CMS / WORDPRESS
Learn how WordPress works as a content management system, from the dashboard and Block Editor to themes, plugins, SEO, security, performance, WooCommerce and custom development.
Current information, honest trade-offs and no invented statistics.
Core, theme, plugins and database are separate layers. Confusing them is the source of most WordPress troubleshooting difficulty.
THE BASICS
WordPress is open-source software for publishing and managing websites — a content management system. It handles creating and organising content, managing media and users, controlling presentation through themes, and extending functionality through plugins.
It began as blogging software, and the description has long outlived its accuracy. WordPress runs business sites, shops, membership platforms, publications and custom applications. Calling it “a blogging platform” today describes what it was in 2004, not what it is.
An important distinction people meet immediately and rarely have explained:
The open-source software. You download it, install it on hosting you choose, and control everything — themes, plugins, code, data. Free to use; you pay for hosting and whatever else you choose. This is what most people mean by “WordPress”.
A commercial hosted service built around WordPress. Hosting, updates and maintenance are handled for you, in exchange for less control — what you can install and customise depends on the plan. A different product with a similar name.
They are not the same thing, and advice written for one frequently does not apply to the other. Everything on this page refers to self-hosted WordPress.org unless stated.
Service pages, contact forms, lead capture and the content around them.
Posts, categories, authors and archives — the original use case, still well served.
Through WooCommerce or other commerce plugins, from small catalogues upward.
Project galleries, case studies and visual work presented with custom layouts.
Restricted content, user accounts, forums and courses through plugins.
With custom post types, the REST API and custom development, well beyond a standard site.
ARCHITECTURE
A visitor requests a page. The web server passes it to PHP, which runs WordPress Core. Core loads the active theme and plugins, queries the database for the content, assembles HTML, and sends it back. The browser renders it.
Understanding these as separate layers is the single most useful thing for troubleshooting.
Core is the WordPress software: the admin interface, content management, user handling, the APIs and the hooks other code attaches to. It updates on its own schedule and should never be edited — changes are overwritten on the next update.
Themes control presentation. Plugins add functionality. Neither is part of core, and both come from elsewhere with their own quality and maintenance.
The database holds content and configuration — posts and pages, metadata, users, settings, taxonomy relationships. Media files sit on disk in the uploads folder, with the database recording where they are. That split matters for backups: a database backup without the uploads folder restores your content with every image missing.
WordPress runs on PHP, which is why PHP version compatibility affects the site, themes and plugins alike. See our PHP guide.
CONTENT
The WordPress admin dashboard holds the familiar sections: Posts, Media, Pages, Comments, Appearance, Plugins, Users, Tools and Settings. Plugins and themes add their own menus, so no two installations look identical — if a guide describes a menu you don’t have, a plugin is usually the reason.
Posts and Pages are the two built-in content types, and choosing correctly matters more than it appears:
The Media Library holds uploaded files. Two habits pay off: rename files descriptively before uploading, since WordPress keeps the filename, and fill in alt text at upload rather than intending to return later. See our image SEO guide.
Categories group posts into broad topics; tags mark specific subjects. Both generate archive pages, which is where restraint matters — dozens of tags used once each produce thin archive pages nobody benefits from.
User roles control what people can do. The principle worth applying is least privilege: give each person the lowest role that lets them do their job. Every administrator account is another route into the site.
Full control including plugins, themes, users and settings. Give this to as few people as genuinely need it.
Can publish and manage all content, including other people's. No access to settings, plugins or themes.
Can publish and manage only their own content.
Can write but not publish. Their drafts need approval.
Profile management only. Used for membership and comment setups.
Blocks are the components content is built from. Themes and plugins add more.
THEMES & EDITING
A theme controls presentation: layout, templates and styling. It should not carry functionality you’d need if you switched themes — that belongs in a plugin. Themes that bundle post types and shortcodes trap you, because changing theme then breaks your content.
WordPress now has two theme architectures, and knowing which you’re using determines which instructions apply.
Block themes are built from block templates and support the Site Editor, where headers, footers, templates and global styles are edited visually in the browser. Classic themes use PHP template files, with customisation through the Customizer, theme options and code.
Neither is better in general. Block themes offer visual control without touching code; classic themes have a mature ecosystem and many established sites run on them perfectly well. The right choice depends on the project, the team and what your existing site already uses.
