Home  ›  CMS  ›  WordPress

CMS / WORDPRESS

WordPress: Complete Guide to the CMS, Themes, Plugins & Website Building

Learn how WordPress works as a content management system, from the dashboard and Block Editor to themes, plugins, SEO, security, performance, WooCommerce and custom development.

Current information, honest trade-offs and no invented statistics.

WORDPRESS CMS ARCHITECTURE
VISITORRequests a page in the browser
WEB SERVERPasses the request to PHP
WORDPRESS COREThe open-source software doing the work
THEMEControls presentation and templates
PLUGINSAdd functionality core does not include
DATABASEStores content, settings and relationships
HTML / CSS / JSWhat is actually sent back
WEBSITEThe page the visitor sees

Core, theme, plugins and database are separate layers. Confusing them is the source of most WordPress troubleshooting difficulty.

WordPress CMS architecture visual showing core theme plugins and database layers

THE BASICS

What Is WordPress?

WordPress is open-source software for publishing and managing websites — a content management system. It handles creating and organising content, managing media and users, controlling presentation through themes, and extending functionality through plugins.

It began as blogging software, and the description has long outlived its accuracy. WordPress runs business sites, shops, membership platforms, publications and custom applications. Calling it “a blogging platform” today describes what it was in 2004, not what it is.

An important distinction people meet immediately and rarely have explained:

WordPress.org

The open-source software. You download it, install it on hosting you choose, and control everything — themes, plugins, code, data. Free to use; you pay for hosting and whatever else you choose. This is what most people mean by “WordPress”.

WordPress.com

A commercial hosted service built around WordPress. Hosting, updates and maintenance are handled for you, in exchange for less control — what you can install and customise depends on the plan. A different product with a similar name.

They are not the same thing, and advice written for one frequently does not apply to the other. Everything on this page refers to self-hosted WordPress.org unless stated.

Business Websites

Service pages, contact forms, lead capture and the content around them.

Blogs & Publications

Posts, categories, authors and archives — the original use case, still well served.

E-Commerce

Through WooCommerce or other commerce plugins, from small catalogues upward.

Portfolios

Project galleries, case studies and visual work presented with custom layouts.

Membership & Community

Restricted content, user accounts, forums and courses through plugins.

Custom Applications

With custom post types, the REST API and custom development, well beyond a standard site.

CONTENTCreated and edited in the admin
DATABASEStored as structured data
REQUESTA visitor asks for a page
CORE + THEMEWordPress assembles the output
PLUGINSAdd or modify behaviour along the way
HTMLGenerated and sent to the browser
WEBSITEWhat the visitor actually sees
How content moves from the WordPress admin through the database to a rendered website
WordPress installation
├── Core — the software itself
│   ├── admin interface
│   ├── content management
│   ├── user management
│   └── APIs and hooks
├── Themes — presentation
├── Plugins — added functionality
├── Uploads — media files
└── Database — content and settings
    ├── posts and pages
    ├── metadata
    ├── users
    ├── options and settings
    └── taxonomy relationships
WordPress installation structure showing core themes plugins uploads and database

ARCHITECTURE

How WordPress Works

A visitor requests a page. The web server passes it to PHP, which runs WordPress Core. Core loads the active theme and plugins, queries the database for the content, assembles HTML, and sends it back. The browser renders it.

Understanding these as separate layers is the single most useful thing for troubleshooting.

Core is the WordPress software: the admin interface, content management, user handling, the APIs and the hooks other code attaches to. It updates on its own schedule and should never be edited — changes are overwritten on the next update.

Themes control presentation. Plugins add functionality. Neither is part of core, and both come from elsewhere with their own quality and maintenance.

The database holds content and configuration — posts and pages, metadata, users, settings, taxonomy relationships. Media files sit on disk in the uploads folder, with the database recording where they are. That split matters for backups: a database backup without the uploads folder restores your content with every image missing.

WordPress runs on PHP, which is why PHP version compatibility affects the site, themes and plugins alike. See our PHP guide.

