Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

SSH gives you a shell on your WordPress server; WP-CLI adds WordPress-aware commands for inspecting, updating, backing up and troubleshooting the site. The safest workflow is to connect, verify the directory, export a database backup, use explicit --path (and --url for multisite), then make one controlled change at a time. This guide covers the commands and recovery checks that matter in 2026.

What SSH and WP-CLI each do

SSH (Secure Shell) logs you into the server account supplied by your host and opens a normal command-line shell. It does not understand WordPress by itself. WP-CLI is the WordPress Command Line Interface for performing administrative and development tasks programmatically, according to the official beginner’s guide. Most hosts provide SSH access, but the username, port, key and document root are host-specific.

Use ordinary shell tools for files, processes and logs; use WP-CLI for WordPress operations such as plugin management, database exports, cron and search-replace.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Workflow Best for Main caution
Interactive SSH, then wp ... Exploration, diagnostics and several commands in sequence Confirm the current directory and account before every state-changing command
WP-CLI --ssh Repeatable commands against a remote installation from your local terminal The remote machine must have wp available on its PATH

Connect and orient yourself

Use the connection details and key supplied by your host. Do not assume that the site lives under /var/www or runs as a particular web-server user.

  1. ssh -i ~/.ssh/id_ed25519 [email protected]
  2. pwd — print the directory you are actually in.
  3. ls -la — show hidden files, including whether this is a WordPress root.
  4. cd /var/www/example.com — replace this with your host’s real document root.
  5. find .. -maxdepth 2 -name wp-config.php -print — locate likely installations when the path is unclear.

Before running WP-CLI, verify that wp-config.php, wp-admin, wp-includes and wp-content belong to the site you intend to manage. On a server with several sites, keep --path=/absolute/path/to/site on every command instead of relying on the shell’s current directory.

Verify WP-CLI and the WordPress installation

Run these read-oriented checks first:

  • wp --info — show WP-CLI, PHP and environment details.
  • wp core version --path=/var/www/example.com — report the installed WordPress version.
  • wp option get siteurl --path=/var/www/example.com — confirm which URL the installation uses.
  • wp plugin list --path=/var/www/example.com — list active and inactive plugins and their versions.
  • wp theme list --path=/var/www/example.com — list installed themes and activation status.

--path is an official WP-CLI global parameter; the WP-CLI help documentation lists it with the other global options. For multisite, target a particular site with the network’s URL, for example --url=https://subsite.example, in addition to the correct path.

Inspect files and configuration without exposing secrets

  • ls -lah wp-content — inspect directories and approximate file sizes.
  • find wp-content/uploads -type f -mtime -7 -print | head — sample files changed in the last seven days.
  • stat wp-config.php — check ownership, permissions and modification time.
  • php -v — see the PHP version used by the shell account (the web worker may use a different binary).

Treat wp-config.php as secret material: it contains database credentials and salts. Avoid commands that print its contents into a shared terminal, shell history, CI output or a support ticket.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Back up before changing anything

A database export is the minimum recovery point for updates, search-replace and permission work. Confirm where the backup will be stored and how you would restore it; a file-level backup is also needed if themes, plugins or uploads may be affected.

mkdir -p ~/backups
wp db export ~/backups/site-$(date +%F).sql --path=/var/www/example.com

Check that the resulting SQL file exists and has a plausible size with ls -lh ~/backups/. Keep the export off the same failure domain when possible. Do not begin a destructive operation until you know the host’s database restore procedure or have tested your own restore path.

Check updates, then apply them deliberately

Start with availability and dry runs:

wp core check-update --path=/var/www/example.com
wp plugin update --all --dry-run --path=/var/www/example.com
wp theme update --all --dry-run --path=/var/www/example.com

Review the proposed versions, compatibility concerns and maintenance window. Only then run the corresponding real update command. The official command index documents the core, plugin, theme and database command families. Keep the database export and a tested rollback plan until the site has been checked in a browser and its logs are clean.

Routine cache, cron and rewrite maintenance

These commands invoke WordPress APIs rather than editing database rows by hand:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • wp cache flush --path=/var/www/example.com — clear the WordPress object cache.
  • wp cron event list --path=/var/www/example.com — inspect scheduled events and timestamps.
  • wp cron event run --due-now --path=/var/www/example.com — run events that are due.
  • wp rewrite flush --path=/var/www/example.com — rebuild rewrite rules after appropriate structural changes.