Two things get confused constantly. The Block Editor (often called Gutenberg, after the project that built it) edits the content of a single post or page — it works with both theme types. The Site Editor edits site-wide structure and styling, and requires a block theme. If you can’t find the Site Editor, you’re almost certainly on a classic theme.
Block patterns are pre-arranged groups of blocks — a hero section, a pricing layout — inserted as a starting point and then edited.
PLUGINS
Plugins add functionality WordPress Core doesn’t include. This extensibility is the main reason WordPress covers such different kinds of site from one codebase.
Plugins are not inherently good or bad, and the most persistent myth deserves dismissing: there is no correct number of plugins. Neither “under ten is safe” nor “twenty makes a site slow” means anything. One badly built plugin can do more damage than twenty well-maintained ones. What matters is code quality, whether each is actively maintained, whether you actually need it, and whether two of them do the same job.
Plugin security is where most WordPress compromises originate — usually through outdated or abandoned plugins. Keep them updated, install from reputable sources, delete what you don’t use rather than deactivating it (deactivated plugin code still sits on the server), and check whether something has been abandoned before relying on it.
One thing to state plainly: never install nulled or pirated plugins. Paid plugins distributed free have frequently been modified, and the modification is the point — backdoors, injected content, credential harvesting. The saving is not worth what it typically costs.
Metadata, sitemaps, canonical control and structured data output.
Contact forms, notifications and submission handling.
Products, carts, payments and orders.
Login protection, monitoring and hardening.
Page caching, asset optimisation and delivery.
Scheduled backups and restoration.
Tracking integration and reporting.
Post types, integrations and site-specific code.
SEO
WordPress does not make a site rank. It produces clean markup and gives you control over the things that matter, which is a decent starting position and nothing more. Content quality, technical health and everything in our website SEO guides still apply.
Permalinks deserve attention on day one. Settings → Permalinks controls URL structure, and the default numeric option produces unreadable URLs. Choose a readable structure — usually Post name — before publishing. Changing it later breaks every existing URL unless you set up redirects, which is entirely avoidable by deciding early. See our technical SEO guide.
SEO plugins — Yoast, Rank Math, All in One SEO among others — handle title and description fields, canonical control, robots directives, XML sitemaps and structured data output. They make these accessible without editing templates.
Two caveats. A green light means the plugin’s own checklist passed, not that a page will rank — some of those checks encode outdated advice, particularly around keyword frequency. And use one: overlapping SEO plugins produce duplicate structured data, conflicting sitemaps and contradictory meta tags. None is universally best; they cover similar ground differently.
PERFORMANCE
WordPress is not inherently slow. Performance depends on hosting, theme, plugins, images and how pages are built. A lean WordPress site outperforms a bloated custom one comfortably.
Hosting sets the floor. Cheap shared hosting with slow server response puts a limit on everything else — no amount of image optimisation fixes a slow time to first byte. This is the first thing to check when a site feels slow everywhere rather than on specific pages.
Caching stores generated output so WordPress doesn’t rebuild every page on every request. Page caching serves stored HTML. Object caching stores database query results, which helps most on query-heavy sites. Browser caching and a CDN reduce repeat downloads and serve assets from closer infrastructure. Which combination helps depends on the site — a mostly static brochure site and a logged-in membership site have completely different caching needs.
Images are usually the heaviest thing on a page: correct dimensions, sensible compression, modern formats, and lazy loading below the fold but never on the hero image, which is typically your LCP element.
Use one optimisation plugin, not three. Stacked caching and optimisation plugins conflict, duplicate work and produce problems harder to diagnose than the slowness they were meant to fix. See Core Web Vitals and website speed.
[ ] Keep core, themes and plugins updated [ ] Use strong, unique passwords with two-factor authentication [ ] Limit administrator accounts to those who need them [ ] Delete unused plugins and themes rather than deactivating [ ] Install only from reputable sources — never nulled software [ ] Choose hosting that takes security seriously [ ] Serve everything over HTTPS [ ] Keep tested, off-site backups [ ] Protect the login page against automated attempts [ ] Monitor for unexpected file changes [ ] Review user accounts periodically [ ] Never leave debug output enabled in production
SECURITY & MAINTENANCE
WordPress security is layered, and no security plugin makes a site secure on its own. A plugin adds monitoring and hardening; it does not compensate for outdated software, weak passwords or poor hosting.
