Vetting a WordPress hosting partner means testing the claims on the sales page before you move a single client site onto it. Uptime, TTFB, support response, backup restores, developer access and exit terms can all be verified in an afternoon, and most of them can be checked before you pay anything. This guide gives your agency an 11-point check, what each one proves, and the answer that should make you walk away.
This page is about verification. If you are earlier than that and still deciding what kind of host an agency needs at all, and what a client portfolio costs to run, read our guide to WordPress hosting for agencies first, then come back and run these checks on your shortlist. If you want a shortlist to run them against, see our comparison of the best WordPress hosting providers for agencies.
Key takeaways
- Run every check on a real trial site, not on the feature table. Feature tables agree with each other; trial sites do not.
- Test developer access (SSH, WP-CLI, Git) on the cheapest plan you would actually put a client site on, not the top tier used in the marketing.
- Time a support reply yourself, at an awkward hour, with a question that needs a WordPress answer rather than a copy-paste one.
- Restore a backup before you trust the backups. A backup you have never restored is an untested assumption.
- Ask what leaving costs. Migration in is usually free everywhere; migration out is where the surprises live.
- Score each host out of 11 and keep the sheet. The same test works at renewal.
Table of Contents
The 11-Point Check for a WordPress Hosting Partner
Every check below has the same three parts: what it is, why it matters to an agency rather than to a single site owner, and how to verify it yourself. Most take a few minutes. Run them on a trial or sandbox site on each host you are seriously considering, including the host you are already on, because the incumbent should have to pass the same test.
1. WordPress expertise: test it, do not trust it
Every host says it specializes in WordPress. What you are testing is whether the people answering the phone know WordPress, or know a control panel. The difference shows up the first time a client site breaks after a plugin update, when you need a diagnosis rather than a link to a help article.
How to check it: open a pre-sales chat and ask something only a WordPress host can answer in one reply. Good questions: which PHP versions can I run, and can different sites run different versions? Do you run a server-level page cache, and can I purge it from WP-CLI? Is there an object cache, and on which plans? A WordPress host answers all three immediately. A generic host escalates or sends you a doc.
Walk away if: the answer to “can I change the PHP version myself” is “raise a ticket and we will do it for you”.
2. White-label terms for agencies
If you want clients to see your brand rather than your host’s, you are buying white-label terms, not just hosting. That means your logo in the client dashboard, your domain on the login, and invoices that do not mention a third party. Some hosts include this, some sell it as an add-on, and some price it per workspace, which quietly changes your margin on every client.
If you intend to bill hosting as your own line item, you are effectively selling Website as a Service, and your host has to allow it. With WaaS, an agency offers hosting, maintenance and support as one branded product while the platform stays invisible behind it.
How to check it: ask three questions in writing. Is white-label included or an add-on, and at what price? Do client-facing emails and invoices carry my brand? Is there a platform or workspace fee on top of per-site cost? Then read the answers against the pricing page, because this is the area where the two most often disagree.
3. What “managed” actually covers
“Managed” is not a defined term. On one host it means the server is patched and nothing else. On another it means core, plugin and theme updates are applied, tested against a staging copy, and rolled back automatically if the site errors. Both are advertised with the same word, and the gap between them is several hours of your team’s time per client per month.
How to check it: ask for the list. Who applies WordPress core updates, and on what schedule? Are plugin and theme updates included or mine to run? If an update breaks a client site at 2am, who reverts it, and how fast? Is there a staging site on every plan, or only on the expensive ones? An integrated migration tool matters here too, because moving a site between environments should not be a manual export.
4. TTFB and uptime: measure, do not read
Time To First Byte is how long the server takes to start responding, and it is the part of page speed the host actually controls. Uptime is the percentage of time the site answers at all. Both are published as marketing numbers by every host, and both are measurable by you in about ten minutes, which makes this the easiest claim on the list to verify.
How to check it: spin up a trial or sandbox site on the host, install the same theme and plugin stack a typical client site runs, and measure TTFB from two or three regions your clients’ visitors actually come from. Test twice: once warm, once after a cache purge, because a cached homepage tells you very little. Google’s guidance on Time to First Byte is a good reference for what a healthy number looks like. Then find the host’s public status page and read the last 90 days of incidents rather than the uptime percentage on the sales page.
Walk away if: there is no public status page, or the incident history is empty for a year.
Learn how to reduce TTFB in WordPress →
5. Performance: included or an add-on
Edge caching, a CDN, image optimization and an object cache are the four things that make a WordPress site fast without touching the code. The question is never whether a host has them. It is which of them are included on the plan you are actually going to buy, and which arrive as a separate monthly line.
