−25%

on annual Windows plans, until 31 Oct. See plans

EQVPS

How to install WordPress on a VPS (Nginx, PHP, MariaDB)

A clean WordPress install on Ubuntu 24.04 with Nginx, PHP-FPM, MariaDB and free HTTPS — plus the settings that matter for speed and security.

Managed WordPress hosting charges per site and hides the knobs. On your own VPS you get the whole server, as many sites as it can hold, and full control over PHP and caching. The classic stack — Nginx, PHP-FPM, MariaDB — installs in about fifteen minutes on Ubuntu 24.04.

Before you start: you need a plan with a dedicated IP (visitors connect to ports 80/443; NAT plans don't accept inbound web traffic) and a domain whose A record points at the server. Micro-IP at $10/month is a comfortable home for a normal site.

1. Install the stack

apt update
apt install -y nginx mariadb-server php8.3-fpm php8.3-mysql php8.3-curl \
  php8.3-gd php8.3-intl php8.3-mbstring php8.3-xml php8.3-zip

2. Create the database

MariaDB on Ubuntu lets root in through the local socket, no password needed:

mariadb <<'SQL'
CREATE DATABASE wordpress DEFAULT CHARACTER SET utf8mb4;
CREATE USER 'wp'@'localhost' IDENTIFIED BY 'use-a-long-random-password';
GRANT ALL PRIVILEGES ON wordpress.* TO 'wp'@'localhost';
FLUSH PRIVILEGES;
SQL

3. Download WordPress

cd /tmp && curl -O https://wordpress.org/latest.tar.gz
tar xzf latest.tar.gz
mv wordpress /var/www/example.com
chown -R www-data:www-data /var/www/example.com

4. Configure Nginx

cat > /etc/nginx/sites-available/example.com <<'EOF'
server {
    listen 80;
    server_name example.com www.example.com;
    root /var/www/example.com;
    index index.php;
    client_max_body_size 64M;

    location / {
        try_files $uri $uri/ /index.php?$args;
    }

    location ~ \.php$ {
        include snippets/fastcgi-php.conf;
        fastcgi_pass unix:/run/php/php8.3-fpm.sock;
    }

    location ~ /\.(?!well-known) { deny all; }
}
EOF

ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/
rm -f /etc/nginx/sites-enabled/default
nginx -t && systemctl reload nginx

The try_files line is what makes pretty permalinks work — the Nginx equivalent of WordPress's .htaccess rules.

Raise PHP's upload limit to match client_max_body_size:

sed -i 's/^upload_max_filesize.*/upload_max_filesize = 64M/; s/^post_max_size.*/post_max_size = 64M/' /etc/php/8.3/fpm/php.ini
systemctl restart php8.3-fpm

5. Free HTTPS

apt install -y certbot python3-certbot-nginx
certbot --nginx -d example.com -d www.example.com

Certbot edits the Nginx config for HTTPS and sets up automatic renewal.

6. Finish in the browser

Open https://example.com, enter the database name (wordpress), user (wp) and password from step 2, and create your admin account. Pick an admin username that isn't "admin".

Keep it fast and safe

FAQ

Which plan do I need for WordPress?

A normal site runs well on Micro-IP (2 GB RAM, $10/mo). Nano-IP (1 GB) works for a small site if you add a swap file. You need a plan with a dedicated IP, because visitors connect to ports 80 and 443 — NAT plans don't accept inbound web traffic.

Nginx or Apache for WordPress?

Either works. Nginx with PHP-FPM uses less memory under load, which matters on small servers. The one thing you lose is .htaccess — Nginx rules go into the server block instead, and for standard WordPress permalinks that's a single line.

How do I get HTTPS?

Point your domain's A record at the server, then run certbot with the Nginx plugin. It fetches a free Let's Encrypt certificate, edits the config and renews automatically every few months.

How do I back up WordPress?

You need two things: the database (mysqldump) and the wp-content folder. Managed Backups copy the whole server daily, and a plugin or a cron job with mysqldump gives you file-level copies you can move elsewhere.

Is a self-hosted WordPress secure?

As secure as you keep it. Turn on automatic updates for WordPress core and plugins you trust, delete plugins you don't use, use strong admin passwords, and keep the server itself patched with unattended-upgrades.

Comments

No comments yet. Be the first.

Leave a comment

Comments are moderated before they appear.