# Run a WordPress membership site

Plan member access, protected content, updates, and recovery responsibilities. An active test member sees protected content; an expired member cannot.

Canonical: https://xcloud.host/use-cases/playbooks/run-a-wordpress-membership-site/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Plan member access, protected content, updates, and recovery responsibilities.
For: business-owner, operator

## Requirements and responsibilities

- Have named ownership of the domain, selected xCloud team and site, and WordPress administrator access. For this scenario, agree who supplies the data and signs off: A paid community wants restricted articles and a clear way to cancel access. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
- Use a compatible Nginx or OpenLiteSpeed stack for native WordPress. Verify current server resources, plan eligibility and each selected plugin or service license and requirements before installing; a Docker server does not host a new native WordPress site. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)
- Prepare a safe test identity and a completed, accessible backup before consequential changes. The important failure to plan around is: A full restore may discard new subscriptions and payments. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/)
- Before a source copy or backup restore starts, the authorized operator must restrict the target and quarantine outbound mail, payment, fulfillment and other provider effects at the receiving environment. Restored WordPress settings can overwrite plugin suppression; reapply sandbox credentials and verify isolation before tests. Sources: [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/)

## Illustrative situation

Illustrative scenario, not a customer case study: A paid community wants restricted articles and a clear way to cancel access. An active test member sees protected content; an expired member cannot.

## Choose the approach

- Select a membership plugin only after reviewing its roles, billing integration and export path. Verify the selected provider or plugin documentation and license against this requirement; xCloud hosting does not supply its business configuration. Paid Memberships Pro is one documented example; confirm its current level, gateway and license choices before selecting it. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Paid Memberships Pro initial setup and payment gateway planning](https://www.paidmembershipspro.com/documentation/initial-plugin-setup/)
- Keep application setup, domain/DNS ownership, mail delivery and external integrations with their named administrators. Use a plain documented path when a proposed integration cannot be demonstrated end to end. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)

## Dashboard and application procedure

### 1. Define member access states

**Where:** WordPress administrator or the selected plugin/application

**Permissions:** Named WordPress or selected app administrator; business owner approves results.

**Inputs:** Owner, hostname, approved requirements, sample record and decision date. Define member access states.

**Action:** Write an access matrix for anonymous visitor, active member, expired member and staff administrator. Include each protected page, renewal interval, cancellation rule and where billing records live.

**Expected result:** Membership rules and data ownership are explicit.

**Verify:** The owner signs the matrix and names one sample URL for each state.

**If it fails:** If billing or access policy is unresolved, do not promise paid access on the public page.

Capability: Configure WordPress content, users and selected plugins
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)

### 2. Select a documented membership plugin

**Where:** WordPress administrator or the selected plugin/application

**Permissions:** Named WordPress or selected app administrator; business owner approves results.

**Inputs:** Target team/site, server or plugin version, license and documented prerequisites. Select a documented membership plugin.

**Action:** Choose a membership plugin from its current vendor documentation. Check compatibility with the site's WordPress/PHP versions, required payment gateway, license and member export path before installation.

**Expected result:** One candidate can implement the required states.

**Verify:** Match every access rule to a documented setting or integration and record any gap.

**If it fails:** If a required state lacks a supported rule, compare a different plugin before collecting payments.

Capability: Configure WordPress content, users and selected plugins
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/); [Paid Memberships Pro initial setup and payment gateway planning](https://www.paidmembershipspro.com/documentation/initial-plugin-setup/)

### 3. Configure levels and sandbox billing

**Where:** WordPress administrator or the selected plugin/application

**Permissions:** Named WordPress or selected app administrator; business owner approves results.

**Inputs:** Approved change scope, backup state, selected version and maintenance window. Configure levels and sandbox billing.

**Action:** Configure the selected plugin's levels and protected content in WordPress, and connect payment in the provider's test mode. Keep gateway keys and billing configuration with authorized administrators.

**Expected result:** A test user can enroll without affecting live billing.

**Verify:** Create a sandbox member and inspect both plugin access state and payment provider event.

**If it fails:** If one system advances while the other does not, stop launch and repair the integration mapping.

Capability: Configure WordPress content, users and selected plugins
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/); [Paid Memberships Pro initial setup and payment gateway planning](https://www.paidmembershipspro.com/documentation/initial-plugin-setup/)

### 4. Test access and cancellation

**Where:** WordPress public pages, administrator and relevant external provider

**Permissions:** Named WordPress or selected app administrator; business owner approves results.

**Inputs:** Test accounts, sample content or transaction, expected result and provider access. Test access and cancellation.

**Action:** Use separate accounts to test active, expired and anonymous access; test renewal and cancellation with the plugin and gateway in test mode. Check personalized pages with cache bypass rules.

**Expected result:** Only the intended account reaches member material.

**Verify:** Compare three session results and confirm the same member state in the application record.

**If it fails:** If a protected page leaks or an active member is blocked, remove the public sales path until rules and caching pass.

Capability: Review a WordPress business journey
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)

### 5. Protect member data and assign operators

**Where:** xCloud Site Backup dashboard

**Permissions:** Named xCloud team/site administrator; confirm the exact production or staging target.

**Inputs:** Observed results, unresolved failures, backup point and owner contacts. Protect member data and assign operators.

