Workflow

A clear security workflow for daily WordPress operations

Follow a predictable path from setup to response: local plugin ownership first, cloud authority where durable state and team coordination matter.

Main Steps

From setup to recovery

Each step is written for a public website visitor deciding what WPLURA does and where the next action belongs.

01

Connect

Start from a site-owned WordPress plugin flow, then hand off to hosted cloud authentication only when cloud workflows are needed.

  • No cloud password collection inside plugin admin
  • Product identity and callback-code handoff
  • Signed site-agent communication after activation

02

Protect

Enable product-specific local controls and understand which features stay local versus which require cloud entitlement.

  • Local security posture
  • Product-scoped settings
  • Free vs paid boundary clarity

03

Monitor

Use public checks, product reports, and customer account views to identify risk without exposing internal operations.

  • SiteCheck and connected-site signals
  • Customer-owned reports
  • Support-ready evidence

04

Recover

Use guided response, backup/restore, and disaster-recovery workflows with realistic confirmations and durable job state.

  • Resumable operational jobs
  • Restore readiness checks
  • Manual recovery guidance on failure

Incident Timeline

Before, during, and after an incident

01

Prepare

Set roles, product scope, backup posture, retention expectations, and escalation paths before an incident.

02

Identify

Review warnings, scan results, public risk, customer reports, and recent changes before taking action.

03

Fix

Contain and remediate through approved plugin, customer-panel, support, or cloud workflow paths.

04

Verify

Confirm the site is stable, reports are updated, follow-up actions are assigned, and recovery guidance is documented.