# Audit WordPress production and staging separation

Confirm domains, credentials, data, and indexing controls for each environment. Check the named site's prerequisites, task result, backup scope and recovery handoff with xCloud.

Canonical: https://xcloud.host/use-cases/operations/audit-wordpress-production-and-staging-separation/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Confirm domains, credentials, data, and indexing controls for each environment.
For: site-owner, administrator

## Requirements and responsibilities

- Name the team, server, hostname, owner and affected users for the WordPress site. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)
- Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)
- For WordPress, verify the file and database backup scope and a safe target for recovery. Native scheduling, destination settings, staging synchronization and restore remain dashboard actions. Agree a maintenance window and owner before any action that interrupts the service or overwrites data. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)
- A clone or recovered database may start scheduled jobs and carry live payment, booking, mail or webhook credentials. Arrange provider or network controls that prevent external side effects before the copied application can run. If the current xCloud flow cannot guarantee that isolation, use a sanitized fixture or postpone the clone; changing credentials after startup may be too late. Sources: [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Illustrative situation

A WordPress staging site was cloned months ago and may still point at live booking and email services. The operator audits its separation before testers use it again.

## Choose the approach

- A different URL is necessary but insufficient: app credentials, indexing, webhook and outbound mail also matter. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)
- Any push/pull action is a separate change that can overwrite newer production data. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)

## Dashboard and application procedure

### 1. Map environments

**Where:** xCloud Sites and WordPress settings

**Permissions:** Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.

**Inputs:** Production/staging IDs, URLs, clone time

**Action:** Confirm which site is production and which is staging. Record versions and domains and test signed-out routes.

**Expected result:** An unambiguous environment map.

**Verify:** Compare dashboard IDs and WordPress site URLs.

**If it fails:** If identities are unclear, prohibit synchronization until resolved.

Capability: Confirm requirements and inspect resources
Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)

### 2. Check access and indexing

**Where:** Staging WordPress and external browser

**Permissions:** Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Test account, robots state, basic access

**Action:** Verify staging requires intended access and inspect actual search-engine visibility and public links. Do not assume xCloud sets noindex constants.

**Expected result:** A private test environment.

**Verify:** Open staging in a signed-out session and inspect response metadata.

**If it fails:** If staging is public or indexable unintentionally, restrict it before test data use.

Capability: Configure and test WordPress in its administrator UI
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)

### 3. Inspect integration endpoints

**Where:** Staging plugin settings and providers

**Permissions:** Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Payment keys, SMTP, booking calendar, webhooks

**Action:** Compare staging credentials and endpoint URLs with production. Replace or disable live side effects using app admin controls.

**Expected result:** A sandboxed integration map.

**Verify:** Submit a harmless test and check only test recipients/systems.

**If it fails:** If any live effect occurs, stop tests and investigate affected records.

Capability: Configure and test WordPress in its administrator UI
Sources: [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)

### 4. Check data freshness and push scope

**Where:** xCloud Manage Staging; WooCommerce if used

**Permissions:** Authorized xCloud site owner with dashboard rights for the exact setting, backup, staging or restore action and a reviewed target.

**Inputs:** Clone time, current production records, sync direction

**Action:** Read available push/pull options and note data classes that have changed since clone, especially orders, bookings and members.

**Expected result:** A safe synchronization recommendation.

**Verify:** Compare recent production IDs to staging.

**If it fails:** If staging DB is older, prohibit database push without reconciliation.

Capability: Create and synchronize WordPress staging
Sources: [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### 5. Record operating rules

**Where:** Staging runbook and agency ticket

**Permissions:** Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.

**Inputs:** Refresh cadence, owners, allowed test data

**Action:** Document who can refresh, push or pull staging and which integrations must be isolated after every clone.

**Expected result:** An auditable separation policy.

**Verify:** Have a tester verify the checklist before next use.

**If it fails:** If isolation cannot be guaranteed, retire the stale copy and create a fresh safe staging site.

Capability: Confirm requirements and inspect resources
Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)

## Maintenance

- Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)
- Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)

## Recovery decisions

- If staging sends to a live provider, stop the integration, identify affected recipients and records, and have its owner correct them in the provider or application. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)
- Rebuild or refresh the isolated staging copy only after suppressing side effects; check newer production records before any push or pull. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)

## AI handoff

Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### Copyable agent brief

```text
Read exact production/staging IDs, versions, backup times and current status. Return an isolation and synchronization risk matrix. Do not push or pull through MCP; app administrator must verify integration endpoints and indexing state.
```

### Manual checkpoints

- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized WordPress administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.

## Feature coverage

- **staging-audit decision, evidence and task action** (covered): The procedure identifies the authorized task boundary and observable result. Steps: step-1, step-2, step-3, step-4
- **backup, ongoing operation and recovery** (covered): Recovery and maintenance are checked in the task procedure. Steps: step-4, step-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/) — reviewed 2026-09-30
- [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/) — reviewed 2026-09-30
- [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/) — reviewed 2026-09-30
- [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/) — reviewed 2026-09-30
- [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/) — reviewed 2026-09-30
- [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/) — reviewed 2026-09-30
- [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/) — reviewed 2026-09-30

## Continue

[Explore all use cases](https://xcloud.host/use-cases/)

- [Manage WordPress plugin updates and security checks](https://xcloud.host/use-cases/operations/wordpress-plugin-updates-and-security/)
- [Release WordPress staging changes without losing live data](https://xcloud.host/use-cases/playbooks/wordpress-staging-release-with-live-data/)
