Setting up managed WordPress hosting correctly from the start prevents configuration headaches, security gaps, and performance issues down the road. This checklist walks you through every step from selecting a provider to launching your site, with the commands and configurations you need along the way.
Pre-Setup: Planning and Provider Selection
1. Define Your Requirements
Before signing up for any managed WordPress host, document:
- Expected monthly traffic and concurrent users
- Number of WordPress sites you'll run
- Required PHP version and WordPress version compatibility
- Staging environment needs
- Geographic location of your primary audience
- Compliance requirements (PCI, HIPAA, GDPR)
2. Verify Provider Features
Confirm your chosen managed WordPress host includes:
- Automatic WordPress core updates with rollback capability
- Daily automated backups with point-in-time restore
- Staging environments for testing changes
- CDN integration or built-in edge caching
- SSH and WP-CLI access for command-line management
- Git integration for version control workflows
- PHP version management with easy switching
- Object caching (Redis or Memcached)
- Server-level security including malware scanning
3. Gather Access Credentials
Collect and store securely:
- Domain registrar login
- DNS provider credentials
- Hosting account credentials
- FTP/SFTP details (if provided)
- Database access information
- SSH keys or password
Step 1: Initial Account Setup
Configure Your Hosting Account
Log into your managed WordPress hosting dashboard and:
- Set a strong account password using a password manager
- Enable two-factor authentication on your hosting account
- Add your SSH public key to the account for passwordless access
- Configure notification preferences for backups, updates, and security alerts
- Set your timezone to match your primary work location
Create Your First WordPress Instance
Most managed hosts offer a one-click WordPress installer. Provide:
- Site name and tagline
- Admin username (avoid "admin" or "administrator")
- Strong admin password
- Admin email address
- Preferred WordPress version (usually latest stable)
Step 2: DNS Configuration
Point Your Domain to the Hosting
Depending on your setup, you'll either:
Option A: Change Nameservers (recommended for full DNS management):
- Get nameserver addresses from your hosting provider
- Log into your domain registrar
- Update nameservers to those provided
- Wait for propagation (typically 4-24 hours)
Option B: Update A and AAAA Records:
- Get IP addresses (IPv4 and IPv6) from your host
- Add A record:
@ IN A <IPv4-address> - Add AAAA record (if provided):
@ IN AAAA <IPv6-address> - Add www subdomain:
www IN CNAME yourdomain.com.
Verify DNS Propagation
Check DNS resolution from multiple locations:
dig yourdomain.com +short
dig www.yourdomain.com +short
Or use online tools to check global propagation status.
Step 3: SSL/TLS Certificate Setup
Enable HTTPS
Most managed WordPress hosts auto-provision Let's Encrypt certificates:
- Navigate to SSL/TLS settings in your hosting dashboard
- Click "Enable SSL" or "Provision Certificate"
- Wait for automatic certificate issuance (usually under 5 minutes)
- Verify certificate installation:
openssl s_client -connect yourdomain.com:443 -servername yourdomain.com < /dev/null 2>/dev/null | openssl x509 -noout -dates
Force HTTPS Redirect
Ensure all HTTP traffic redirects to HTTPS. Most managed hosts handle this at the server level, but verify in your WordPress settings:
- Log into WordPress admin
- Navigate to Settings → General
- Update both URL fields to use
https:// - Save changes
If you need manual control, add to your .htaccess (Apache) or verify nginx configuration:
# Force HTTPS (Apache)
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}/$1 [R=301,L]
Configure HSTS
For enhanced security, enable HTTP Strict Transport Security. Check if your host applies this by default:
curl -I https://yourdomain.com | grep -i strict-transport
If not present and you need it, add via your host's control panel or request support enable it.
