WordPress needs three things your plain HTML site did not: PHP to run its code, a database to hold your posts, and a few permissions set correctly. This takes about twenty minutes.
Do Set up your server so a browser can open your site first, so Apache is installed and ports 80 and 443 are open in both firewalls.
1. Install PHP and the database
sudo apt update
sudo apt install -y php php-mysql libapache2-mod-php mariadb-server
sudo systemctl enable --now mariadb
2. Create the database
sudo mysql
At the MariaDB [(none)]> prompt, type these four lines, one at a time. Replace choose-a-strong-password with a password you invent, and keep it: WordPress asks for it in step 4.
CREATE DATABASE wordpress;
CREATE USER 'wpuser'@'localhost' IDENTIFIED BY 'choose-a-strong-password';
GRANT ALL ON wordpress.* TO 'wpuser'@'localhost';
EXIT;
The database listens only on the server itself, which is what you want. Nothing about it is exposed to the internet.
3. Put WordPress in place
cd /tmp
curl -O https://wordpress.org/latest.tar.gz
tar xzf latest.tar.gz
sudo rm -rf /var/www/html/index.html
sudo cp -r wordpress/. /var/www/html/
sudo chown -R www-data:www-data /var/www/html
sudo find /var/www/html -type d -exec chmod 755 {} \;
sudo find /var/www/html -type f -exec chmod 644 {} \;
sudo systemctl restart apache2
The chown line matters: WordPress writes files when you install plugins or upload images, and it can only do that if the web server owns the folder.
4. Finish in the browser
Open your site (http://yourcompany.com, or the public IP if the domain is not ready). The WordPress wizard asks for:
- Database Name:
wordpress - Username:
wpuser - Password: the one you invented in step 2
- Database Host:
localhost - Table Prefix: leave as
wp_
Then it asks for your site title and an administrator account. Use a real email address, and a password a person cannot guess. This account can change everything on your site.
5. Turn on HTTPS straight away
A WordPress login over plain http sends the password across the internet in the clear. Do Turn on HTTPS now, before you write anything.
Keeping it safe
- Update WordPress, plugins and themes when it asks. Out-of-date plugins are the usual way these sites get broken into.
- Install only plugins you actually need, from wordpress.org.
- Take a snapshot of the server before big changes: Back up your data.
- Never edit files as
rootover FileZilla. Upload into/var/www/htmland keep the ownership above.
Common problems
- "Error establishing a database connection": the password in step 4 does not match step 2. Run
sudo nano /var/www/html/wp-config.phpand checkDB_PASSWORD. - A blank white page: PHP is missing or failed. Run
sudo apt install -y php libapache2-mod-php && sudo systemctl restart apache2. - WordPress asks for FTP details when installing a plugin: the ownership in step 3 was not applied. Run the
chownline again.