Getting Started

Creating a Staging Environment

By the Domain India teamPublished 10 min read
Knowledge base article
Contents (10 sections)

A staging site is a private copy of your website where you try updates, new plugins, design changes and code before your visitors see them. If something breaks on staging, nothing breaks for your customers. This guide shows three ways to build one on Domain India shared hosting, how to keep it private, and how to move your changes to the live site without losing orders or comments.

Key takeaways

On cPanel hosting, the quickest route for WordPress is WP Toolkit › Clone to a subdomain such as staging.yourdomain.in. On DirectAdmin and Webuzo, look for the clone or staging option under Installations in Softaculous. For any other site, copy the files to a subdomain, copy the database into a new one, and point the copy's config file at the new database. Always password-protect staging, keep it out of search engines, and take a backup before you push anything to the live site.

1. What a staging site is for

Use staging whenever a change could break the site:

  • WordPress core, theme and plugin updates, especially major versions;
  • a new plugin, theme or page builder;
  • a PHP version change;
  • custom code, .htaccess rules and redirects;
  • a redesign you want to show a client before it goes live.

A staging copy is not a backup. Keep backups separately, and delete the staging copy when you no longer need it: it uses your plan's disk space, database and file limits like any other site.

2. Choose a method

MethodBest forPanelsEffort
WP Toolkit CloneWordPress on cPanelcPanelA few clicks
Softaculous clone or stagingWordPress and other Softaculous appscPanel, DirectAdmin, WebuzoA few clicks
Manual copy to a subdomainAny PHP site, custom apps, full controlAll15 to 30 minutes

Use a subdomain (staging.yourdomain.in) rather than a folder inside your live site where you can. A subdomain keeps staging's files, cookies and rewrite rules apart from the live site, and gets its own free SSL certificate once it resolves. Subdomains, addon domains and folders are compared in parked, addon and subdomains.

3. WordPress on cPanel: WP Toolkit

cPanel hosting includes WP Toolkit, which can clone a site and later copy changes back.

  1. Create the subdomain.
    In cPanel, open Domains and create staging.yourdomain.in.
  2. Clone the site.
    Open WP Toolkit, find your live site and choose Clone. Pick the new subdomain as the target. WP Toolkit copies the files and the database and updates the site address in the copy.
  3. Hide it.
    In the copy's WordPress dashboard, go to Settings › Reading and tick Discourage search engines. Then password-protect it (section 5).
  4. Test.
    Make your updates and changes on staging and check every important page, form and checkout.
  5. Copy back.
    When you are happy, use Copy Data in WP Toolkit to send the changes to the live site. Take a backup of the live site first.

The full WP Toolkit guide is in WP Toolkit compared with Softaculous.

4. DirectAdmin and Webuzo: Softaculous

WP Toolkit is not available on DirectAdmin or Webuzo. The DirectAdmin and Webuzo plans list Softaculous Premium, which adds clone and staging options for installations made with Softaculous:

  1. Open Softaculous in your control panel and go to Installations.
  2. Find your site and look for the clone or staging option next to it.
  3. Choose the subdomain as the destination and let Softaculous copy the files and database.

The exact options depend on your panel and on whether the site was installed through Softaculous. If you don't see a clone or staging option, use the manual method below or ask support.

5. The manual method: any website

This works for WordPress, Laravel, a plain PHP site or anything else.

  1. Create a subdomain
    in your control panel and note its document root (the folder the panel shows for it).
  2. Copy the files.
    In the File Manager, compress the live site's folder, copy the archive into the subdomain's folder and extract it there. Leave out the staging folder itself if it sits inside the live folder.
  3. Create an empty database and user
    for staging, with a new password. Never point staging at the live database.
  4. Copy the database.
    Export the live database from phpMyAdmin and import it into the staging database. The phpMyAdmin import limit on our cPanel servers is 50 MB; for bigger databases, use SSH (below).
  5. Point the copy at the new database.
    Edit the config file in the staging folder: wp-config.php for WordPress (DB_NAME, DB_USER, DB_PASSWORD), .env for Laravel.
  6. Change the site address.
    WordPress stores its address in the database. Replace the live address with the staging address using a search-and-replace tool that understands serialized data (WP-CLI or a search-replace plugin), never a plain SQL REPLACE.
  7. Test the login and a few pages,
    then protect the site.

If jailed SSH is enabled on your account, steps 2 to 6 are faster from the command line. Jailed SSH is available on every shared hosting plan; it is off by default, so ask support to enable it. Tools in the jail vary; tar, mysqldump and WP-CLI are present on our cPanel servers:

bash
# Pack the live site, leaving out the staging folder, and unpack the copy
cd ~/public_html
tar --exclude='./staging' -czf ~/site-copy.tar.gz .
tar -xzf ~/site-copy.tar.gz -C ~/public_html/staging

# Export the live database (you are asked for the database user's password)
mysqldump -u live_user -p live_db > ~/live.sql

# After importing live.sql into the staging database, change the address
cd ~/public_html/staging
wp search-replace 'https://yourdomain.in' 'https://staging.yourdomain.in' --all-tables

Replace the paths and names with your own; the subdomain's real folder is the one your panel showed in step 1. Delete site-copy.tar.gz and live.sql from your home folder when you are done: they contain your whole site and database. SSH setup is covered in enabling and accessing jailed SSH.

