WordPress Pre-launch Checklist

Use this checklist before a new WordPress site or migration begins receiving production traffic. It is a verification aid, not a guarantee of availability, security, accessibility, search visibility, legal compliance, or business results.

The checkboxes run only in this browser tab. They are not submitted, stored, tracked, or restored after a refresh. Use the print button to create a paper copy or save a local PDF without providing an email address.

Scope note: the Wangdada Labs local non-production rehearsal did not test real DNS delegation, public TLS issuance, production email delivery, CDN behavior, payment processing, or live traffic. Those items must be verified in the actual production environment.

Benchmark & Verification Baseline - Audit Reference: WordPress 6.6+ production stack, PHP 8.2/8.3 official runtime requirements (WordPress Hosting Requirements). - Evaluation Date: Updated 2026-09-04 with multi-region DNS cutover and TLS termination protocols. - Primary Focus: Minimizing post-migration downtime, avoiding mixed content lockouts, and securing rollback capability.

1. Backup and restore readiness

WordPress treats files and database as separate parts of a complete backup. Review the official WordPress backup guidance and use the hosting backup, migration, and support evaluation guide to verify the provider's restore boundary.

2. HTTPS and transport security

3. Canonical URLs and redirects

Follow the full website migration checklist when a launch changes hosting, domain, path, or URL structure.

4. Robots, sitemap, and Search Console

Google documents canonical signals, redirects, robots controls, and sitemap submission in its official Search documentation.

5. Forms and transactional email

6. Login, roles, and updates

7. Performance and accessibility

The W3C Web Accessibility Initiative explains that automated checks cover only part of accessibility evaluation. Use its official evaluation resources as a starting point.

8. Privacy and cookies

9. Logs, monitoring, and rollback

10. DNS and traffic cutover

11. Launch ownership and final sign-off


12. Frequently Asked Questions

What are the most critical technical checks before taking WordPress live?

The three non-negotiable verification gates are: (1) an off-server database and uploads backup with tested restore capability, (2) automated HTTPS redirect without mixed content errors, and (3) a verified robots.txt and XML sitemap that do not accidentally block search engines.

Why is an off-site backup required if the host provides daily backups?

Hosting-managed backups frequently share the same physical server or user account. If the account is suspended for resource overuse, hacked, or suffers filesystem corruption, local backups are inaccessible. An off-site export (e.g. to Amazon S3, Cloudflare R2, or remote SFTP) guarantees business continuity.

How do I verify DNS cutover without experiencing cached records?

Use external multi-location DNS resolvers (such as Google 8.8.8.8, Cloudflare 1.1.1.1, or dig +trace) rather than local browser cache. Lowering the TTL to 300 seconds (5 minutes) 24 hours prior to cutover ensures global resolvers refresh rapidly once new IPs are published.

If the launch changes your operating model, use the Small Website Hosting Total Cost Calculator to include maintenance time, backup services, support, and migration work in the decision.