Run cron manually only when you understand the workload; a due event can trigger email, imports or other expensive jobs.

Move a site with a dry-run search-replace

WP-CLI’s search-replace command understands serialized data, which makes it safer for WordPress URLs than an ad-hoc SQL replacement. Export the database first, then preview the affected rows:

wp search-replace 'https://old.example' 'https://new.example' --all-tables-with-prefix --dry-run --path=/var/www/example.com
wp search-replace 'https://old.example' 'https://new.example' --all-tables-with-prefix --path=/var/www/example.com

Inspect the dry-run counts and table scope. Check uploads, redirects, multisite domains and third-party integrations separately; a replacement can be technically successful while an external service still points at the old address.

Troubleshoot a broken site in layers

1. Confirm the shell and path

Repeat pwd, ls -la and wp --info. A “not a WordPress installation” error often means the command is running one directory too high or against another site’s files.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Turn on WP-CLI diagnostics

wp --debug core version --path=/var/www/example.com

Use the output to distinguish PHP startup errors, missing extensions, permissions and WordPress bootstrap failures. The official shell documentation lists --debug, --skip-plugins, --skip-themes and --ssh as supported global parameters.

3. Isolate plugins and themes

wp plugin deactivate --all --path=/var/www/example.com
wp theme list --skip-plugins --path=/var/www/example.com
wp shell --path=/var/www/example.com

Deactivating all plugins changes live behavior, so use a maintenance window and record the original active set. Re-enable plugins in controlled groups after identifying the cause. wp shell opens an interactive PHP console; use it only if you understand the code you are executing.

4. Read the server logs

Application-level diagnostics cannot replace PHP-FPM, Apache or Nginx logs. The location is host-specific; once you have the correct path, follow new entries with:

tail -f /path/to/error.log

Look for the timestamp of the failure, PHP fatal errors, upstream timeouts, permission denials and exhausted memory. Stop the command with Ctrl-C.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Run WP-CLI directly on a remote site

Instead of opening an interactive shell, pass the remote target to WP-CLI:

wp plugin list [email protected]:2222~/srv/www/example.com
wp cache flush [email protected]~/srv/www/example.com

The documented syntax is --ssh=[<scheme>:][<user>@]<host>[:<port>][<path>]. The remote machine must have wp on its PATH; aliases can also be used. See the official remote-execution guide for the supported user, port and path forms.

Shell tools that complement WP-CLI

  • du -sh . wp-content/* — find large directories before investigating disk exhaustion.
  • grep -R "Fatal error" /path/to/logs | tail -n 20 — sample recent fatal-error lines (use the real log path).
  • ps aux | grep -E 'php-fpm|apache|nginx' — check whether expected services have processes.
  • rsync -a --dry-run ./ [email protected]:/srv/www/example.com/ — preview a file transfer.

Review both source and destination before replacing --dry-run with a real rsync. Do not add --delete until the direction, exclusions and backup have been independently confirmed.

A safe command checklist

  1. Authenticate with the host-provided key, account and port.
  2. Run pwd and ls -la; locate the correct wp-config.php.
  3. Use an explicit --path; add --url when targeting a multisite subsite.
  4. Take and verify a database export before any state-changing command.
  5. Prefer dry runs for updates, search-replace and file synchronization.
  6. Record what you changed and how to restore it.
  7. Afterward, test the site, cron, cache behavior and relevant logs.

Frequently Asked Questions

Can I manage WordPress over SSH without WP-CLI?

Yes, SSH provides the server shell, but it does not provide WordPress-aware operations. WP-CLI is the tool that safely exposes commands for core, plugins, themes, database exports and maintenance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why does WP-CLI say this is not a WordPress installation?

The command is commonly pointed at the wrong directory. Recheck pwd, locate wp-config.php, and pass the installation’s absolute directory with --path.

Is a database export a complete WordPress backup?

No. It preserves database content, but themes, plugins, uploads and other files require a separate filesystem backup when those assets matter to recovery.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.