Tell WordPress it is a staging site

Add define( 'WP_ENVIRONMENT_TYPE', 'staging' ); to the staging wp-config.php. Many plugins read it and switch off things that should only happen on the live site, such as payment gateways in live mode or outgoing marketing mail. For Laravel, set APP_ENV=staging in the staging .env.

6. Keep staging private

A public staging site can be indexed by Google as duplicate content, and it shows your unfinished work to anyone who finds it.

  • Password-protect the whole subdomain. In cPanel, use Files › Directory Privacy on the staging folder; DirectAdmin and Webuzo have a password-protected directories feature. See password-protecting directories.
  • Tell search engines to stay away. Tick Discourage search engines in WordPress, or add a robots.txt with Disallow: /. The password is what really keeps it out; robots.txt is only a request.
  • Stop real email and payments. Switch payment gateways to test mode and turn off order and newsletter emails, so staging never charges or mails a real customer.
  • Use HTTPS. Free SSL covers the subdomain once it points to your hosting.

7. Move changes to the live site safely

The live site keeps changing while you test: new orders, comments, sign-ups and form entries go into the live database. If you copy the whole staging database over it, those are lost.

Never overwrite a live shop's database

For a WooCommerce shop or any site that takes orders, bookings or registrations, don't push the staging database to live. Push files only (themes, plugins, code), then repeat any settings changes on the live site by hand.

A safe order of work:

  1. Back up the live site (files and database) and download the copy.
  2. Push files, not data, where you can: the updated theme, plugins or code. WP Toolkit's Copy Data lets you choose what to copy.
  3. Repeat settings changes made in the dashboard on the live site.
  4. Check the live site straight away: home page, login, forms, checkout.
  5. If something breaks, restore the backup you took in step 1.

On cPanel, the nginx cache in front of the site can show an old page for a while after a change. Add ?t= and any text to the address, for example https://yourdomain.in/?t=1, to see the current version.

8. Custom apps and developers

For a Laravel or other framework app, use a separate folder, database and .env, with APP_DEBUG=false if staging is reachable from the internet. A staging branch deployed to the staging subdomain keeps both copies in step; see deploy with Git. Composer can't run on shared hosting, so build with vendor/ locally or in CI and upload it.

9. Where Domain India fits

All three Domain India shared hosting panels let you run a staging copy on a subdomain of your own domain:

  • cPanel hosting includes WP Toolkit with Clone and Copy Data, plus Softaculous.
  • DirectAdmin and Webuzo hosting include Softaculous for app installs, with clone options where available.
  • Staging copies count towards your plan's disk space, database and file limits, so choose a plan with room for two copies of your site.

Compare plans on cPanel hosting, DirectAdmin hosting and Webuzo hosting. For cPanel and DirectAdmin hosting, JetBackup keeps weekly account backups you can restore from the panel; see backup and restore with JetBackup. Take your own backup before every push as well.

Frequently asked questions

What is a staging site?

A staging site is a private copy of your website, usually on a subdomain such as staging.yourdomain.in, where you test updates, plugins, design changes and code before applying them to the live site.

How do I create a WordPress staging site on cPanel?

Create a subdomain in cPanel under Domains, then open WP Toolkit, choose Clone on your live site and select the subdomain as the target. WP Toolkit copies the files and database and updates the address in the copy.

Can I create a staging site on DirectAdmin or Webuzo hosting?

Yes. Use the clone or staging option under Installations in Softaculous, if your site was installed with Softaculous. Otherwise copy the files to a subdomain and copy the database into a new one by hand.

Should staging use the same database as the live site?

No. Always give staging its own database and database user. A staging site connected to the live database changes live data every time you test.

How do I stop Google indexing my staging site?

Password-protect the staging folder or subdomain with Directory Privacy or your panel's password-protected directories feature, and tick Discourage search engines in WordPress. The password is what reliably keeps it out.

Can I copy the staging database back over the live site?

Not on a site that takes orders, comments or sign-ups, because everything added to the live site since the copy was made would be lost. Push files only and repeat settings changes on the live site, after taking a backup.

Ready to test safely? Open your hosting services to reach your control panel, read WP Toolkit compared with Softaculous, or open a support ticket if you can't find the clone option on your plan.

Test changes before your visitors see them

cPanel hosting includes WP Toolkit with one-click cloning to a staging subdomain, Softaculous and free SSL for every subdomain.

See cPanel hosting

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Create a Staging Site (WordPress & PHP) | Domain India