# Recover a WordPress site from backup

Select a recovery target and validate the restored site and its business data. The recovered copy logs in and contains agreed representative content.

Canonical: https://xcloud.host/use-cases/playbooks/recover-a-wordpress-site-from-backup/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Select a recovery target and validate the restored site and its business data.
For: business-owner, operator

## Requirements and responsibilities

- Have named ownership of the domain, selected xCloud team and site, and WordPress administrator access. For this scenario, agree who supplies the data and signs off: A content site becomes unusable after a release and the last backup predates new posts. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
- Use a compatible Nginx or OpenLiteSpeed stack for native WordPress. Verify current server resources, plan eligibility and each selected plugin or service license and requirements before installing; a Docker server does not host a new native WordPress site. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)
- Prepare a safe test identity and a completed, accessible backup before consequential changes. The important failure to plan around is: In-place restore overwrites newer posts, comments and form records. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/)
- Before a source copy or backup restore starts, the authorized operator must restrict the target and quarantine outbound mail, payment, fulfillment and other provider effects at the receiving environment. Restored WordPress settings can overwrite plugin suppression; reapply sandbox credentials and verify isolation before tests. Sources: [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/)

## Illustrative situation

Illustrative scenario, not a customer case study: A content site becomes unusable after a release and the last backup predates new posts. The recovered copy logs in and contains agreed representative content.

## Choose the approach

- Choose an alternate restore target first when investigation can continue safely. Verify the selected provider or plugin documentation and license against this requirement; xCloud hosting does not supply its business configuration. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/)
- Keep application setup, domain/DNS ownership, mail delivery and external integrations with their named administrators. Use a plain documented path when a proposed integration cannot be demonstrated end to end. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)

## Dashboard and application procedure

### 1. Establish incident and data delta

**Where:** xCloud selected team/site resource view and owner planning sheet

**Permissions:** Named xCloud team/site administrator; confirm the exact production or staging target.

**Inputs:** Owner, hostname, approved requirements, sample record and decision date. Establish incident and data delta.

**Action:** Identify the affected site, last healthy time and records created since that time. Preserve logs and current files or database evidence before choosing a restore point.

**Expected result:** Incident impact and possible data loss are visible.

**Verify:** Compare backup timestamps with the newest post, form entry and user account.

**If it fails:** If live records are still arriving, establish a controlled intake route before recovery.

Capability: Confirm requirements and inspect resources
Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs)

### 2. Choose backup and safe target

**Where:** xCloud Site Backup dashboard

**Permissions:** Named xCloud team/site administrator; confirm the exact production or staging target.

**Inputs:** Target team/site, server or plugin version, license and documented prerequisites. Choose backup and safe target.

**Action:** List available xCloud site backups by completion, location and files/database scope. Prefer an isolated target to inspect a candidate point when possible.

**Expected result:** The recovery point and target are deliberate.

**Verify:** Confirm selected backup identifier, storage access and target hostname with the owner.

**If it fails:** If no backup includes required data, investigate alternate copies rather than overwriting the current site.

Capability: Configure native WordPress backup and restore
Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### 3. Restore a test copy in dashboard

**Where:** xCloud Site Backup dashboard

**Permissions:** Named xCloud team/site administrator; confirm the exact production or staging target.

**Inputs:** Approved change scope, backup state, selected version and maintenance window. Restore a test copy in dashboard.

**Action:** In the xCloud dashboard restore the chosen backup to a safe target or follow the documented recreation path. Do not use an inferred MCP restore call.

**Expected result:** A test copy exists without changing public traffic.

**Verify:** Wait for the dashboard operation to finish and inspect logs, WordPress login and representative media.

**If it fails:** If the copy fails, retain the original evidence and try another documented recovery point.

Capability: Restore a backup
Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud restore backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/); [xCloud recreate WordPress from backups](https://xcloud.host/docs/recreate-wordpress-website-from-backups/)

### 4. Test restored business journeys

**Where:** WordPress public pages, administrator and relevant external provider

**Permissions:** Named WordPress or selected app administrator; business owner approves results.

**Inputs:** Test accounts, sample content or transaction, expected result and provider access. Test restored business journeys.

**Action:** Run the site's public and administrator acceptance tests on the copy, including forms and HTTPS. Compare missing posts or submissions with records created after the backup.

**Expected result:** The owner can see exactly what would be recovered and lost.

**Verify:** Record observed URLs, sample identifiers and the delta requiring replay.

**If it fails:** If critical data is missing, defer cutover and plan manual reconciliation or forward repair.

Capability: Review a WordPress business journey
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)

### 5. Cut over after reconciliation

**Where:** WordPress public pages, administrator and relevant external provider

**Permissions:** Named WordPress or selected app administrator; business owner approves results.

**Inputs:** Observed results, unresolved failures, backup point and owner contacts. Cut over after reconciliation.

**Action:** Approve final target, data reconciliation and routing change with the business owner. Recheck login, content and business flow after traffic moves.

