Two WordPress sites can look identical on launch day and behave very differently a year later. On one, the marketing team adds a project in minutes and updates install without drama. On the other, every update breaks something and only the original developer understands how it works. The gap comes down to a handful of WordPress best practices that visitors never see.
Here they are as an owner’s checklist, for questioning a developer before you commission a site or reviewing the one you already run. A note on bias: we build on WordPress, with Elementor or Breakdance where a page builder suits, but we’ll be honest about the trade-offs and about when WordPress is the wrong choice.
WordPress best practices at a glance
A solid WordPress build has six traits:
- A lean theme, or a page builder set up with global styles, so the design is defined once and reused.
- Features in plugins, not the theme, so a redesign changes the look without losing content.
- A short list of maintained plugins, each with one clear job.
- Content types and fields for repeated content such as services, projects and people.
- Individual logins with the lowest role that works, plus an administrator account your business owns.
- Staging, off-site backups and routine updates, so changes are tested before they go live and mistakes can be undone.
The foundation: a lean theme or a well-configured page builder
Lean theme vs multipurpose theme
The riskiest foundation is a multipurpose theme bought for its demo: dozens of layouts, bundled sliders and several “required” plugins. Visitors download code for features you never use, and your site depends on one vendor keeping all of it updated. A lean theme loads little beyond what your pages need.
Page builder vs block editor: an honest comparison
WordPress’s block editor has been part of core since version 5.0 (December 2018). With a block theme and the site editor, added in version 5.9, it can lay out whole pages, headers and footers included. Page builders such as Elementor and Breakdance add their own visual editor. Both can produce a fast, maintainable site; they fail in different ways.
| At a glance | Block editor with a block theme | Page builder |
|---|---|---|
| Licence cost | Included with WordPress | Free versions exist; the full feature set is usually a yearly licence |
| Editing | Capable and still evolving; fewer design controls | Very visual; editors see the page as they change it |
| Code sent to visitors | Typically lighter | Heavier by default; depends on configuration |
| If you switch away | Content in core blocks is stored as standard HTML and carries over | Pages lose their layout and usually need rebuilding |
| Main risk | Custom blocks nobody maintains | Every page styled by hand, with no system behind it |
The setup matters more than the choice. A page builder done well has:
Done badly, changing the brand colour means editing forty pages by hand. Done well, it frees your team: the property developer’s website we rebuilt runs on Breakdance, set up so their marketing team updates everything themselves.
Child themes: where theme changes belong
If someone changes a classic theme’s templates or styles in code, those changes belong in a child theme: a small theme that inherits everything from its parent and holds only your customisations. Edit the parent directly and the next update overwrites the work, so nobody dares update it. Page builder and site editor designs live in the database, so they survive theme updates without a child theme.
Check it yourself. Open Appearance → Themes. If the active theme is a parent theme someone has edited, or an update has been waiting for months, ask why.
Keep features in plugins, not the theme
A theme should decide how things look. What the site does belongs in plugins: content types, shortcodes, contact forms, tracking scripts and integrations. WordPress.org’s theme review rules call this “plugin territory” and keep it out of themes in the official directory.
Here’s why. A developer registers your Projects section inside the theme. Two years later a redesign switches themes, and Projects disappears from the dashboard. The entries are still in the database, but nothing displays or edits them until someone rebuilds that code.
The redesign test. Ask your developer: “If we changed the theme next year, what would we lose?” The right answer is “the design”; content, forms, tracking and integrations should survive.
Custom code belongs in a small site-specific plugin, kept in version control so every change is recorded; our plain-English guide to website development explains how that fits into a release process.
Too many WordPress plugins? Judge the list, not the count
“Too many WordPress plugins” is a common worry, but the count is a poor measure: one badly coded plugin can do more harm than ten careful ones. A typical business site needs plugins for SEO, forms, languages, caching, security and backups, and perhaps a page builder. What matters is what each does, who maintains it and what it loads; how to speed up a WordPress website shows how to audit plugins by their front-end weight.
A plugin check you can run
Go through Plugins → Installed Plugins and ask of each one:
Pirated premium plugins, often called “nulled”, are a well-known route for malware and miss the normal updates. Our WordPress security guide covers the rest of the hardening basics.
Give structured content its own content types
WordPress ships with posts and pages. Most business sites also publish things with a repeated shape: services, projects, team members, job openings. A solid build gives each its own custom post type (WordPress’s term for a content type) with custom fields for its details, and one template that displays every entry. Fields usually come from a plugin such as Advanced Custom Fields or Meta Box; a page builder’s dynamic content features can then display them.
