# Clone a WordPress site for staging

Use the documented staging/clone path and verify environment separation and indexing settings. Check the named site's prerequisites, task result, backup scope and recovery handoff with xCloud.

Canonical: https://xcloud.host/use-cases/workflows/clone-a-wordpress-site-for-staging/
Published: 2026-09-30 · Updated: 2026-09-30 · Technical review: 2026-09-30
Evidence: Source reviewed; no production deployment test claimed
Editorial owner: xCloud editorial

Intent: Use the documented staging/clone path and verify environment separation and indexing settings.
For: site-owner, administrator

## Requirements and responsibilities

- Name the team, server, hostname, owner and affected users for the WordPress site. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)
- Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)
- For WordPress, verify the file and database backup scope and a safe target for recovery. Native scheduling, destination settings, staging synchronization and restore remain dashboard actions. Agree a maintenance window and owner before any action that interrupts the service or overwrites data. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)
- A clone or recovered database may start scheduled jobs and carry live payment, booking, mail or webhook credentials. Arrange provider or network controls that prevent external side effects before the copied application can run. If the current xCloud flow cannot guarantee that isolation, use a sanitized fixture or postpone the clone; changing credentials after startup may be too late. Sources: [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

## Illustrative situation

An agency must test a plugin upgrade for a live booking site. It needs a staging copy that cannot send real booking mail or accept live payments.

## Choose the approach

- Use xCloud Add Staging only for an eligible plan and inspect the current dashboard before copying data. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)
- Decide whether a full clone is appropriate: customer records copied into staging require restricted access, mail suppression and a retention plan. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)

## Dashboard and application procedure

### 1. Confirm staging eligibility

**Where:** xCloud production Site overview

**Permissions:** Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.

**Inputs:** Site ID, plan, backup timestamp

**Action:** Open the production site overview, confirm Add Staging is offered for this plan, and record current WordPress and plugin versions.

**Expected result:** A supported staging path and production baseline.

**Verify:** Check the exact source site ID and latest completed file/database backup.

**If it fails:** If Add Staging is absent, do not invent an MCP staging-create call; resolve plan eligibility first.

Capability: Confirm requirements and inspect resources
Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)

### 2. List copied side effects

**Where:** WordPress plugins and connected providers

**Permissions:** Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Payment mode, booking endpoint, SMTP route, webhooks

**Action:** Inventory plugins that can charge, notify or synchronize outside WordPress. Plan sandbox credentials, mail capture or disabled triggers for the copy.

**Expected result:** A written isolation checklist before customer data is cloned.

**Verify:** Have the booking owner sign off on each integration's staging state.

**If it fails:** If an external endpoint cannot be isolated, exclude that test or use a separate harmless fixture.

Capability: Configure and test WordPress in its administrator UI
Sources: [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)

### 3. Create the staging site

**Where:** xCloud Site overview → Add Staging

**Permissions:** Authorized xCloud site owner with dashboard rights for the exact setting, backup, staging or restore action and a reviewed target.

**Inputs:** Source site, staging name and current form inputs

**Action:** Create staging from the named production site in the dashboard. Wait for the new site to appear, then record both URLs and site IDs.

**Expected result:** A separate staging environment with a traceable source.

**Verify:** Compare the staging ID and URL with production; confirm production content has not changed.

**If it fails:** If the copy stalls, inspect its task status and logs rather than restarting production.

Capability: Create and synchronize WordPress staging
Sources: [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### 4. Lock down the copy

**Where:** Staging WordPress and site access controls

**Permissions:** Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Test users, indexing choice, sandbox endpoints

**Action:** Restrict access, inspect WordPress search-engine visibility, replace live payment or mail credentials with test routes, and clear or anonymize unnecessary customer data.

**Expected result:** Staging can be tested without public indexing or live side effects.

**Verify:** Submit a test booking and verify it reaches only sandbox recipients and no live charge occurs.

**If it fails:** If any real notification or charge occurs, disable the integration and investigate before giving testers access.

Capability: Configure and test WordPress in its administrator UI
Sources: [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)

### 5. Run and document the rehearsal

**Where:** Staging URL and production comparison

**Permissions:** Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.

**Inputs:** Selected plugin update and booking cases

**Action:** Apply the update only on staging, check booking creation, cancellation and notifications, and document differences from production. Keep production unchanged until a separate release approval.

**Expected result:** Evidence for or against promoting the change.

**Verify:** Inspect staging version, test records and production version side by side.

**If it fails:** If staging diverged for unrelated reasons, fix the fixture or repeat on a fresh copy; do not push its database blindly.

Capability: Configure and test WordPress in its administrator UI
Sources: [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/)

## Maintenance

- Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)
- Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)

## Recovery decisions

- If staging sends to a live provider, stop the integration, identify affected recipients and records, and have its owner correct them in the provider or application. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)
- Rebuild or refresh the isolated staging copy only after suppressing side effects; check newer production records before any push or pull. Sources: [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md); [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/); [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/); [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/); [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/); [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/); [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/); [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/)

## AI handoff

Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.

### Supported scope

- **Confirm requirements and inspect resources** (mcp; read): Discover the connected profile and operation schema first; only teams granted to the connection are visible. Checkpoint: Confirm exact team, server and site identity. Use dashboard\_url returned by the resource; do not invent a dashboard link. Operation identifiers to discover: teams.index, servers.show, sites.show. Scopes: read:servers, read:sites. Sources: [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs); [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md)

### Copyable agent brief

```text
Read the production site and backup state. List staging eligibility, copied data and risky integrations. Staging creation and synchronization are dashboard-only; do not call a Git staging operation or push production data. Return a test and isolation checklist.
```

### Manual checkpoints

- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized WordPress administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.

## Feature coverage

- **staging decision, evidence and task action** (covered): The procedure identifies the authorized task boundary and observable result. Steps: step-1, step-2, step-3, step-4
- **backup, ongoing operation and recovery** (covered): Recovery and maintenance are checked in the task procedure. Steps: step-4, step-5

## Sources

- [xCloud agent capability boundaries](https://github.com/xCloudDev/xcloud-agent-skills/blob/main/plugins/xcloud/reference/capability-map.md) — reviewed 2026-09-30; v4.4.2 package; xCloud v2.8.8 capability review
- [xCloud MCP documentation and connection profiles](https://app.xcloud.host/mcp/docs) — reviewed 2026-09-30
- [Create a staging environment in xCloud](https://xcloud.host/docs/how-to-create-a-staging-environment-in-xcloud/) — reviewed 2026-09-30
- [Manage WordPress core, themes and plugins](https://xcloud.host/docs/manage-and-update-wordpress-core-themes-in-xcloud/) — reviewed 2026-09-30
- [Site backups in xCloud](https://xcloud.host/docs/site-backups-in-xcloud/) — reviewed 2026-09-30
- [WordPress security hardening](https://developer.wordpress.org/advanced-administration/security/hardening/) — reviewed 2026-09-30
- [WordPress roles and capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/) — reviewed 2026-09-30
- [Create WordPress pages](https://wordpress.org/documentation/article/create-pages/) — reviewed 2026-09-30
- [Manage WordPress plugins](https://wordpress.org/documentation/article/manage-plugins/) — reviewed 2026-09-30

## Continue

[Explore all use cases](https://xcloud.host/use-cases/)

- [Manage WordPress plugin updates and security checks](https://xcloud.host/use-cases/operations/wordpress-plugin-updates-and-security/)
- [Release WordPress staging changes without losing live data](https://xcloud.host/use-cases/playbooks/wordpress-staging-release-with-live-data/)