CONTENT

The Dashboard, Posts, Pages, Media and Users

The WordPress admin dashboard holds the familiar sections: Posts, Media, Pages, Comments, Appearance, Plugins, Users, Tools and Settings. Plugins and themes add their own menus, so no two installations look identical — if a guide describes a menu you don’t have, a plugin is usually the reason.

Posts and Pages are the two built-in content types, and choosing correctly matters more than it appears:

Aspect
Posts
Pages
Purpose
PostsTime-based content
PagesStructured, standing content
Typical use
PostsBlog articles, news, updates
PagesAbout, Contact, Services, landing pages
Organisation
PostsCategories and tags
PagesHierarchical parent and child pages
Archives
PostsAppear in date, category and author archives
PagesNo archives by default
Feeds
PostsIncluded in RSS
PagesNot included
Ordering
PostsNewest first by default
PagesManual, by menu or hierarchy
WordPress posts compared with pages

The Media Library holds uploaded files. Two habits pay off: rename files descriptively before uploading, since WordPress keeps the filename, and fill in alt text at upload rather than intending to return later. See our image SEO guide.

Categories group posts into broad topics; tags mark specific subjects. Both generate archive pages, which is where restraint matters — dozens of tags used once each produce thin archive pages nobody benefits from.

User roles control what people can do. The principle worth applying is least privilege: give each person the lowest role that lets them do their job. Every administrator account is another route into the site.

Administrator

Full control including plugins, themes, users and settings. Give this to as few people as genuinely need it.

Editor

Can publish and manage all content, including other people's. No access to settings, plugins or themes.

Author

Can publish and manage only their own content.

Contributor

Can write but not publish. Their drafts need approval.

Subscriber

Profile management only. Used for membership and comment setups.

POSTSBlog articles and time-based content
PAGESStanding content like About and Services
MEDIAImages and files, stored on disk
CATEGORIESBroad topic grouping for posts
TAGSSpecific subjects — use sparingly
COMMENTSReader responses, if enabled
USERSAccounts and the roles controlling access
WordPress content types and management areas in the admin dashboard
BLOCKS IN THE EDITOR
TEXTParagraph
TEXTHeading
TEXTList
MEDIAImage
MEDIAGallery
MEDIAVideo
DESIGNColumns
DESIGNGroup
DESIGNSpacer
WIDGETButtons
WIDGETTable
THEMENavigation

Blocks are the components content is built from. Themes and plugins add more.

Common WordPress block types including text media design and theme blocks
BLOCKA single component — a paragraph, image, button
PATTERNA ready-made arrangement of blocks
TEMPLATE PARTA reusable region such as a header or footer
TEMPLATEThe layout for a type of page
SITEAll of it together, edited in the Site Editor
How blocks patterns template parts and templates build up to a complete site

THEMES & EDITING

Themes, the Block Editor and the Site Editor

A theme controls presentation: layout, templates and styling. It should not carry functionality you’d need if you switched themes — that belongs in a plugin. Themes that bundle post types and shortcodes trap you, because changing theme then breaks your content.

WordPress now has two theme architectures, and knowing which you’re using determines which instructions apply.

Block themes are built from block templates and support the Site Editor, where headers, footers, templates and global styles are edited visually in the browser. Classic themes use PHP template files, with customisation through the Customizer, theme options and code.

Neither is better in general. Block themes offer visual control without touching code; classic themes have a mature ecosystem and many established sites run on them perfectly well. The right choice depends on the project, the team and what your existing site already uses.

Two things get confused constantly. The Block Editor (often called Gutenberg, after the project that built it) edits the content of a single post or page — it works with both theme types. The Site Editor edits site-wide structure and styling, and requires a block theme. If you can’t find the Site Editor, you’re almost certainly on a classic theme.

Block patterns are pre-arranged groups of blocks — a hero section, a pricing layout — inserted as a starting point and then edited.

