Running WordPress on your own VPS gives you full control over PHP, caching and resources. It also means you are responsible for security, updates and backups. If you would rather not manage the server, our WordPress Cloud Hosting or a Managed VPS with StackCP installs WordPress in one click.
This guide assumes you followed How to Install a LEMP Stack, so Nginx, PHP-FPM and MariaDB are already working and your domain points to the VPS.
Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.
Step 1: Create the database
sudo mariadb
At the MariaDB prompt (use your own strong password):
CREATE DATABASE wordpress CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci; CREATE USER 'wpuser'@'localhost' IDENTIFIED BY 'change-this-long-password'; GRANT ALL PRIVILEGES ON wordpress.* TO 'wpuser'@'localhost'; FLUSH PRIVILEGES; EXIT;
Step 2: Download WordPress
cd /tmp curl -LO https://wordpress.org/latest.tar.gz tar xzf latest.tar.gz sudo mkdir -p /var/www/example.com sudo rm -rf /var/www/example.com/public sudo mv wordpress /var/www/example.com/public
The rm line removes the empty test folder from the LEMP guide. Skip it if that folder already holds something you need.
Step 3: Create wp-config.php
cd /var/www/example.com/public sudo cp wp-config-sample.php wp-config.php sudo nano wp-config.php
Fill in DB_NAME (wordpress), DB_USER (wpuser), DB_PASSWORD and leave DB_HOST as localhost. Replace the block of put your unique phrase here lines with fresh keys from api.wordpress.org/secret-key/1.1/salt/.
Step 4: Set ownership and permissions
PHP must own the files so WordPress can install plugins and updates without asking for FTP details:
# Ubuntu / Debian (use apache:apache on AlmaLinux / Rocky) sudo chown -R www-data:www-data /var/www/example.com/public sudo find /var/www/example.com/public -type d -exec chmod 755 {} \; sudo find /var/www/example.com/public -type f -exec chmod 644 {} \; sudo chmod 640 /var/www/example.com/public/wp-config.php
AlmaLinux and Rocky Linux: SELinux
SELinux blocks PHP from writing files and making outgoing connections by default. Allow uploads, updates and plugin installs:
sudo dnf install -y policycoreutils-python-utils sudo semanage fcontext -a -t httpd_sys_rw_content_t "/var/www/example.com/public/wp-content(/.*)?" sudo restorecon -Rv /var/www/example.com sudo setsebool -P httpd_can_network_connect 1
For one-click core updates, WordPress also needs to write outside wp-content; many admins update the core with WP-CLI instead (see below).
Step 5: Check the Nginx configuration
The server block from the LEMP guide already works for WordPress: the line try_files $uri $uri/ /index.php?$args; makes pretty permalinks work, and client_max_body_size 64M; allows larger uploads. Make sure root points to /var/www/example.com/public, then run sudo nginx -t && sudo systemctl reload nginx.
Step 6: Add HTTPS before installing
Get the certificate first so WordPress saves https:// addresses from the start:
sudo certbot --nginx -d example.com -d www.example.com
Details: How to Install a Free SSL Certificate with Certbot.
Step 7: Run the installer
- Open
https://example.com. Choose your language. - Enter the site title, an admin username (not
admin), a strong password and your email address. - Click Install WordPress and log in at
https://example.com/wp-admin.
Recommended extras
WP-CLI
curl -O https://raw.githubusercontent.com/wp-cli/builds/gh-pages/phar/wp-cli.phar chmod +x wp-cli.phar sudo mv wp-cli.phar /usr/local/bin/wp # always run it as the web user (apache on AlmaLinux / Rocky) sudo -u www-data wp --path=/var/www/example.com/public core update sudo -u www-data wp --path=/var/www/example.com/public plugin update --all
Real cron instead of WP-Cron
Add define('DISABLE_WP_CRON', true); to wp-config.php above the That's all, stop editing line, then open the web user's crontab with sudo crontab -u www-data -e (-u apache on AlmaLinux/Rocky) and add:
*/5 * * * * php /var/www/example.com/public/wp-cron.php > /dev/null 2>&1
A new VPS has no mail server, so contact forms and password resets may not arrive. Install an SMTP plugin and send through a proper mailbox; see WordPress SMTP Plugin Settings.
Security and backups
- Keep WordPress, plugins and themes updated, and remove anything you don't use.
- Limit login attempts with a security plugin, and protect SSH with Fail2ban.
- Back up files and the database daily: How to Back Up Your VPS.
Common problems
- Error establishing a database connection: the database name, user or password in
wp-config.phpdoesn't match Step 1. Test withmariadb -u wpuser -p wordpress. - WordPress asks for FTP details when installing plugins: file ownership is wrong. Repeat the
chownin Step 4. - Uploads fail with “HTTP error” or 413: raise
client_max_body_sizein Nginx andupload_max_filesize/post_max_sizeinphp.ini. - Permalinks give 404: the
try_filesline is missing from thelocation /block.
Need help?
If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.
Categories
Written by
FimuroHost Team
Technical Writer