Here’s the difference for a Projects section:
| Task | Projects as ordinary pages | Projects as a content type with fields |
|---|---|---|
| Adding a project | Duplicate an old page and edit its layout | Fill in a form: name, location, year, photos |
| Changing every project’s design | Edit each page by hand | Edit one template |
| “Latest projects” on the homepage | Updated manually, often forgotten | Updates itself |
| Filtering by sector or location | Hard to add later | Categories (taxonomies) make it straightforward |
| A future redesign | Content tangled up with old layouts | Content is data, ready for a new template |
Not everything needs a content type: three services that rarely change can stay as pages. The test is a repeated structure, more than a handful of entries, and regular updates.
Check it yourself. Do Projects, Services or Team have their own dashboard menu items, or is everything under Pages, with dozens of near-identical entries?
Roles, logins and a staging copy
Give everyone the lowest role that works
WordPress has five standard roles on a single site. Most business websites need two or three.
| Role | What it can do | Usually right for |
|---|---|---|
| Administrator | Everything: plugins, themes, users and settings | One or two trusted people, including someone at your company |
| Editor | Publish and edit all content, including other people’s | Marketing leads who run the site day to day |
| Author | Publish and edit their own posts | Regular article writers |
| Contributor | Write their own posts, but not publish them | Occasional writers whose work needs review |
| Subscriber | Manage their own profile | Rarely needed on a business website |
Then check access:
If only your developer can log in, every change and every emergency waits on them.
Test changes on staging first
A staging site is a private, password-protected copy of your website, hosted like the live one. Updates, new plugins and design changes are tried there first, then applied to the live site. Pair it with automatic off-site backups and a restore someone has actually tested.
Tools → Site Health is a quick first check: it flags an outdated PHP version and waiting updates. The website maintenance checklist sets out what should happen weekly, monthly and yearly, whether your own team does it or a website care plan does.
Signs of a badly built WordPress site
Each sign, and what to ask:
| Sign | Ask your developer |
|---|---|
| Updates are postponed because they “break things” | Where does custom code live, and is there a staging copy? |
| Adding a project means copying a page | Could this be a content type with fields? |
| Brand colours differ from page to page | Where are global styles set? |
| A redesign quote says content must be re-entered | What survives a theme change? |
| Only the developer has admin or hosting access | When do we get our own logins? |
One or two can usually be fixed in place. Several together usually point to a redesign rather than more patching; see the signs your website needs a redesign.
When WordPress is the wrong fit
WordPress suits content-rich business websites that will grow, in one language or several. It’s the wrong tool when:
- The business is the online shop. A hosted commerce platform may be simpler to run; our WordPress vs Wix vs Shopify comparison weighs this up.
- Signed-in users working with their own data is the point. Portals, quoting tools and complex booking rules are applications; see website or web app.
- Nobody will look after it. A simple site with no upkeep budget may be safer on a hosted builder that manages the software for you.
- Content must feed many channels, such as apps and in-store screens, where a headless CMS may fit better.
Still weighing platforms? See how to choose a CMS.
Frequently asked questions
How many plugins is too many for a WordPress site?
There’s no fixed limit. Twenty well-maintained plugins with distinct jobs can be lighter and safer than eight poorly built ones. A better test is whether someone can explain why each plugin is installed and who keeps it updated.
Are page builders bad for WordPress?
No, but they need discipline. Set up with global styles, templates and only the modules you use, a builder can be fast and easy to edit. The real trade-off is lock-in: leaving one usually means rebuilding the pages made with it.
Can a badly built WordPress site be fixed without a rebuild?
Often, in part. Removing duplicate plugins, moving custom code into a plugin, adding staging and tidying user roles all work on an existing site. Replacing hand-styled layouts or moving content into proper content types usually means rebuilding the affected templates.
What to do next
Put the six practices to any proposal before you commission a site, or to the dashboard you log into today; a developer who builds this way will answer each without jargon. For more to ask, see questions to ask before hiring a web designer.
Planning a new site? Our website design and development service builds on WordPress this way, with editor training and the domain, hosting and full admin access in your name. Worried the site you run now is the fragile kind? Start with a free website audit. It needs only your web address, and slow pages and security gaps are often the first visible symptoms of the problems above.