How to check it: take the cheapest plan you would put a live client site on and write down, from the pricing table, whether it includes a CDN and how much bandwidth, whether an object cache is available on that tier, and whether image optimization is included or billed. Then add the add-ons back to the headline price. That is the real per-site cost, and it is the number to compare across hosts.
6. Support: test it before you need it
You will contact support more than a single site owner ever does, because you are responsible for dozens of sites and every one of them can break. Response time matters, but the thing you are really testing is whether the first reply moves the problem forward or just acknowledges it.
How to check it: open a ticket during your trial, at an awkward hour for the host’s timezone, describing a real symptom rather than asking a sales question. Something like “this site returns a 502 for logged-in users only” is ideal. Time the first human reply, and judge whether it asked a diagnostic question or sent a template. Do this twice on different days before you commit a client portfolio to the answer.
7. Security: ask who cleans up
Security features are easy to list and hard to compare. The question that separates hosts is not which acronyms they support, it is what happens after a client site is compromised, and whether cleaning it up is included or billed to you at an hourly rate you will not be able to pass on.
- A Web Application Firewall (WAF) that filters out harmful traffic.
- Real-time failover ensures continuous uptime by automatically switching to backup servers in the event of a server failure.
- Additionally, regular backups provide an extra layer of protection, allowing you to restore data quickly in case of emergencies.
How to check it: ask whether the WAF is on by default or something you enable, whether malware scanning is included on your tier, and whether a hacked-site cleanup is free. Then verify the backups rather than the backup policy: create a test post, take or wait for a backup, delete the post, and restore. If restoring takes a support ticket, that is your real recovery time during an incident.
8. Staging: one per site, or a paid extra
A staging environment is a copy of a client site where you test a core update, a plugin change or a redesign against real data before visitors see it. For an agency the question is not whether staging exists, it is whether every site can have one at a price you can absorb across a whole portfolio.
How to check it: create a staging copy during the trial and push a change back to production. Watch what happens to the database. Does the push overwrite the live database, which is dangerous on any site that takes orders or form entries, or can you sync selectively? Ask what a staging site costs per month, because “included” sometimes means one per account rather than one per site.
9. Developer access: check it on the cheapest plan
This is the check agencies most often get wrong, because developer tooling is usually demonstrated on the top tier and then quietly restricted on the cheap tiers where most client sites actually live. Test it where your sites will be.
- SSH access, which allows developers to securely access server resources and execute commands remotely.
- Git integration enables version control, facilitating collaborative development and tracking changes to website code.
- WP-CLI support streamlines administrative tasks by allowing developers to manage WordPress installations via a command-line interface.
- Sandbox for testing website changes before implementing them on the live site, ensuring a smooth and error-free development process.
- Dummy content generation so a developer can populate a test site quickly instead of hand-writing content.
How to check it: on the lowest paid tier, SSH in and run wp core version. If that works, try a deployment from a Git branch. Two commands tell you more about whether a host fits your workflow than any feature page will.
10. Pricing mechanics: per site or per server
Two billing models dominate. Per-server hosting sells you a box and lets you pack client sites onto it. Per-site hosting prices each site on its own. Per-server looks cheaper until one client’s traffic spike degrades every other site on the box, and it makes rebilling a single client awkward. Per-site costs more at the very small end and is far easier to attribute and resell.
How to check it: ask the four mechanical questions that decide your monthly bill. Is there a minimum term or annual prepay? If I upgrade a site mid-month, is the change prorated? If I delete a site on the 3rd, do I pay for the month? Can different sites sit on different tiers under one account? A host that answers all four cleanly is a host whose invoice you can predict.
11. Servers actually tuned for WordPress
A server tuned for WordPress runs a current PHP version, has sensible database settings, keeps a server-level cache in front of the site, and does not impose limits that WordPress routinely trips over. Generic servers run WordPress; tuned servers run it without you tuning anything.
How to check it: install a diagnostic plugin such as Site Health, already in WordPress core under Tools, and read what it flags on a fresh install. Check the PHP version offered by default, whether the memory limit is high enough for a builder-based site, and whether cron is run by the system rather than by page visits. Site Health complaining on a brand new install is a signal about the host, not about your site.
The Check Most Agencies Skip: How You Leave
Almost every host will migrate sites in for free, because that is the sale. Very few make it equally easy to take them out again, and an agency is more exposed to this than anyone, because leaving means moving a whole portfolio rather than one site.
Ask before you sign, and get the answers in writing:
- Can I download a full backup of a site, files and database, without opening a ticket?
- Is there a charge for migrating a site off the platform?
- What happens to a client’s site if I close the account, and how much notice do I get?
- Who holds the domain and the DNS, me or the host?
- Are there proprietary plugins that have to stay installed for the site to work elsewhere?
The last one catches people out. If a host’s caching or security layer is a plugin that only functions on their infrastructure, a migrated site does not simply work somewhere else, it has to be rebuilt around whatever replaces it.
