# Rehearse a WordPress restore without affecting production

Use a safe target and verify the selected backup and acceptance path before an incident. Check the named site's prerequisites, task result, backup scope and recovery handoff with xCloud.

Canonical: https://xcloud.host/use-cases/operations/rehearse-a-wordpress-restore-without-affecting-production/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Use a safe target and verify the selected backup and acceptance path before an incident.
For: site-owner, administrator

## Requirements and responsibilities

- Name the team, server, hostname, owner and affected users for the WordPress site. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud restore a WordPress backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/)
- Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud restore a WordPress backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/)
- For WordPress, verify the file and database backup scope and a safe target for recovery. Native scheduling, destination settings, staging synchronization and restore remain dashboard actions. Agree a maintenance window and owner before any action that interrupts the service or overwrites data. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud restore a WordPress backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/)
- A clone or recovered database may start scheduled jobs and carry live payment, booking, mail or webhook credentials. Arrange provider or network controls that prevent external side effects before the copied application can run. If the current xCloud flow cannot guarantee that isolation, use a sanitized fixture or postpone the clone; changing credentials after startup may be too late. Sources: [xCloud restore a WordPress backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Illustrative situation

A WordPress site has never been restored since launch. The operations lead wants a rehearsal that measures recovery time and tests login and a business action without touching production.

## Choose the approach

- Use an isolated target with restricted access and disabled live integrations. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud restore a WordPress backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/)
- A successful backup status is not evidence of restore until data and business tasks are checked. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud restore a WordPress backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/)

## Dashboard and application procedure

### 1. Set rehearsal objective

**Where:** Recovery runbook and production inventory

**Permissions:** Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.

**Inputs:** RTO goal, site ID, critical business flow

**Action:** Choose one recent completed backup and define what must work after restoration: admin login, page, media and a safe form or order test.

**Expected result:** A measurable rehearsal plan.

**Verify:** Confirm the target time and check list with the owner.

**If it fails:** If no accepted recovery target exists, document that before starting.

Capability: Confirm requirements and inspect resources
Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/)

### 2. Choose isolated destination

**Where:** xCloud site inventory and DNS

**Permissions:** Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.

**Inputs:** Disposable WordPress site, separate hostname

**Action:** Pick a destination with no valuable data, verify its own backup, and ensure no customer DNS points to it.

**Expected result:** A safe restore target.

**Verify:** Compare production and target site IDs aloud.

**If it fails:** If the destination has live data, choose another site.

Capability: Confirm requirements and inspect resources
Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/)

### 3. Quarantine the destination

**Where:** Target network and provider controls

**Permissions:** Infrastructure, network and provider owners able to quarantine the destination before its application starts.

**Inputs:** Mail, payment, webhook and public access routes

**Action:** Before restore, have infrastructure and provider owners block public traffic and outbound mail, webhook and payment access at controls the restored database cannot overwrite. Keep the destination stopped or inaccessible until confirmed.

**Expected result:** A restore target that cannot send live side effects as it starts.

**Verify:** Verify isolation from an external browser and provider test account.

**If it fails:** If isolation cannot be established, do not restore the production snapshot yet.

Capability: Quarantine a restore destination before application start
Sources: [xCloud restore a WordPress backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/)

### 4. Restore and time the process

**Where:** xCloud Previous Backups → Restore to Another Site

**Permissions:** Authorized xCloud site owner with dashboard rights for the exact setting, backup, staging or restore action and a reviewed target.

**Inputs:** Source snapshot, target ID, start time

**Action:** Apply the selected backup to the quarantined destination through the dashboard, recording start and terminal times. Reapply sandbox app credentials before allowing any test traffic.

**Expected result:** A restored, isolated test site and observed duration.

**Verify:** Check restore status and core content while quarantine remains active.

**If it fails:** If restore fails, preserve logs and backup; do not retry on production.

Capability: Restore a backup
Sources: [xCloud restore a WordPress backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### 5. Validate and close gaps

**Where:** Restored WordPress site and runbook

**Permissions:** Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Known records and limited test user

**Action:** Test login, content, media and representative business action. Record elapsed time, missing external data and any manual repair.

**Expected result:** An honest recovery result against target time.

**Verify:** Compare sample record IDs and snapshot age to production baseline.

**If it fails:** If time or data falls short, assign a corrective action and schedule another rehearsal.

Capability: Configure and test WordPress in its administrator UI
Sources: [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/)

## Maintenance

- Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud restore a WordPress backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/)
- Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud restore a WordPress backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/)

## Recovery decisions

- Before data recovery, identify incident time, completed backup, target and records created after the snapshot. Preserve current evidence and live data before replacement. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud restore a WordPress backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/)
- Use the documented dashboard or application recovery procedure with the authorized owner. Repeat the task-specific limited-user check; reconcile newer records before reopening writes. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [xCloud restore a WordPress backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/)

## AI handoff

Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### Copyable agent brief

```text
Read source site, completed backup and safe destination identities. Return snapshot age, expected loss and rehearsal checklist. Do not restore through MCP or touch production; the owner approves a dashboard restore to the isolated target.
```

### Manual checkpoints

- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized WordPress administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.

## Feature coverage

- **restore-rehearsal decision, evidence and task action** (covered): The procedure identifies the authorized task boundary and observable result. Steps: step-1, step-2, step-3, step-4
- **backup, ongoing operation and recovery** (covered): Recovery and maintenance are checked in the task procedure. Steps: step-4, step-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/) — reviewed 2026-09-30
- [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/) — reviewed 2026-09-30
- [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/) — reviewed 2026-09-30
- [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/) — reviewed 2026-09-30
- [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/) — reviewed 2026-09-30
- [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/) — reviewed 2026-09-30
- [xCloud restore a WordPress backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/) — reviewed 2026-09-30

## Continue

[Explore all use cases](https://xcloud.host/use-cases/)

- [Manage WordPress plugin updates and security checks](https://xcloud.host/use-cases/operations/wordpress-plugin-updates-and-security/)
- [Release WordPress staging changes without losing live data](https://xcloud.host/use-cases/playbooks/wordpress-staging-release-with-live-data/)