Aspect
Block themes
Classic themes
Built with
Block themesBlock templates in HTML
Classic themesPHP template files
Site-wide editing
Block themesSite Editor
Classic themesCustomizer, where the theme supports it
Templates
Block themesEditable visually in the browser
Classic themesEdited in PHP files
Header and footer
Block themesTemplate parts, editable visually
Classic themesTheme files
Global styles
Block themesA styles interface
Classic themesCSS, often with theme options
Menus
Block themesNavigation block
Classic themesClassic menu system
Widgets
Block themesBlocks in template parts
Classic themesClassic widget areas
Customising safely
Block themesChild theme or style variations
Classic themesChild theme
Block themes compared with classic themes

PLUGINS

WordPress Plugins

Plugins add functionality WordPress Core doesn’t include. This extensibility is the main reason WordPress covers such different kinds of site from one codebase.

Plugins are not inherently good or bad, and the most persistent myth deserves dismissing: there is no correct number of plugins. Neither “under ten is safe” nor “twenty makes a site slow” means anything. One badly built plugin can do more damage than twenty well-maintained ones. What matters is code quality, whether each is actively maintained, whether you actually need it, and whether two of them do the same job.

Plugin security is where most WordPress compromises originate — usually through outdated or abandoned plugins. Keep them updated, install from reputable sources, delete what you don’t use rather than deactivating it (deactivated plugin code still sits on the server), and check whether something has been abandoned before relying on it.

One thing to state plainly: never install nulled or pirated plugins. Paid plugins distributed free have frequently been modified, and the modification is the point — backdoors, injected content, credential harvesting. The saving is not worth what it typically costs.

SEO

Metadata, sitemaps, canonical control and structured data output.

Forms

Contact forms, notifications and submission handling.

E-Commerce

Products, carts, payments and orders.

Security

Login protection, monitoring and hardening.

Caching & Performance

Page caching, asset optimisation and delivery.

Backups

Scheduled backups and restoration.

Analytics

Tracking integration and reporting.

Custom Functionality

Post types, integrations and site-specific code.

COREWordPress on its own
PLUGINAdds a capability core lacks
HOOKSAttaches at defined points in core
RESULTNew functionality, no core edits
THE COSTAnother dependency to maintain and trust
How plugins extend WordPress core through hooks without editing core files

Choosing a plugin

PERMALINKSSet to Post name before publishing anything
TITLESUnique and descriptive per page
HEADINGSOne H1, logical structure below it
SITEMAPGenerated and submitted
CANONICALSCorrect, usually handled by your SEO plugin
INTERNAL LINKSAdded in content, not only in widgets
IMAGESSized, compressed, with alt text
SPEEDMeasured with real-user data
WordPress SEO fundamentals from permalinks through metadata to performance

SEO

WordPress SEO

WordPress does not make a site rank. It produces clean markup and gives you control over the things that matter, which is a decent starting position and nothing more. Content quality, technical health and everything in our website SEO guides still apply.

Permalinks deserve attention on day one. Settings → Permalinks controls URL structure, and the default numeric option produces unreadable URLs. Choose a readable structure — usually Post name — before publishing. Changing it later breaks every existing URL unless you set up redirects, which is entirely avoidable by deciding early. See our technical SEO guide.

SEO plugins — Yoast, Rank Math, All in One SEO among others — handle title and description fields, canonical control, robots directives, XML sitemaps and structured data output. They make these accessible without editing templates.

Two caveats. A green light means the plugin’s own checklist passed, not that a page will rank — some of those checks encode outdated advice, particularly around keyword frequency. And use one: overlapping SEO plugins produce duplicate structured data, conflicting sitemaps and contradictory meta tags. None is universally best; they cover similar ground differently.

PERFORMANCE

WordPress Performance and Caching

WordPress is not inherently slow. Performance depends on hosting, theme, plugins, images and how pages are built. A lean WordPress site outperforms a bloated custom one comfortably.

Hosting sets the floor. Cheap shared hosting with slow server response puts a limit on everything else — no amount of image optimisation fixes a slow time to first byte. This is the first thing to check when a site feels slow everywhere rather than on specific pages.

Caching stores generated output so WordPress doesn’t rebuild every page on every request. Page caching serves stored HTML. Object caching stores database query results, which helps most on query-heavy sites. Browser caching and a CDN reduce repeat downloads and serve assets from closer infrastructure. Which combination helps depends on the site — a mostly static brochure site and a logged-in membership site have completely different caching needs.

