WordPress website testing checklist

Download as Excel (.xlsx)

WordPress problems have a pattern: a setting left from development, a plugin that conflicts after an update, a page builder layout that was only ever checked on desktop. This checklist adds the WordPress-specific checks to a general website test. Run it before launch and after every major theme, plugin or core update. Download it as a spreadsheet.

Settings left from development

  • “Discourage search engines from indexing this site” is off — Settings → Reading
  • Site Address and WordPress Address use the live HTTPS domain — Settings → General
  • Permalinks are set to the intended structure — Settings → Permalinks; save once after migration
  • Debug mode is off on the live site — WP_DEBUG false in wp-config.php
  • No test posts, pages, users or orders are published — check drafts and trash too
  • The admin e-mail is a real, monitored address — Settings → General

Theme and page builder

  • Every template works at 320 to 430 px — page builder mobile settings per section
  • Sections hidden on mobile are not hiding important content — check the responsive visibility settings
  • Headers, footers and menus work on phones — the mobile menu opens and closes
  • The child theme is used for customisations — so theme updates do not overwrite them
  • Custom CSS does not use fixed widths that break on phones — search for width: px values

Plugins

  • Every active plugin is needed and up to date — remove what you do not use
  • No plugin errors in the browser console or the PHP error log — after updates
  • Contact forms send and arrive — test each form plugin
  • SMTP is configured so e-mails do not land in spam — test with an external inbox
  • Caching and optimisation plugins do not break layouts or scripts — test with the cache on
  • The first image on the page is not lazy-loaded by an optimisation plugin — slows LCP

SEO plugin

  • Post types and taxonomies you want in Google are set to index — Yoast, Rank Math or similar
  • Tag, author and date archives are noindex or useful — thin archives
  • Only one plugin writes titles, canonicals and schema — two SEO plugins duplicate tags
  • The XML sitemap works and lists only indexable pages — /sitemap_index.xml or /wp-sitemap.xml
  • Breadcrumbs and Organization schema are configured — in the SEO plugin

Speed

  • Page caching is on and pages are served from cache — check response headers
  • Images are resized and served as WebP or AVIF — media settings or an image plugin
  • Unused scripts and styles are not loaded on every page — page builders and sliders
  • Mobile LCP is under 2.5 s on key pages — PageSpeed Insights

Security and maintenance

  • WordPress core, themes and plugins are current — and auto-updates set as intended
  • Admin accounts use strong passwords and two-factor login — remove unused admins
  • The login page is protected against brute force — a security plugin or host rule
  • File editing in the dashboard is disabled on the live site — DISALLOW_FILE_EDIT
  • Automatic off-site backups run and a restore has been tested — not only stored on the same server
  • The server reveals no version details in headers — X-Powered-By, Server