Setting the Foundation for Success
Before we begin managing your WordPress site, we require specific server configurations, access levels, and baseline security measures. These requirements ensure optimal performance, reliable backups, seamless updates, and robust protection against threats. If your current setup doesn't match these standards, our team can help migrate or reconfigure your environment at no extra cost.
Server & Hosting Environment
Infrastructure prerequisites
- PHP version 8.1 or higher (8.2 recommended)
- MySQL 5.7+ or MariaDB 10.3+ with InnoDB engine
- Valid SSL/TLS certificate installed & active
- cPanel, Plesk, or SSH/FTP access enabled
- Server timezone correctly configured
- Minimum 1GB RAM & 2GB free disk space
Note: Shared hosting with restrictive resource limits or outdated control panels may require migration to a compatible environment.
WordPress & Software Stack
CMS & plugin standards
- WordPress core updated to latest stable version
- Well-coded, responsive theme (preferably with child theme)
- Maximum 25 active plugins (optimized stack)
- No deprecated or abandoned plugins (>2 years old)
- PHP error reporting disabled for public access
- Permalinks properly configured (not default)
Optimization: We recommend LiteSpeed or Nginx for superior request handling and caching performance.
Access & Credentials
What we need to manage your site
- WordPress Administrator login credentials
- Hosting account login (cPanel/Plesk/SSH)
- FTP/SFTP credentials (if required by host)
- DNS management access (for CDN/SSL configs)
- Third-party service logins (email, analytics, etc.)
- Two-Factor Authentication setup completed beforehand
Security: All credentials are stored in encrypted vaults with zero-knowledge architecture. We never share or reuse access.
Security & Compliance
Pre-onboarding security checklist
- Site clean from malware, spam, and unauthorized users
- Strong password policy enforced (12+ chars, mixed)
- Admin URLs not publicly exposed (custom /wp-login.php)
- XML-RPC disabled if not actively used
- GDPR/CCPA compliance basics in place (if applicable)
- No disabled core security features (e.g., file editing)
Our Role: If your site fails security baseline, we perform a mandatory audit & cleanup before activation.
Recommended Optimal Stack
Ideal configuration for peak performance
- Managed WordPress Hosting (Cloudways, Kinsta, WP Engine, or equivalent)
- Redis or Memcached Object Caching enabled
- Full-page caching with edge CDN (Cloudflare/StackPath)
- Automatic daily backups with off-site replication
- Staging environment with 1-click deployment
- Server-level security headers & WAF rules configured
Flexibility: These are recommendations, not hard requirements. We optimize within your existing infrastructure whenever possible.