# WordPress Feature Roadmap Proposal for Ploi

**Project:** Sites | **Board:** In progress | **Votes:** 20
**URL:** https://roadmap.ploi.io/projects/2-site-level-requests/items/1300-wordpress-feature-roadmap-proposal-for-ploi

---

This outlines WordPress-focused features that would make Ploi.io the go-to platform for developers and agencies managing multiple WP installs.

As it stands, ploi is great - but i feel the below would add a huge advantage over the competition. This list is not exhaustive but i feel would be a great starting point.

## WordPress Config

### Installation
I think this could be expanded on - maybe transition installation and config using wp-cli
* wp core download
* wp config set db etc
* wp core install
1. --url={pulled from site}
2. --title={pulled from free text field in ploi}
3. --admin_user={pulled from free text field in ploi}
4. --admin_password={automatically generated, but pulled from text fiels}
5. --admin_email={again - pulled from field (maybe default to ploi user?}}
* ability to run custom wp cli copmmand afetr install?

### General
* Ability to see version info on general tab? https://roadmap.ploi.io/projects/3-panel-requests/items/1105-show-project-laravel-wordpress-etc-version-on-the-sites-list
* Theres some other useful info available that could be displayed in the dashboard.
* Run custom wp-cli commands
* Per site resource metrics would allow the ability to find a site that is being hammered. requency tied to Ploi’s existing check intervals.
* Ability to quickly enable and disable WP debug. and add that log file to the logs section on the site panel.
* One-click login. but this will probably need a mu-plugin. (not too important
* WP Cron can be triggered using wp-cli - related https://roadmap.ploi.io/projects/2-site-level-requests/items/607-option-for-run-wordpress-cron-with-wp-cli

## Staging / Templates / Cloning
* Ability to clone a wordpress site (use wp db export to dump the db in the clone) wp search-replace for handling of url changes.
* Ability to create a staging site using a similar method (making sure no-index is set)
* The above would allow the creation of a blueprint / template site. Maybe could be marked in a templates section in ploi.
* cross server cloning would be helpful.

See - https://roadmap.ploi.io/projects/2-site-level-requests/items/939-clone-wp-incl-database

## Caching
* consider use of nginx helper plugin installation and config in ploi
* adopt WP_REDIS_PREFIX per site to avoid wp_ conflicts

both above should be achievable using wp-cli as well

## Security
* Integrate with Wordfence Threat Intel API (free for commercial use).
* Flag outdated/insecure plugins/themes.
* Periodic wp core/plugin verify-checksums
* 7g/8g firewall https://perishablepress.com/8g-firewall/ works with all sites, not just WP
* Ability to quickly enable / disable xml-rpc
* fail2ban integration with wordpress rules
* support for editing wp-config.php files that are placed outside the webroot directory. https://roadmap.ploi.io/projects/3-panel-requests/items/1192-wordpress-support-for-wp-configphp-outside-webroot

## Backups
Although more server level, WP DB and files would ideally be saved in a single archive. this could be simplified by allowing a custom command to be run before and after backup. Or maybe a checkbox that will run a wp db export whatever.sql then remove after??? On restore - the db would have to be re-imported, then the file deleted.

See - https://roadmap.ploi.io/projects/6-api-level-requests/items/1247-implement-restore-backup-of-a-website-specially-for-wordpress-based-websites

## WordPress updates
* Ability to see outstanding updates and update wither wp, plugin, or theme etc.

Thats off the top of my head - i have tried linking existing roadmap items where poss.

Apologies for any terrible markdown formatting :/

---

## Comments

**Kay van Aarssen** (2025-09-18T19:07:37+00:00):
- WP-CLI Search and Replace - also for Elementor

**phil** (2025-09-22T11:48:03+00:00):
EdwardG added some extra features that would be helpful that I probably missed...

* Staging with a custom domain
* PHP settings to change per site from the panel (This is possible, but require knowledge of php config files), a few simple fields (on the site level) like execution time, input time, input vars, memory limit, post max size, max upload, session garbage collection time, php worker count.
* We have FastCGI cache clearing per site, but Redis / opcache per site would be very handy
* ModSecurity implementation

Thanks again Edward - lets keep this conversation going.

**Brendyn** (2025-10-31T03:33:43+00:00):
Would love to help test any steps in this direction. We still use Gridpane because of the cloning and simplicity of full WP support and I'd love WP to feel as integrated as laravel does on Ploi

**Stephan Rohaan** (2025-10-31T09:29:02+00:00):
Most of the key features have already been mentioned here. I would be super happy to help test anything if this starts moving forward. Would be a huge relieve to have all of our websites managed through ploi.

**Mike Reall** (2025-12-19T22:21:44+00:00):
Changing the theme or disabling/enabling a plugin would be useful.

**Kendric** (2025-12-24T12:41:56+00:00):
Also fail2ban config for WP maybe

**Mohamed Alaa** (2025-12-29T12:13:29+00:00):
Bubblewrap https://github.com/containers/bubblewrap can be used for better userspace isolation when a site user accesses shell through SSH. 

