Hosting plans are often compared by storage, visitor estimates, and labels such as shared, cloud, managed, or VPS. Those labels do not tell a client who will notice a failed backup at 2 a.m., install a security update, or restore the site after a bad plugin release.
Start with a responsibility budget: the work the owner or team can reliably perform every month. A small brochure site with no technical staff may need more provider management than a busy publication run by an experienced operations team. The first site can be the better candidate for managed hosting even if it receives fewer visitors.
Write the workload in plain language
Use a normal busy day, not a launch-day guess. Record the platform, business function, busiest expected period, and anything that cannot be unavailable. Examples:
- A five-page service site with a contact form and occasional updates.
- A WordPress publication with new images every day and several editors.
- A store where checkout, inventory sync, and transactional email matter.
- A client portal containing personal or confidential information.
- A campaign page expecting a short traffic spike after an advertisement.
Then list the moving parts: content management system, database, email delivery, file storage, scheduled jobs, payment integrations, and external services. “Ten thousand visits” is not enough information. Ten thousand cached article views and ten thousand searches against a large product catalogue can create very different loads.
Build the responsibility map
For each job below, write one name: provider, client, developer, or shared. If the contract says “managed,” check what that word covers instead of assuming.
| Responsibility | Question to ask | Evidence to request |
|---|---|---|
| Server and platform updates | Who patches the operating system, runtime, and database? | Scope document and update policy |
| Application updates | Who updates WordPress core, plugins, themes, or the chosen app? | Maintenance terms and exclusions |
| Backups | What is copied, how often, and how long is it kept? | Backup schedule and restore procedure |
| Restore | Who can restore, how long should it take, and what does it cost? | Support procedure or test restore |
| Monitoring | Who receives alerts for downtime, disk space, or certificate failure? | Alert examples and escalation route |
| Security response | What happens after malware, account compromise, or abuse? | Incident and suspension policy |
| Migration | What is included when arriving or leaving? | Migration scope and export access |
A blank row is work no one has agreed to do. Price that work before comparing plans.
Match the operating model
Website builder or hosted platform: Useful when the owner values a bounded system and does not need server access. Confirm export options, custom-domain support, and what happens to forms, media, and store data when leaving.
Managed application hosting: Often a fit for a client who wants the provider to handle part of the platform, backups, caching, and support. Read the exclusions. “Managed WordPress” may still leave plugin compatibility, content, and third-party integrations with the owner.
General shared hosting: Can suit a simple site when the account has the required software, isolation, backups, and support. Resource limits matter more than the word “unlimited.” Ask what happens when CPU, memory, processes, or file counts exceed policy.
VPS or cloud server: Provides more control, but control creates work. Unless a management service is included, the buyer normally owns operating-system updates, firewall rules, monitoring, backups, and incident response. A low server price does not include the time needed to operate it safely.
The categories overlap and providers use them differently. Choose the responsibility map first, then find the plan that contractually covers it.
Check the software baseline
If the site will use WordPress, compare the host with WordPress’s current published requirements. As of September 2026, WordPress recommends PHP 8.3 or greater, MariaDB 10.11 or MySQL 8.0 or greater, and HTTPS. It also warns that older supported versions may have reached end of life. Requirements change, so recheck the official page when buying.
For any platform, ask the same practical questions: Is the required runtime version available? Can it be selected per site? How are updates handled? Can scheduled tasks run? Is outbound email restricted? Can the database and files be exported without opening a support ticket?
Test support with a real scenario
Do not ask only whether support is available “24/7.” Send a presales question that resembles an incident:
Our WordPress site shows a database connection error after an update. The last known good point is yesterday at 16:00 UTC. Which parts can you restore, who initiates it, what is the expected process, and is there a fee?
Judge the answer for scope and clarity, not just response speed. A quick reply that redirects every issue to the customer is still useful information.
Use the Hosting Fit Test
Before paying, require a clear “yes” for these five statements:
- The plan supports the application’s current technical requirements.
- Every recurring operational job has a named owner.
- The backup contains the files and data needed for a full restore.
- The team can reach the correct support path during an outage.
- The site and domain can leave without rebuilding from screenshots.
If a plan fails because the team lacks time or expertise, buy management rather than unused capacity. If it fails because exports or restores are unclear, keep looking. The next article turns the surviving options into a real 12-month cost, including the items hidden outside the promotional headline.
How we researched this guide
This framework uses WordPress’s current hosting requirements and general security practices to define questions buyers can verify. It does not benchmark providers or promise that a hosting category performs the same across companies. No affiliate links appear in this article.