**Action:** Confirm that backups include membership data and rehearse a safe-target restore. Assign a staff member to review failed payments, access requests and plugin updates.

**Expected result:** Membership service has a named operator and recovery path.

**Verify:** Inspect a restored test member and compare the backup time with new payments or registrations.

**If it fails:** Never overwrite newer member or payment data without an explicit reconciliation plan.

Capability: Configure native WordPress backup and restore
Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Maintenance

- Assign a cadence for selected WordPress core, theme and plugin updates, review version-based findings and retest the path in this guide. In particular, repeat: An active test member sees protected content; an expired member cannot. A chat prompt is not a scheduled task. Sources: [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/); [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/)
- Record actual backup completion, storage access and responsible staff. Recheck connected application and provider behavior after changes rather than relying on a site health status alone. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Recovery decisions

- Before restoring, compare the chosen recovery point with newer business records. A full restore may discard new subscriptions and payments. Use the xCloud dashboard for native restore only after the owner approves target and scope; reconcile or preserve newer data first. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- Validate the restored copy with representative content, authentication, HTTPS and this guide’s business acceptance test before moving traffic or closing the incident. Sources: [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/)

## AI handoff

Connect xCloud MCP through the current documented profile and grant only the scopes needed for the selected team. Discover tool schemas first. Read resources to plan; require approval for any supported write. Use returned dashboard URLs for manual work. The packaged REST wrapper accepts GET requests only.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)
- **Configure WordPress content, users and selected plugins** (app; manual): Requires a named WordPress administrator or suitable editor. Plugin behavior, commercial license, payment, email and external integration are verified in the chosen vendor documentation and application; xCloud hosting or MCP reads do not configure them. Checkpoint: Open the actual WordPress or selected plugin interface, record the version and role, and have the business owner accept a real user journey. Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/)
- **Review a WordPress business journey** (app; manual): Application data and observed transactions cannot be inferred from xCloud resource reads. Use authorized test accounts and the application or provider evidence. Checkpoint: Record the test identity, timestamp, expected outcome, observed result and owner decision. Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
- **Configure native WordPress backup and restore** (dashboard; manual): Native schedule, retention and destination changes and all restores are dashboard-only. Checkpoint: Use Site → Site Backup. Before restoring, confirm backup, target, scope and treatment of newer records. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### Copyable agent brief

```text
Help with run a wordpress membership site for the exact xCloud team and site I name. First inspect only resources the connection permits and confirm returned identity, stack and relevant versions. Prepare the following authored workflow: Define member access states; Select a documented membership plugin; Configure levels and sandbox billing; Test access and cancellation; Protect member data and assign operators. Ask the named dashboard, domain, WordPress and application owners to perform operations outside connected capabilities. WordPress staging push/pull, native backup schedules, restore and cache settings remain manual dashboard tasks; the packaged REST wrapper is GET-only. Use the guide’s checks to report observed application evidence, unresolved questions and recovery implications; do not claim completion from a hosting resource read. Acceptance: Only the intended account reaches member material.
```

### Manual checkpoints

- The named WordPress, app, dashboard or provider administrator performs the guide’s actual configuration step: Configure the selected plugin's levels and protected content in WordPress, and connect payment in the provider's test mode. Keep gateway keys and billing configuration with authorized administrators.
- The business owner compares the controlled sample with this observable result: Only the intended account reaches member material.
- Staging push/pull, native backup schedules, restores and cache-setting edits require the authorized xCloud dashboard operator; the packaged REST wrapper is GET-only.

## Feature coverage

- **business-acceptance** (covered): An active test member sees protected content; an expired member cannot. Steps: phase-4
- **recovery** (covered): A full restore may discard new subscriptions and payments. Steps: phase-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/) — reviewed 2026-09-30
- [WordPress plugin administration](https://wordpress.org/documentation/article/manage-plugins/) — reviewed 2026-09-30
- [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/) — reviewed 2026-09-30
- [WordPress hardening handbook](https://developer.wordpress.org/advanced-administration/security/hardening/) — reviewed 2026-09-30
- [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/) — reviewed 2026-09-30
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [Paid Memberships Pro initial setup and payment gateway planning](https://www.paidmembershipspro.com/documentation/initial-plugin-setup/) — reviewed 2026-09-30
- [Manage WordPress updates with Updates Manager](https://xcloud.host/docs/manage-wordpress-updates-with-updates-manager/) — reviewed 2026-09-30
- [Vulnerability Checker in xCloud](https://xcloud.host/docs/vulnerability-checker-in-xcloud/) — reviewed 2026-09-30

## Continue

[Explore the next WordPress workflow](https://xcloud.host/use-cases/playbooks/publish-a-wordpress-editorial-site/)

- [Check membership access after a release](https://xcloud.host/use-cases/solutions/check-membership-access-after-a-release/)
- [Check editorial roles before site handover](https://xcloud.host/use-cases/solutions/check-editorial-roles-before-site-handover/)
- [Create a WordPress staging acceptance checklist](https://xcloud.host/use-cases/solutions/create-a-wordpress-staging-acceptance-checklist/)