Step 4: WordPress Core Configuration
Update WordPress Settings
-
General Settings (Settings → General): - Site Title and Tagline - Timezone - Date and time format - Set appropriate site language
-
Permalink Structure (Settings → Permalinks): - Choose SEO-friendly structure:
/%postname%/or/%category%/%postname%/- Avoid default?p=123structure -
Reading Settings (Settings → Reading): - Set homepage display (posts or static page) - Configure posts per page - Discourage search engines during development
Secure wp-config.php
Connect via SSH or SFTP and verify wp-config.php security:
ssh [email protected]
cd public_html # or your WordPress root
ls -la wp-config.php
Ensure permissions are 644 or 640:
chmod 640 wp-config.php
Add security keys if not already present (use the WordPress secret key generator):
define('AUTH_KEY', 'put your unique phrase here');
define('SECURE_AUTH_KEY', 'put your unique phrase here');
define('LOGGED_IN_KEY', 'put your unique phrase here');
define('NONCE_KEY', 'put your unique phrase here');
// ... additional keys
Disable File Editing
Prevent plugin and theme editing from the WordPress admin:
// Add to wp-config.php
define('DISALLOW_FILE_EDIT', true);
Step 5: Security Hardening
Change Default Admin Username
If you used "admin" during setup:
- Create a new admin user with a strong, unique username
- Log out and log in as the new user
- Delete the old "admin" account, attributing posts to the new user
Limit Login Attempts
Most managed hosts include brute-force protection, but verify:
- Check if login attempt limiting is enabled by default
- Configure IP allowlisting for admin access if your IP is static
- Enable notifications for suspicious login activity
Configure Security Headers
Verify your host sets appropriate security headers:
curl -I https://yourdomain.com | grep -E '(X-Frame-Options|X-Content-Type-Options|Referrer-Policy)'
Expected headers:
- X-Frame-Options: SAMEORIGIN
- X-Content-Type-Options: nosniff
- Referrer-Policy: strict-origin-when-cross-origin
Install Security Plugin
Even with managed hosting security, install a WordPress security plugin:
wp plugin install wordfence --activate
# or
wp plugin install sucuri-scanner --activate
Configure: - Enable firewall rules - Schedule malware scans - Set up security notifications - Configure two-factor authentication for all admin users
Step 6: Performance Optimization
Enable Object Caching
If your host provides Redis or Memcached:
wp plugin install redis-cache --activate
wp redis enable
Verify caching is working:
wp redis status
Configure CDN
If your host includes CDN integration:
- Enable CDN in your hosting dashboard
- Note the CDN URL provided
- Install a CDN plugin if needed (many hosts auto-configure this)
- Purge cache after enabling
Install Caching Plugin
While managed hosts provide server-level caching, page caching plugins help:
wp plugin install wp-rocket --activate
# or use your host's recommended caching plugin
Configure: - Enable page caching - Enable GZIP compression (if not server-level) - Lazy load images - Minify CSS and JavaScript - Defer JavaScript loading
Optimize Images
Install an image optimization plugin:
wp plugin install ewww-image-optimizer --activate
Configure bulk optimization and automatic optimization on upload.
Step 7: Backup Configuration
Verify Automatic Backups
Confirm your host's backup schedule:
- Backup frequency (daily recommended)
- Retention period
- Backup scope (files, database, or both)
- Restore testing capability
Test Backup Restore
Before going live, test the restore process:
- Create a manual backup
- Make a visible change to your site (add a test post)
- Restore from the backup you created
- Verify the test post is gone and site is restored
Configure Off-Site Backups
For critical sites, add an additional backup layer:
wp plugin install updraftplus --activate
Configure UpdraftPlus to send backups to: - Amazon S3 - Google Drive - Dropbox - Remote FTP/SFTP
Step 8: Staging Environment Setup
Create Staging Site
Use your host's staging feature:
- Navigate to staging section in hosting dashboard
- Click "Create Staging Environment"
- Wait for staging site provisioning
- Note the staging URL (usually
staging.yourdomain.comoryourdomain.com/staging)
Configure Staging Workflow
Set up your deployment process:
- Make all changes and test in staging first
- Use your host's push-to-production feature when ready
- Document which files/databases to sync
- Schedule staging-to-production pushes during low-traffic periods
Step 9: Monitoring and Maintenance
Enable Uptime Monitoring
Set up external monitoring:
- Use your host's included uptime monitoring
- Add a third-party monitor (UptimeRobot, Pingdom) for redundancy
- Configure alerts via email and SMS
- Set check interval to 5 minutes or less
Configure Performance Monitoring
Enable application performance monitoring:
- Check if your host provides built-in APM
- Review dashboard metrics regularly: response time, PHP errors, database query time
- Set up alerts for performance degradation
Set Update Schedule
Establish a maintenance routine:
- Weekly: Review security logs, check backup success, monitor performance metrics
- Monthly: Update plugins and themes in staging, test, then push to production
- Quarterly: Review hosting resources, check SSL expiry dates, audit user accounts
Step 10: Pre-Launch Checklist
Before making your site public:
- [ ] All DNS records pointing correctly
- [ ] SSL certificate installed and HTTPS enforced
- [ ] All placeholder content removed
- [ ] Contact forms tested and receiving email
- [ ] Search engine discouragement disabled (Settings → Reading)
- [ ] Google Analytics or tracking configured
- [ ] 404 page customized
- [ ] Privacy policy and legal pages published
- [ ] Mobile responsiveness tested
- [ ] Cross-browser compatibility verified
- [ ] Page load speed tested (under 3 seconds target)
- [ ] Broken link check completed
- [ ] SEO plugin configured (Yoast or Rank Math)
- [ ] XML sitemap submitted to Google Search Console
- [ ] Backup confirmed working
- [ ] Admin accounts secured with 2FA
- [ ] User roles and permissions reviewed
Conclusion
Managed WordPress hosting simplifies many technical tasks, but proper setup remains critical for security, performance, and reliability. Follow this checklist systematically, document your configuration choices, and test everything in staging before production deployment. Regular maintenance and monitoring ensure your managed WordPress site remains fast, secure, and available. The upfront time investment in correct configuration prevents troubleshooting headaches and security incidents down the road.