Images are usually the heaviest thing on a page: correct dimensions, sensible compression, modern formats, and lazy loading below the fold but never on the hero image, which is typically your LCP element.

Use one optimisation plugin, not three. Stacked caching and optimisation plugins conflict, duplicate work and produce problems harder to diagnose than the slowness they were meant to fix. See Core Web Vitals and website speed.

HOSTINGServer response time sets the floor
CACHINGAvoid rebuilding pages on every request
IMAGESUsually the heaviest assets
PLUGINSEach adds queries, CSS and JavaScript
THEMEPage complexity and DOM size
DATABASEGrows over time and needs occasional attention
DELIVERYCDN and compression for what remains
MEASUREDiagnose before optimising
WordPress performance factors from hosting through caching and images to delivery

Security checklist

Backup and update workflow

BACKUPFull site and database, stored off-site
STAGINGApply updates on a copy first
TESTCheck the site actually works
DEPLOYApply to production
VERIFYConfirm nothing broke
RESTORE TESTPeriodically prove the backup works
WordPress update workflow from backup through staging and testing to deployment
 WordPress security checklistEXAMPLE
[ ] Keep core, themes and plugins updated
[ ] Use strong, unique passwords with two-factor authentication
[ ] Limit administrator accounts to those who need them
[ ] Delete unused plugins and themes rather than deactivating
[ ] Install only from reputable sources — never nulled software
[ ] Choose hosting that takes security seriously
[ ] Serve everything over HTTPS
[ ] Keep tested, off-site backups
[ ] Protect the login page against automated attempts
[ ] Monitor for unexpected file changes
[ ] Review user accounts periodically
[ ] Never leave debug output enabled in production

SECURITY & MAINTENANCE

Security, Updates, Backups and Staging

WordPress security is layered, and no security plugin makes a site secure on its own. A plugin adds monitoring and hardening; it does not compensate for outdated software, weak passwords or poor hosting.

The largest single factor is updates. Most WordPress compromises exploit known vulnerabilities in outdated plugins — issues that were patched, sometimes months earlier. Updating is unglamorous and it is the work.

Backups need stating carefully: a backup you have never restored is a hope, not a backup. Back up the database and the uploads folder, store copies off-site rather than only on the same server, and actually test a restore occasionally. Plenty of people discover their backups were incomplete at the worst possible moment.

Staging is a copy of the site for testing updates, new plugins and design changes before they reach visitors. Many hosts provide it. For a site that matters commercially, updating directly on production is a gamble you will eventually lose.

Migration — moving hosts or domains — needs the same care: back up first, move files and database, update configuration and URLs, test thoroughly before switching DNS, and watch for broken links, missing files and mixed content afterwards.

HOSTING

WordPress Hosting and Requirements

WordPress needs a server running PHP with a supported database. Hosting types differ mainly in resources, management and price: shared hosting is cheapest with resources split between sites, VPS and cloud give dedicated resources with more responsibility, and managed WordPress hosting handles updates, caching, backups and staging at higher cost.

Hosting affects more than speed. Server response time, uptime, PHP version availability, resource limits and security practices all shape what the site can do. It’s the foundation, and it’s where under-investing shows up everywhere else. See our hosting and domains guides.

WordPress.org currently recommends a hosting environment with PHP 8.3 or greater, MariaDB 10.11 or greater or MySQL 8.0 or greater, and HTTPS support.

Two notes on that. These are recommendations rather than hard minimums — WordPress runs on older versions, though doing so means missing security and performance improvements. And recommendations change; check wordpress.org for the current figures rather than trusting any article, including this one, indefinitely.

Shared Hosting

Lowest cost, resources shared between many sites. Workable for small, low-traffic sites.

VPS & Cloud

Dedicated resources with more configuration control, and more responsibility for maintaining it.

Managed WordPress

Updates, caching, backups and staging handled for you. Costs more, saves maintenance time.

CURRENT WORDPRESS.ORG RECOMMENDATIONS
PHPVersion 8.3 or greater
DATABASEMariaDB 10.11+ or MySQL 8.0+
HTTPSSupport required

These are the recommended environment specifications published by WordPress.org. They are recommendations rather than absolute minimums, and they change over time — verify current figures at wordpress.org before relying on them.