The largest single factor is updates. Most WordPress compromises exploit known vulnerabilities in outdated plugins — issues that were patched, sometimes months earlier. Updating is unglamorous and it is the work.
Backups need stating carefully: a backup you have never restored is a hope, not a backup. Back up the database and the uploads folder, store copies off-site rather than only on the same server, and actually test a restore occasionally. Plenty of people discover their backups were incomplete at the worst possible moment.
Staging is a copy of the site for testing updates, new plugins and design changes before they reach visitors. Many hosts provide it. For a site that matters commercially, updating directly on production is a gamble you will eventually lose.
Migration — moving hosts or domains — needs the same care: back up first, move files and database, update configuration and URLs, test thoroughly before switching DNS, and watch for broken links, missing files and mixed content afterwards.
HOSTING
WordPress needs a server running PHP with a supported database. Hosting types differ mainly in resources, management and price: shared hosting is cheapest with resources split between sites, VPS and cloud give dedicated resources with more responsibility, and managed WordPress hosting handles updates, caching, backups and staging at higher cost.
Hosting affects more than speed. Server response time, uptime, PHP version availability, resource limits and security practices all shape what the site can do. It’s the foundation, and it’s where under-investing shows up everywhere else. See our hosting and domains guides.
WordPress.org currently recommends a hosting environment with PHP 8.3 or greater, MariaDB 10.11 or greater or MySQL 8.0 or greater, and HTTPS support.
Two notes on that. These are recommendations rather than hard minimums — WordPress runs on older versions, though doing so means missing security and performance improvements. And recommendations change; check wordpress.org for the current figures rather than trusting any article, including this one, indefinitely.
Lowest cost, resources shared between many sites. Workable for small, low-traffic sites.
Dedicated resources with more configuration control, and more responsibility for maintaining it.
Updates, caching, backups and staging handled for you. Costs more, saves maintenance time.
These are the recommended environment specifications published by WordPress.org. They are recommendations rather than absolute minimums, and they change over time — verify current figures at wordpress.org before relying on them.
<?php
// An ACTION runs your code at a defined point.
// Nothing is returned — you are doing something.
add_action( 'wp_enqueue_scripts', function () {
wp_enqueue_style(
'child-style',
get_stylesheet_directory_uri() . '/style.css',
array( 'parent-style' )
);
} );
// A FILTER modifies data passing through.
// You must return the value.
add_filter( 'excerpt_length', function ( $length ) {
return 30;
} );
add_filter( 'the_content', function ( $content ) {
if ( is_single() ) {
$content .= '<p>Thanks for reading.</p>';
}
return $content; // always return
} );
// A custom post type belongs in a PLUGIN, not a theme —
// so the content survives a theme change.
add_action( 'init', function () {
register_post_type( 'project', array(
'labels' => array( 'name' => 'Projects' ),
'public' => true,
'has_archive' => true,
'show_in_rest' => true, // enables the Block Editor and REST API
'supports' => array( 'title', 'editor', 'thumbnail' ),
) );
} );
// Child theme style.css header (classic themes)
/*
Theme Name: Example Child
Template: example-parent
*/
// Never edit core files. Updates overwrite them.DEVELOPMENT
WordPress development uses PHP on the server with HTML, CSS and JavaScript in the browser. What makes it extensible is hooks.
Actions let your code run at defined moments — when WordPress initialises, when a post saves, when scripts load. You’re doing something; nothing is returned. Filters let you modify data as it passes through — changing an excerpt length, adjusting content before display. You must return the value, and forgetting to is the classic filter bug that blanks content.
Both work without editing core files, which is the point. Never edit core — updates overwrite it.
A child theme lets you customise a classic theme without losing changes when the parent updates. For block themes, style variations and Site Editor changes often cover what a child theme used to.
The dividing line for custom code: presentation belongs in a theme, functionality belongs in a plugin. A custom post type defined in a theme disappears when you switch themes, taking your content’s visibility with it.
The REST API exposes WordPress data over HTTP, enabling headless setups where WordPress manages content and a separate frontend renders it. That buys flexibility and costs complexity — two systems, two deployments, and you take on rendering and SEO decisions yourself. It’s one architecture among several, not an upgrade. See our website APIs guide.