**Expected result:** Visitors reach a verified site and newer records have a disposition.

**Verify:** Have an independent user repeat a representative transaction and inspect the application record.

**If it fails:** If acceptance fails, invoke the pre-agreed routing rollback while preserving records written to either target.

Capability: Review a WordPress business journey
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)

## Maintenance

- Assign a cadence for selected WordPress core, theme and plugin updates, review version-based findings and retest the path in this guide. In particular, repeat: The recovered copy logs in and contains agreed representative content. A chat prompt is not a scheduled task. Sources: [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/)
- Record actual backup completion, storage access and responsible staff. Recheck connected application and provider behavior after changes rather than relying on a site health status alone. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Recovery decisions

- Before restoring, compare the chosen recovery point with newer business records. In-place restore overwrites newer posts, comments and form records. Use the xCloud dashboard for native restore only after the owner approves target and scope; reconcile or preserve newer data first. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- Validate the restored copy with representative content, authentication, HTTPS and this guide’s business acceptance test before moving traffic or closing the incident. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/)

## AI handoff

Connect xCloud MCP through the current documented profile and grant only the scopes needed for the selected team. Discover tool schemas first. Read resources to plan; require approval for any supported write. Use returned dashboard URLs for manual work. The packaged REST wrapper accepts GET requests only.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Configure native WordPress backup and restore** (dashboard; manual): Native schedule, retention and destination changes and all restores are dashboard-only. Checkpoint: Use Site → Site Backup. Before restoring, confirm backup, target, scope and treatment of newer records. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Restore a backup** (dashboard; manual): Native and Docker restore operations are dashboard-only. An in-place Docker restore replaces current data. Checkpoint: Use Site → Site Backup → Previous Backups → Restore Backup (or Restore to Another Site where offered). Confirm exact target and recovery point before proceeding. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/)
- **Review a WordPress business journey** (app; manual): Application data and observed transactions cannot be inferred from xCloud resource reads. Use authorized test accounts and the application or provider evidence. Checkpoint: Record the test identity, timestamp, expected outcome, observed result and owner decision. Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)

### Copyable agent brief

```text
Help with recover a wordpress site from backup for the exact xCloud team and site I name. First inspect only resources the connection permits and confirm returned identity, stack and relevant versions. Prepare the following authored workflow: Establish incident and data delta; Choose backup and safe target; Restore a test copy in dashboard; Test restored business journeys; Cut over after reconciliation. Ask the named dashboard, domain, WordPress and application owners to perform operations outside connected capabilities. WordPress staging push/pull, native backup schedules, restore and cache settings remain manual dashboard tasks; the packaged REST wrapper is GET-only. Use the guide’s checks to report observed application evidence, unresolved questions and recovery implications; do not claim completion from a hosting resource read. Acceptance: The owner can see exactly what would be recovered and lost.
```

### Manual checkpoints

- The named WordPress, app, dashboard or provider administrator performs the guide’s actual configuration step: In the xCloud dashboard restore the chosen backup to a safe target or follow the documented recreation path. Do not use an inferred MCP restore call.
- The business owner compares the controlled sample with this observable result: The owner can see exactly what would be recovered and lost.
- Staging push/pull, native backup schedules, restores and cache-setting edits require the authorized xCloud dashboard operator; the packaged REST wrapper is GET-only.

## Feature coverage

- **business-acceptance** (covered): The recovered copy logs in and contains agreed representative content. Steps: phase-4
- **recovery** (covered): In-place restore overwrites newer posts, comments and form records. Steps: phase-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/) — reviewed 2026-09-30
- [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/) — reviewed 2026-09-30
- [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/) — reviewed 2026-09-30
- [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/) — reviewed 2026-09-30
- [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/) — reviewed 2026-09-30
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/) — reviewed 2026-09-30
- [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/) — reviewed 2026-09-30
- [xCloud restore backup to another site](https://xcloud.host/docs/how-to-restore-a-backup-to-another-site/) — reviewed 2026-09-30
- [xCloud recreate WordPress from backups](https://xcloud.host/docs/recreate-wordpress-website-from-backups/) — reviewed 2026-09-30
- [Back up and restore Docker apps](https://xcloud.host/docs/backup-and-restore-docker-apps/) — reviewed 2026-09-30

## Continue

[Explore the next WordPress workflow](https://xcloud.host/use-cases/playbooks/separate-client-work-with-xcloud-teams/)

- [Rehearse a WordPress restore without affecting production](https://xcloud.host/use-cases/operations/rehearse-a-wordpress-restore-without-affecting-production/)
- [Check WordPress backup completion routinely](https://xcloud.host/use-cases/operations/check-wordpress-backup-completion-routinely/)
- [Hand over WordPress recovery information](https://xcloud.host/use-cases/operations/hand-over-wordpress-recovery-information/)