WordPress.org recommended hosting environment specifications
 WordPress — actions, filters and a child themeEXAMPLE
<?php
// An ACTION runs your code at a defined point.
// Nothing is returned — you are doing something.
add_action( 'wp_enqueue_scripts', function () {
    wp_enqueue_style(
        'child-style',
        get_stylesheet_directory_uri() . '/style.css',
        array( 'parent-style' )
    );
} );

// A FILTER modifies data passing through.
// You must return the value.
add_filter( 'excerpt_length', function ( $length ) {
    return 30;
} );

add_filter( 'the_content', function ( $content ) {
    if ( is_single() ) {
        $content .= '<p>Thanks for reading.</p>';
    }
    return $content;   // always return
} );

// A custom post type belongs in a PLUGIN, not a theme —
// so the content survives a theme change.
add_action( 'init', function () {
    register_post_type( 'project', array(
        'labels'       => array( 'name' => 'Projects' ),
        'public'       => true,
        'has_archive'  => true,
        'show_in_rest' => true,   // enables the Block Editor and REST API
        'supports'     => array( 'title', 'editor', 'thumbnail' ),
    ) );
} );

// Child theme style.css header (classic themes)
/*
Theme Name: Example Child
Template: example-parent
*/

// Never edit core files. Updates overwrite them.

DEVELOPMENT

WordPress Development, Hooks and APIs

WordPress development uses PHP on the server with HTML, CSS and JavaScript in the browser. What makes it extensible is hooks.

Actions let your code run at defined moments — when WordPress initialises, when a post saves, when scripts load. You’re doing something; nothing is returned. Filters let you modify data as it passes through — changing an excerpt length, adjusting content before display. You must return the value, and forgetting to is the classic filter bug that blanks content.

Both work without editing core files, which is the point. Never edit core — updates overwrite it.

A child theme lets you customise a classic theme without losing changes when the parent updates. For block themes, style variations and Site Editor changes often cover what a child theme used to.

The dividing line for custom code: presentation belongs in a theme, functionality belongs in a plugin. A custom post type defined in a theme disappears when you switch themes, taking your content’s visibility with it.

The REST API exposes WordPress data over HTTP, enabling headless setups where WordPress manages content and a separate frontend renders it. That buys flexibility and costs complexity — two systems, two deployments, and you take on rendering and SEO decisions yourself. It’s one architecture among several, not an upgrade. See our website APIs guide.

THE ECOSYSTEM

Elementor, WooCommerce and Multisite

Three things frequently mistaken for WordPress features. None is part of WordPress Core.

Elementor

A third-party visual page builder plugin. It provides containers, widgets, responsive controls, templates and a Theme Builder for headers, footers and archive layouts. It replaces much of what the theme would do, which is why an Elementor site is built quite differently. Powerful, and it adds its own CSS and JavaScript — worth building restrained pages rather than assuming the builder is free.

WooCommerce

A plugin adding e-commerce: products, variations, cart, checkout, orders, payments, shipping and inventory. It changes performance characteristics noticeably — product and checkout pages carry far more than a standard page, and caching them needs care since parts must stay dynamic.

Multisite

A core feature, though not enabled by default: several sites sharing one WordPress installation, themes and plugins. Genuinely useful for networks of genuinely similar sites under one administration. For a business with three unrelated sites, separate installations are usually simpler to manage and update.

WORDPRESSCore, content and database
ELEMENTORVisual page and theme building
PAGE DESIGNBuilt in the editor, not in theme files
FRONTENDRendered output with builder assets
How Elementor builds page designs on top of WordPress
WORDPRESSThe underlying CMS
WOOCOMMERCEAdds products and commerce
PRODUCTSCatalogue and variations
CARTSession-based, resists caching
CHECKOUTPayment and order creation
ORDERStored, with fulfilment workflow
How WooCommerce adds e-commerce functionality to WordPress

TROUBLESHOOTING

Accessibility, Responsive Design and Troubleshooting

Accessibility in WordPress depends on your theme, your content and your plugins — not on WordPress itself. Semantic headings, keyboard navigation, sufficient contrast, real alt text, accessible forms, visible focus and descriptive link text are all things you control.

