A staging site is a private copy of your live site where you can break things safely. Update a plugin, change PHP version, try a new theme, and if the copy survives, do the same on the real site with some confidence. Some hosts provide one-click staging through a WordPress management tool or an installer; if yours does, use it. The manual method below works everywhere and shows what those tools do.
1. Create the subdomain
In cPanel, open Domains and create a new one, for example staging.yourdomain.com. Untick the option to share the document root with the main domain, so the copy gets its own folder. Then open SSL/TLS Status and run AutoSSL so the new name has a certificate.
2. Copy the files
In File Manager, select everything in the live site's folder, choose Copy, and give the staging folder as the destination. For a large site, compress the live folder to a zip first, move the zip, and extract it; that is much faster than copying thousands of small files.
3. Copy the database
- In phpMyAdmin, select the live database and use Export to download it.
- With MySQL Database Wizard, create a new database and a new user with a new password, and give that user all privileges on it.
- Back in phpMyAdmin, select the new database and Import the file.
Use a separate database user for staging. If the copy is ever compromised or misconfigured, it then has no way to touch live data.
4. Point the copy at its own database and address
Edit the configuration file in the staging folder and enter the new database name, user and password. For WordPress that file is wp-config.php.
WordPress also stores its own address in the database, so the copy will keep sending you to the live site until that is changed. If WP-CLI is available in cPanel's Terminal, run this from the staging folder:
wp search-replace 'https://yourdomain.com' 'https://staging.yourdomain.com' --all-tables
Without a terminal, a search-and-replace plugin does the same job. Do not edit the exported database file with a plain find-and-replace in a text editor; WordPress stores some settings in a format that records the length of each piece of text, and changing the text by hand corrupts them.
5. Lock it down
- Put a password on the staging folder with cPanel's Directory Privacy.
- Tell search engines to stay out: in WordPress, tick Discourage search engines under Settings > Reading.
- Stop it sending email. A copy of your site will happily email real subscribers. Disable or redirect outgoing mail on staging.
- Remove or disable ad and analytics code on the copy, so test visits are not counted.
6. Moving changes to live
This is the part that needs care. Pushing files from staging to live, such as a theme or plugin you changed, is straightforward: back up live, then copy the changed folders across.
Pushing the database is different. Since you made the copy, the live site has gained new posts, comments, orders or sign-ups. Overwriting the live database with the staging one throws those away. For most changes, the safer route is to repeat the settings change by hand on the live site once it has been proven on staging.
Keeping staging useful
A staging copy drifts out of date. Refresh it from live before each round of testing, by repeating steps 2 to 4, so you are testing against what visitors actually see. Delete it when a project ends; an abandoned copy with old software is a security risk with your name on it.
Common questions
Can I use a subfolder instead of a subdomain?
You can, for example yourdomain.com/staging/, and it saves creating a DNS name and a certificate. The subdomain is cleaner: it keeps the copy's files out of the live site's folder, so a rule in the live .htaccess does not leak into the copy, and a careless delete cannot take both.
Will Google index the staging copy as duplicate content?
Not if it is password protected, because crawlers cannot read it. The "discourage search engines" setting is a second layer, not a replacement for the password.
Why does the staging copy keep sending me to the live site?
The address stored in the database was not changed, or a cached redirect is in the way. Run the search-and-replace in step 4 again, clear any cache plugin on the copy, and test in a private window.
Do licences for paid plugins work on staging?
It depends on the vendor. Many allow a staging address alongside the live one; some count it as a second site. Check before activating, so the live licence is not deactivated by surprise.