily | A backup fails or is older than planned | Your backup plugin's email report |
| SSL certificate and domain | Daily | Expiry is less than 14 days away | Many uptime tools include it |
| Updates waiting | Weekly | Security updates are pending | Dashboard > Updates |
| Speed and Core Web Vitals | Weekly and after updates | A key page drops out of "good" | Search Console, PageSpeed Insights |
| Forms and checkout | Weekly | No enquiries or orders when there usually are | A test submission or test order |
| Restore test | Monthly | The backup does not restore | Restore to a test location |
| Users, roles and Site Health | Monthly | Unused admins or critical issues | Users screen, Tools > Site Health |
Our recommended baseline. Stores, membership sites and sites that earn money every hour need tighter checks.
To set it up on a single site, work through these steps in order:
- Add uptime monitoring. Check the home page and one key page every few minutes, from more than one location, with alerts by email.
- Watch SSL and domain expiry. Turn on certificate and domain expiry checks, with an alert at least 14 days ahead.
- Set up security checks. Use a security plugin or service that checks for known vulnerabilities daily and scans for malware and changed files.
- Verify the site in Google Search Console. Google then emails you about hacked content, manual actions and indexing problems.
- Make backups report back. Turn on failure emails in your backup tool and schedule a monthly test restore.
- Record a speed baseline. Note the Core Web Vitals for your key pages and test again after every round of updates.
- Send alerts to a person. Point every alert at an inbox someone reads, and review the quiet checks once a week.
WordPress monitoring tools
There is no single free WordPress monitoring tool that covers everything above. Most people combine a few:
| Job | Built in or free | For many sites at once |
|---|---|---|
| Configuration and errors | Site Health, recovery mode email, debug log | A platform that reads Site Health data per site |
| Uptime | Jetpack Monitor (5-minute checks), free tiers of uptime services | Uptime monitoring software or a platform |
| Security | Wordfence free (rules and signatures 30 days behind premium), Search Console security emails | A security service that checks every site daily |
| Performance | PageSpeed Insights, Search Console Core Web Vitals report | Scheduled tests with alerts on regressions |
| Backups | Your backup plugin's email reports | Central backup health with restore testing |
| Search visibility | Google Search Console | Search Console per property, plus your own reporting |
Facts on free tools from each vendor's own documentation, checked 10 October 2026.
On one site, that combination works. On ten, it means forty or fifty dashboards, logins and email streams, and the alert that mattered lands between twenty that did not.
Alerts that people trust
Monitoring only works if someone acts on the alerts. The fastest way to break that is noise: after a week of false alarms, people stop reading them. Three rules keep alerts worth reading:
- Confirm before alerting. An outage should be confirmed from more than one location before anyone is told. Jetpack Monitor, for example, rechecks a suspected outage from three servers in different places and only alerts if all three fail.
- Separate notes from alarms. A plugin updating its own files is a note. A new administrator at 3 a.m. is an alarm. Only alarms should interrupt someone.
- Send alerts to a person, not a shared inbox nobody owns. WordPress sends its own emails to the site's admin address. Make sure that address reaches someone who reads it.
Monitoring multiple WordPress sites from one dashboard
If you look after more than a handful of sites, the checks above stop fitting into anyone's week. The answer is to monitor multiple WordPress sites from one dashboard, where every site is checked the same way and only problems reach you. (Disclosure: WPCentrify is our product.)
We run WPCentrify on our own sites. The account we use day to day manages 18 WordPress sites with automated checks around the clock. On 10 October 2026, the morning we finished this guide, its dashboard showed 11 updates waiting for review across those sites. That is the kind of number that is easy to miss when each site has its own wp-admin, and obvious when they share one screen.
WPCentrify is a WordPress website management platform. For monitoring, it covers:
- Uptime monitoring every 60 seconds from three locations: Malaysia, Canada and the USA. An alert is sent only when locations on different providers agree, after three failed checks in a row, so a single network blip does not page anyone.
- SSL, domain expiry and DNS changes, plus content checks and specific URLs, not just the home page.