Accessibility overlay plugins deserve caution: they do not make a site compliant, and the accessibility community’s assessment of them is largely negative. Building accessibly beats bolting something on. See our website accessibility guide.

Responsive design comes from the theme or page builder. Check real breakpoints on real devices rather than trusting the editor preview, and watch for layouts that work at desktop width and fall apart at 360 pixels. See our responsive design guide.

For troubleshooting, the most valuable question is: what changed? WordPress problems almost always follow an update, a new plugin or a code change. Common cases and usual causes: a white screen is typically a PHP fatal error; a 500 error means checking logs; 404s on every page but the homepage usually means resaving permalinks; broken CSS often means a caching or minification conflict; mixed content warnings follow HTTPS migrations with hard-coded HTTP URLs; and a slow admin frequently means a plugin doing too much on every page load.

01

Reproduce

Confirm exactly what triggers the problem and where.

02

Check Recent Changes

A plugin update, a theme change, new code. Nearly always the cause.

03

Test for Conflicts

Deactivate plugins, switch to a default theme — on staging, not production.

04

Check Error Logs

PHP error logs usually name the file and line.

05

Check the Browser Console

JavaScript errors and failed requests for front-end faults.

06

Check the Database

Connection errors and query problems for the harder cases.

07

Fix on Staging

Verify before it reaches visitors.

08

Deploy and Verify

Confirm the fix held and nothing else broke.

Maintenance checklist

 WordPress maintenance checklistEXAMPLE
[ ] Core, plugins and themes updated
[ ] Backups running and verified
[ ] Security monitoring active
[ ] Broken links checked
[ ] Forms tested end to end
[ ] Email delivery confirmed
[ ] Performance measured
[ ] Search Console reviewed
[ ] Analytics reviewed
[ ] SSL certificate valid
[ ] Domain renewal current
[ ] Database reviewed if it has grown
[ ] Major changes tested on staging

MISTAKES

Common WordPress Mistakes

Outdated Software

The most common route into a compromised site.

Weak Passwords

Combined with an unprotected login page.

Too Many Administrators

Every extra admin account is another way in.

Nulled Plugins

Frequently modified with backdoors. Never worth it.

No Tested Backups

Backups that have never been restored.

Changing Permalinks Late

Breaking every URL without redirects.

Stacked Plugins

Several caching, SEO or optimisation plugins conflicting.

Uploading Huge Images

Camera originals displayed at 600 pixels.

Lazy-Loading the Hero

A blanket setting delaying the LCP element.

Editing Core Files

Overwritten on the next update.

Functionality in the Theme

Custom post types lost when the theme changes.

Under-Investing in Hosting

A slow server capping everything else.

Deactivating Instead of Deleting

Unused plugin code still sitting on the server.

Updating on Production

No staging, no way back.

Tag Sprawl

Dozens of single-use tags creating thin archives.

Leaving Debug On

Exposing paths and errors to visitors.

FAQ

WordPress: Frequently Asked Questions

Short answers to the questions people ask most about WordPress as a CMS, platform and development environment.

NEXT TOPICS

Related CMS Topics

Each platform makes different trade-offs between control, ease of use, hosting responsibility and cost. Which suits a project depends on the project rather than on any general ranking.

Joomla

Another established open-source CMS with a different administration model and its own extension ecosystem.

Drupal

An open-source CMS oriented toward structured content and complex data relationships, with a steeper learning curve.

Webflow

A hosted visual development platform combining design tools with a CMS, producing sites without self-hosting.

Wix

A hosted website builder focused on ease of use, with the platform managing hosting and infrastructure.

Shopify

A hosted commerce platform built specifically for selling, where WordPress needs WooCommerce to compete.

Squarespace

A hosted builder with strong design templates and integrated hosting, trading flexibility for simplicity.

Framer

A design-led site builder with a visual canvas and publishing, aimed at designers building marketing sites.

Website SEO

How SEO principles apply across any CMS, including WordPress.

Explore the WordPress Ecosystem

Continue exploring CMS platforms, hosting, website development, SEO, performance and ecommerce topics.