Manage WordPress Like an Agency: Why Updates Aren’t Enough
If you’re responsible for your company’s WordPress website, you probably already know you’re supposed to keep it updated. But here’s the problem: that’s not how an agency actually manages WordPress. Clicking update and seeing a green tick doesn’t tell you the website is secure.
It doesn’t tell you nothing broke either. And it definitely doesn’t tell you nobody got in before you installed the fix.
Over the past few weeks, I’ve been covering WordPress vulnerabilities every day, and something keeps coming up. The individual vulnerabilities are different, but the lessons behind them are remarkably similar. You need to know what’s actually running on your website, and you need to understand whether a vulnerability really affects you.
You need backups you can actually recover from. And you need to test the parts of the website your business depends on, too. When something does go wrong, you need to know the difference between fixing the problem and proving the problem hasn't already been exploited.
I’ve spent 25 years building production software, and I’ve managed hundreds of WordPress websites. So I’m putting together a new series to show you how we approach this from the agency side. It’s not to turn you into a developer, and not to scare you with security jargon, but to give you a system.
We’ll look at updates, backups, vulnerabilities, hosting, testing, monitoring, and what you should actually do if you think your website has been compromised. So if you’re a marketing manager, a business owner, or simply the person everyone turns to when the WordPress site breaks, this series is for you.
It’s called Manage WordPress Like an Agency. And we’re starting with something surprisingly simple: why managing WordPress is about much more than keeping it updated.