How InstaWP Answers These Checks
It would be strange to publish a test and dodge it, so here is how InstaWP hosting answers the same questions, including the ones that are not flattering.

| Check | How InstaWP answers it |
|---|---|
| Developer access on the cheapest plan | SSH, SFTP and WP-CLI are on every tier, including the $2 sandbox, not gated behind a higher plan. |
| Staging per site | A $2 sandbox acts as the dev or staging box for a site and converts to production in one click, with no migration step. |
| Backups | Automatic off-site backups with one-click restore: weekly on Starter, daily from Plus upward, monthly on a sandbox. |
| Security | InstaShield, a managed WAF, is on every site. Bot protection, DDoS mitigation and vulnerability scans come in from the Plus tier. |
| Performance included | InstaCDN is bundled on every production tier, premium edge from Plus upward. Object cache from Plus, image optimization from Pro. |
| Pricing mechanics | Per site, billed daily, invoiced monthly. Tier changes prorate from that day. No annual contract or minimum. |
| White-label | White-label is available in the pay-per-use model with no workspace fee, so you pay for the sites you sell. A branded domain for client sites is a paid extra. |
| The exit | Migrating in is free and zero-downtime. Migrating a site off the platform is the one migration InstaWP charges for, which is worth knowing before you commit a portfolio. |
The pattern behind those answers is that the developer tooling is not tiered. An agency’s cheapest client site gets the same shell, the same CLI and the same sandbox-to-production path as its busiest one, which is what makes a portfolio manageable from one dashboard rather than from six.
Run the test on us
Spin up a site, SSH in, restore a backup, and time our support. That is checks 1, 6, 7 and 9 in about twenty minutes.
Score the Shortlist, Then Move One Site
Take two or three hosts, run the eleven checks plus the exit questions, and score each out of eleven. The winner is rarely the one with the longest feature list. It is usually the one whose support answered like a WordPress developer and whose cheapest plan still gave you a shell.
Then move one site, not the portfolio. Pick a low-risk client site, run it for a full billing cycle, and watch what the invoice and the support queue actually look like in normal operation. A portfolio migration is a decision you make after the evidence, not to get it.
FAQs on Vetting a WordPress Hosting Partner
What is a WordPress hosting partner, and how is it different from a host?
A WordPress hosting partner is a host you build your agency’s delivery process on top of, rather than one you resell at arm’s length. In practice that means per-site billing you can attribute to a client, a staging environment on every site, one dashboard for the whole portfolio, developer access such as SSH and WP-CLI, and white-label options if clients are meant to see your brand. The underlying servers are often similar to consumer plans. The management layer and the commercial terms are what make it a partner rather than a supplier.
How do I test a WordPress host before moving client sites?
Spin up a trial or sandbox site and run five checks in under an hour. Measure TTFB warm and after a cache purge from the regions your clients’ visitors are in. SSH in on the cheapest paid tier and run a WP-CLI command. Create a staging copy and push a change back, watching what happens to the database. Delete a test post and restore it from a backup. Open a support ticket at an awkward hour with a real symptom and time the first human reply. Those five results predict day-to-day life on the host better than any feature comparison.
What questions should an agency ask a hosting provider before signing?
Ask what managed covers and who reverts a broken update, whether white-label is included or an add-on and whether there is a workspace fee, which performance features are bundled on the tier you will actually buy, whether a hacked-site cleanup is billed, whether staging is per site or per account, whether tier changes prorate, and what it costs to migrate a site off the platform. Get the white-label and exit answers in writing, because those are the two that most often differ from the pricing page.
Is a cheap host a false economy for an agency?
It is when the savings move work onto your team. A plan without staging, automatic backups, a managed firewall or shell access does not remove those jobs, it just makes them yours, and agency hours cost far more per client than the price gap between tiers. The honest comparison is the plan price plus the add-ons you would have to buy plus the hours your team would spend. Judged that way, the cheapest line on a pricing page is often the most expensive option on the shortlist.
How often should an agency re-run this check on its current host?
Once a year, and immediately after any incident that cost you client trust. Hosts change: plans get re-tiered, features move behind higher plans, support teams grow or get outsourced, and the company may be acquired. Re-running the same eleven checks on your incumbent takes an afternoon and either confirms the relationship or gives you the evidence to renegotiate before renewal.
Should every client site be on the same host?
For most agencies, yes, because the operational gain comes from one dashboard, one invoice, one support relationship and one update routine. Split portfolios multiply every recurring task. The exception is a client with a genuine constraint, such as a compliance requirement, a fixed region, or an existing contract you inherited. Keep those as deliberate exceptions with a documented reason, not as a portfolio that drifted across four hosts because nobody consolidated it.