Requirements and responsibilities
Name the team, server, hostname, owner and affected users for the WordPress site. Record the current version and the actual business flow that must survive the change. Confirm the current dashboard form, plan eligibility, and server capacity before committing a resource change. A one-click catalog listing is discovery, not permission or proof that the connected MCP profile can install it.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Prepare a non-sensitive test input and an acceptance record. Keep access to the app administrator and an independent observer where possible; omit secrets from AI prompts and client reports.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
For WordPress, verify the file and database backup scope and a safe target for recovery. Native scheduling, destination settings, staging synchronization and restore remain dashboard actions. Agree a maintenance window and owner before any action that interrupts the service or overwrites data.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Illustrative situation
An agency is handing a WordPress site to a client whose plugins have mixed license owners. The client needs an inventory that explains each plugin’s business purpose and update responsibility.
Choose the approach
Inventory active, inactive and must-use plugins; WordPress default plugin screen omits must-use entries from normal update notices.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Record license ownership without including license keys or administrator passwords in the deliverable.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Dashboard and application procedure
Follow these steps yourself, or use the scoped AI handoff below for supported hosting operations.
Step 1 of 5
Confirm the client site
- Where
- xCloud team/site and WordPress admin
- Permissions
- Authorized xCloud read access to the named team and site; the relevant app or provider owner supplies records outside xCloud.
- Inputs
- Client name, domain, site ID, handover date
- Action
- Identify the exact production site and capture WordPress and PHP versions before exporting plugin data.
- Expected result
- A dated inventory header linked to one client.
- Verify
- Ask the client owner to confirm domain and team.
- If it fails
- If multiple domains share a site, list them explicitly rather than creating duplicate inventories.
Sources: xCloud MCP documentation and connection profiles · xCloud agent capability boundaries · xCloud site PHP settings
Step 2 of 5
List installed components
- Where
- WordPress Plugins and must-use directory view
- Permissions
- Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.
- Inputs
- Plugin names, slugs, versions, active status
- Action
- Record every normal and must-use plugin, current version, installed source and activation state. Compare with xCloud's WordPress management list.
- Expected result
- A complete component table.
- Verify
- Reconcile discrepancies between WordPress and xCloud views.
- If it fails
- If a plugin is unrecognized, investigate its origin before labeling it safe.
Sources: Manage WordPress plugins
Step 3 of 5
Map business dependencies
- Where
- Client task owners and site journeys
- Permissions
- Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.
- Inputs
- Form, booking, checkout, search and cache flows
- Action
- For each active plugin, state what business function fails if it is disabled. Identify duplicate or abandoned functionality separately.
- Expected result
- A dependency map, not just a software list.
- Verify
- Have owners run one representative task for critical plugins.
- If it fails
- If a purpose cannot be demonstrated, mark for review rather than deleting immediately.
Sources: Manage WordPress plugins
Step 4 of 5
Assign licenses and updates
- Where
- Vendor accounts and agency contract
- Permissions
- Authorized WordPress/WooCommerce application administrator or delegated role with rights for this task; hosting access alone is insufficient.
- Inputs
- Renewal date, account owner, update cadence
- Action
- Record who pays, receives vendor notices, tests updates and approves production changes. Keep secrets in the client's approved password manager.
- Expected result
- Named ownership for every important component.
- Verify
- Verify access transfer and renewal contact with the client.
- If it fails
- If the agency is the sole license owner, document the transfer or service obligation.
Sources: Manage WordPress plugins
Step 5 of 5
Deliver a safe inventory
- Where
- Client report and maintenance plan
- Permissions
- Authorized xCloud site owner with dashboard rights for the exact setting, backup, staging or restore action and a reviewed target.
- Inputs
- Sanitized table, open risks, next review date
- Action
- Share versions, purpose, owner and unresolved risks with the approved client contact. Set a date to refresh the inventory after changes.
- Expected result
- A usable maintenance handoff.
- Verify
- Check the recipient can locate the list and no secret/token appears.
- If it fails
- If access rights are uncertain, restrict the report and confirm authorized recipients first.
Sources: WordPress website maintenance reports for clients · xCloud agent capability boundaries
Maintenance
Review this task after app or template updates and at the cadence agreed with the owner. Record failures as dated observations rather than assuming host health proves service health.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Watch access changes, backup completion, free storage and external providers. Recheck integrations after credential, DNS, mail or source-data changes.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Recovery decisions
If the inventory, finding, report or plan is wrong, preserve its dated source evidence and issue a corrected version to the approved owner. Keep the prior record visible as superseded.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
Recheck the exact site, timestamp and task-specific test before approving any separate change. A bad review does not by itself justify replacing live site data.
xCloud agent capability boundaries · xCloud MCP documentation and connection profiles · Manage WordPress core, themes and plugins · Site backups in xCloud · WordPress security hardening · WordPress roles and capabilities · Create WordPress pages · Manage WordPress plugins
AI handoff
Connect an authorized xCloud MCP profile and discover its exact tools and team scope. The packaged REST wrapper is GET-only; use dashboard or app controls for undocumented writes.
Supported scope
- Confirm requirements and inspect resources mcp · read
Discover the connected profile and operation schema first; only teams granted to the connection are visible.
Checkpoint: Confirm exact team, server and site identity. Use dashboard_url returned by the resource; do not invent a dashboard link.
Operation identifiers and scopes to discover
teams.index, servers.show, sites.show
Scopes: read:servers, read:sites
xCloud MCP documentation and connection profiles · xCloud agent capability boundaries
Copyable agent brief
Manual checkpoints
- Approve exact site, target, cost and any write or maintenance window after inspecting the proposed plan.
- An authorized WordPress administrator must configure and test app users, content, integrations and business rules in the app.
- Native WordPress staging, backup schedule/settings, push/pull and all restores are dashboard-only; Docker restore is dashboard-only and replaces state.
- Reconcile data created after the chosen recovery point before any destructive restore.
Feature coverage
- inventory decision, evidence and task action (covered): The procedure identifies the authorized task boundary and observable result. Confirm the client site List installed components Map business dependencies Assign licenses and updates
- backup, ongoing operation and recovery (covered): Recovery and maintenance are checked in the task procedure. Assign licenses and updates Deliver a safe inventory
Sources
- xCloud agent capability boundaries
- xCloud MCP documentation and connection profiles
- Manage WordPress core, themes and plugins
- Site backups in xCloud
- WordPress security hardening
- WordPress roles and capabilities
- Create WordPress pages
- Manage WordPress plugins
- xCloud site PHP settings
- WordPress website maintenance reports for clients