THE ECOSYSTEM
Three things frequently mistaken for WordPress features. None is part of WordPress Core.
A third-party visual page builder plugin. It provides containers, widgets, responsive controls, templates and a Theme Builder for headers, footers and archive layouts. It replaces much of what the theme would do, which is why an Elementor site is built quite differently. Powerful, and it adds its own CSS and JavaScript — worth building restrained pages rather than assuming the builder is free.
A plugin adding e-commerce: products, variations, cart, checkout, orders, payments, shipping and inventory. It changes performance characteristics noticeably — product and checkout pages carry far more than a standard page, and caching them needs care since parts must stay dynamic.
A core feature, though not enabled by default: several sites sharing one WordPress installation, themes and plugins. Genuinely useful for networks of genuinely similar sites under one administration. For a business with three unrelated sites, separate installations are usually simpler to manage and update.
TROUBLESHOOTING
Accessibility in WordPress depends on your theme, your content and your plugins — not on WordPress itself. Semantic headings, keyboard navigation, sufficient contrast, real alt text, accessible forms, visible focus and descriptive link text are all things you control.
Accessibility overlay plugins deserve caution: they do not make a site compliant, and the accessibility community’s assessment of them is largely negative. Building accessibly beats bolting something on. See our website accessibility guide.
Responsive design comes from the theme or page builder. Check real breakpoints on real devices rather than trusting the editor preview, and watch for layouts that work at desktop width and fall apart at 360 pixels. See our responsive design guide.
For troubleshooting, the most valuable question is: what changed? WordPress problems almost always follow an update, a new plugin or a code change. Common cases and usual causes: a white screen is typically a PHP fatal error; a 500 error means checking logs; 404s on every page but the homepage usually means resaving permalinks; broken CSS often means a caching or minification conflict; mixed content warnings follow HTTPS migrations with hard-coded HTTP URLs; and a slow admin frequently means a plugin doing too much on every page load.
Confirm exactly what triggers the problem and where.
A plugin update, a theme change, new code. Nearly always the cause.
Deactivate plugins, switch to a default theme — on staging, not production.
PHP error logs usually name the file and line.
JavaScript errors and failed requests for front-end faults.
Connection errors and query problems for the harder cases.
Verify before it reaches visitors.
Confirm the fix held and nothing else broke.
[ ] Core, plugins and themes updated [ ] Backups running and verified [ ] Security monitoring active [ ] Broken links checked [ ] Forms tested end to end [ ] Email delivery confirmed [ ] Performance measured [ ] Search Console reviewed [ ] Analytics reviewed [ ] SSL certificate valid [ ] Domain renewal current [ ] Database reviewed if it has grown [ ] Major changes tested on staging
MISTAKES
The most common route into a compromised site.
Combined with an unprotected login page.
Every extra admin account is another way in.
Frequently modified with backdoors. Never worth it.
Backups that have never been restored.
Breaking every URL without redirects.
Several caching, SEO or optimisation plugins conflicting.
Camera originals displayed at 600 pixels.
A blanket setting delaying the LCP element.
Overwritten on the next update.
Custom post types lost when the theme changes.
A slow server capping everything else.
Unused plugin code still sitting on the server.
No staging, no way back.
Dozens of single-use tags creating thin archives.
Exposing paths and errors to visitors.
FAQ
Short answers to the questions people ask most about WordPress as a CMS, platform and development environment.
NEXT TOPICS
Each platform makes different trade-offs between control, ease of use, hosting responsibility and cost. Which suits a project depends on the project rather than on any general ranking.
Another established open-source CMS with a different administration model and its own extension ecosystem.
An open-source CMS oriented toward structured content and complex data relationships, with a steeper learning curve.
A hosted visual development platform combining design tools with a CMS, producing sites without self-hosting.
A hosted website builder focused on ease of use, with the platform managing hosting and infrastructure.
A hosted commerce platform built specifically for selling, where WordPress needs WooCommerce to compete.
A hosted builder with strong design templates and integrated hosting, trading flexibility for simplicity.
A design-led site builder with a visual canvas and publishing, aimed at designers building marketing sites.
How SEO principles apply across any CMS, including WordPress.
Continue exploring CMS platforms, hosting, website development, SEO, performance and ecommerce topics.