- Sentinel security monitoring checks every plugin, theme and WordPress version against a vulnerability database daily, looks for malware and tampered files, watches sign-ins and new administrators, and checks each site from outside. Each site gets one plain verdict: Safe, Needs attention, At risk or Hacked.
- Performance monitoring tracks Core Web Vitals and PageSpeed for every site, with alerts when a page gets slower after an update.
- Backups with restore testing. Backup health for every site in one view, with untested copies flagged and scheduled restore tests that boot the backup and record the result.
- Form enquiries from every site in one list, so a site that has gone quiet stands out before the client asks.
- Updates with risk scores and automatic rollback when an update causes a PHP fatal error, a 5xx error or a visual break.
- One fleet dashboard that opens on what needs attention, with email alerts when a person is needed, and an activity log of every change on every site.
Sources
- Site Health Screen, WordPress.org documentation, and Fatal error recovery mode in 5.2, Make WordPress Core
- Debugging in WordPress and Cron, WordPress developer documentation
- Ballot SC-081v3, CA/Browser Forum
- Expired Registration Recovery Policy, ICANN
- State of WordPress Security in 2026, Patchstack
- Web Vitals and INP becomes a Core Web Vital, web.dev
- Jetpack Monitor, Jetpack support, and Wordfence on WordPress.org
- Security issues report, Google Search Console Help
All sources checked on 10 October 2026.
Questions about WordPress site monitoring
WordPress site monitoring is the ongoing, automatic checking of a site for the things that go wrong: downtime, expiring SSL certificates and domains, security holes and malware, slow pages, failed backups, pending updates and broken forms. A good setup alerts a person only when something needs them.
Check uptime every one to five minutes, security, backups, SSL and domain expiry daily, updates, speed and forms weekly, and restore a backup and review users and Site Health monthly. Busy stores and high-risk sites need tighter checks.
Partly. Site Health (Tools, then Site Health) checks your setup and runs a weekly background test, but only shows results in the dashboard. Recovery mode emails the admin when a plugin or theme causes a fatal error. Nothing in WordPress tells you when the site is down, because a site that is down cannot send the alert.
No single free tool covers everything. A common free setup is Jetpack Monitor or another uptime checker for downtime, a security plugin such as Wordfence for scanning, Google Search Console for security and indexing problems, and Site Health for configuration. That works for one site but means several dashboards per site.
Use an uptime monitor that checks the site from outside every few minutes and emails or messages you when it stops responding. Choose one that confirms the failure from more than one location, so a brief network problem does not wake you up for nothing.
Certificates now expire faster. Since 15 March 2026 public SSL certificates last at most 200 days, falling to 100 days in March 2027 and 47 days in March 2029. More renewals mean more chances for one to fail, and an expired certificate makes browsers warn visitors away.
Check every plugin, theme and WordPress version against a vulnerability database daily, scan for malware and changed files, watch for new administrators and password guessing, and verify the site in Google Search Console so Google can email you about hacked content.
Use the Core Web Vitals report in Google Search Console and PageSpeed Insights for real visitor data, and run lab tests after updates. Good scores are LCP within 2.5 seconds, INP of 200 milliseconds or less and CLS of 0.1 or less.
Most false alerts come from checking from one location: a network problem between the monitor and your host looks like an outage. Monitors that recheck from several locations, and only alert when they agree, avoid most of them.
Yes. A WordPress management platform such as WPCentrify monitors uptime, SSL, security, performance, backups, updates and form enquiries for every connected site and shows them in one dashboard, with email alerts when something needs a person.
Related reading
Manage multiple WordPress sites
Updates, backups, uptime, security and reports for every site, from one dashboard.
See how it worksUptime monitoring software compared
Nine uptime tools compared on intervals, locations, alerts and price.
Read the comparisonSentinel security monitoring
One plain verdict per site, with daily vulnerability and malware checks.
See the featureMore on this topic: how to monitor WordPress uptime and WordPress uptime monitoring from three locations.
Monitor every WordPress site from one dashboard
Uptime, SSL, security, speed, backups, updates and enquiries for every site you manage, with email alerts only when something needs you.
Free during early access. No credit card required.