Currently, users are able to see other users processes, home directories and critical system files are also accessible. Such critical info should be only available to root and ploi

**Shawn** (2026-02-23T15:38:06+00:00):
https://roadmap.ploi.io/projects/3-panel-requests/items/1435-more-settings-in-the-panel

**Brendyn** (2026-03-05T03:05:20+00:00):
Just looking around at the state of play as we move away from Gridpane

7G/8G rules are super handy for high target platforms like WP. And the combined backup of database and files are the same time with seamless restore and the ability to clone over existing sites (on other servers as well) is key to a smooth workflow. 

Here's a nice example from Spinwpup on flexible backup settings

 ![](https://roadmap.ploi.io/storage/XGJ6lzoz5ufph8lDqgPCpz8QnqMNaESj9W7Xv6JI.png)

**Dennis** (2026-03-29T06:42:26+00:00):
👀 I have started.

Multiple repositories:

![](https://roadmap.ploi.io/storage/bS6T3M95u3V6slxCAfrCBfpDtELOHw2OtcSa3qQD.png)

Plugin & theme management:

![](https://roadmap.ploi.io/storage/nhW5Yn5tQZtYTw0sZM1UndgZzegPqVxRkA2GBeDu.png)
**All will be available in the Ploi API as well!**

**Kay van Aarssen** (2026-03-31T19:53:16+00:00):
[@Dennis](/user/Dennis) May is suggest Bulk actions for plugin / theme pages for bulk removal of themes for example / unwanted plugins in one go.

wp cli can also do this with specifing multiple plugins / themes

**Kay van Aarssen** (2026-04-03T17:48:53+00:00):
[@Dennis](/user/Dennis) as discussed: https://roadmap.ploi.io/projects/2-site-level-requests/items/1475-hide-getting-started-when-wordpress-or-other-is-detected
Since its not completly WordPress related hereby a seperate feature request.

**Stephan Rohaan** (2026-04-07T15:03:24+00:00):
Another idea would be to implement a way to protect sites from malware. I've come across third-party systems like Imunify360 that actively scan directories and databases to verify whether a site is safe. If it isn't, the system automatically removes or cleans the affected files to restore the site to a safe state.

Of course, when hosting a site you hope everything stays secure, but I've had a few situations where hackers managed to get in and take control using malware. Having something like this built in would be a huge relief when it happens, you'd be able to fix the issue instantly (or prevent it)

**Dennis** (2026-04-14T17:36:59+00:00):
Yesterday a whole lot was added again to the WordPress tab:

- **WP_DEBUG toggle** — Flip WP_DEBUG on or off from the panel, with smarter wp-config.php location handling and UX polish.
- **Site cloning** — Clone a full WordPress site including its database, with automatic Cloudflare subdomain matching.
- **Bulk plugin actions** — Activate, deactivate, update, or delete multiple plugins at once; install card moved below the list.
- **Bulk theme actions** — Manage multiple themes in one go with bulk activate, update, and delete.
- **Plugin & theme install/delete** — Install and remove plugins and themes directly from the panel, no CLI needed.
- **Search-replace** — Safely swap URLs or strings across your WordPress database, ideal after a clone or domain change.
- **API support** — New API endpoints for site cloning, plugin & theme install/delete, and search-replace, so you can automate everything from your own tooling.

**Dennis** (2026-04-21T11:35:37+00:00):
Also releasing today: 

![](https://roadmap.ploi.io/storage/HFe7OQnw6ilbsJ5NJJg2TR4aRfA0c3RXzpr8h7QY.png)
Also available via API: https://developers.ploi.io/wordpress-management/complete-install

**Olli Koskimäki** (2026-04-27T18:09:18+00:00):
1. Setting up cron for wp works as it should work. Would be great to have similiar single click for redis/valkey.
2. Sometimes cron for wp fails. There should be notification if this happens.

**Angel** (2026-05-01T17:01:57+00:00):
Some comments of what I have been finding out testing the current solution: 
- no WordPress updates button, which is missing because we have plugins and themes updates, so WP makes sense as well. 
- Missing clear cache and rewrite permalinks. Those are critical to run after each update.
- filter or at least sort plugins by active/inactive
- remove activate button for dropin plugins (you can test it with query-monitor plugin that has one dropin) 


**Angel** (2026-05-01T17:05:04+00:00):
I found an issue, when the site WP CLI  is not working due to a plugin with bad code (obsolete or whatever), then nothing works on the dashboard. 
Running the commands for plugins list and updates with --skip-plugins --skip-themes will allow for ploi dashboard to work even when a plugin is breaking wp cli. 


**Kay van Aarssen** (2026-05-06T18:06:41+00:00):
Dennis first time testing site clone (WordPress) - but it will not create a new user / you do not have to option to create a new user. Can you please make this an option? 
Now we have a dev site that needed to be cloned to live domain - and now we have it under the same dev-username
And if we create the domain / user first - we get that the domain already exists so doing everything by hand again now

**Kay van Aarssen** (2026-05-06T18:07:14+00:00):
Dennis first time testing site clone (WordPress) - but it will not create a new user / you do not have to option to create a new user. Can you please make this an option? 
Now we have a dev site that needed to be cloned to live domain - and now we have it under the same dev-username
And if we create the domain / user first - we get that the domain already exists so doing everything by hand again now

