home / blog / how-to-start-a-wordpress-website-for-your-business-or-personal-blog

Standing Up a WordPress Site in 2026: My Default Stack

The domain, droplet, DNS, and email setup I use whenever a client says they want a WordPress site. With the specific gotchas (Cloudflare origin certs, MX records, wp-config hardening) that catch people on their first time through.

How to Start a WordPress Website for Your Business or Personal Blog

WordPress runs about 43% of websites and is what most clients land on when they want something they can edit themselves later without paying a developer for every change. The stack I default to in 2026 is boring on purpose: Namecheap for the domain, DigitalOcean Marketplace 1-Click for hosting, Cloudflare in front, Google Workspace for email. Total monthly cost is ~$6–$12 for the infra and around $7/user/month for Workspace.

The stack at a glance

LayerWhat I useCost
Domain registrarNamecheap~$10–$15/year
HostingDigitalOcean WordPress 1-Click$6/month basic droplet
DNS + CDN + edge securityCloudflare (free tier is plenty)$0
EmailGoogle Workspace~$7/user/month
TLSLet’s Encrypt (or Cloudflare origin cert)$0

1. Buy the domain at Namecheap

Search at namecheap.com for the .com you want. Buy it. Turn on WhoisGuard. It’s free and keeps your address out of the public WHOIS database. Don’t buy the email or SSL upsells. You don’t need them.

2. Spin up the DigitalOcean WordPress 1-Click

In the DigitalOcean console, create a new Droplet, choose “Marketplace,” search for WordPress. Pick the smallest plan ($6/month, 1 GB RAM). That runs a small business site easily.

The Marketplace image installs WordPress, MySQL, nginx, and a Let’s Encrypt helper for you. On first login (via the web console or SSH) the included script asks for your domain and email and finishes the setup automatically. The “follow the on-screen instructions” bit is genuinely the whole install.

3. Point the domain through Cloudflare

Sign up for a free Cloudflare account, add your domain. Cloudflare gives you two nameservers; paste them into Namecheap’s “Custom DNS” field on the domain. Propagation takes a few minutes to a few hours.

Then in Cloudflare DNS, add an A record pointing your domain to the Droplet’s public IP, orange-clouded (proxied). That’s when CDN + DDoS protection kick in.

The Cloudflare + Let’s Encrypt gotcha

Once Cloudflare is in proxied (orange-cloud) mode, the Let’s Encrypt cert issuance on your server can fail because Cloudflare intercepts the HTTP-01 challenge. Either issue the cert before orange-clouding, or use a Cloudflare Origin Certificate instead. Free, valid 15 years, generated in Cloudflare’s dashboard. Drop it in /etc/ssl/cloudflare/ and point nginx at it. Set Cloudflare SSL mode to “Full (strict).”

4. Email through Google Workspace

Sign up for Workspace at workspace.google.com. The wizard asks you to verify domain ownership (TXT record in Cloudflare) and gives you the MX records to add.

Workspace MX records, the ones you’ll add to Cloudflare:

MX  @  smtp.google.com.  Priority 1

(They used to require 5 MX records; the single-host setup has been the default since 2023.)

5. Lock down the WordPress side

Inside /wp-admin:

  • Rename the default admin user (or create a new admin and delete the old one).
  • Install Wordfence Security. The free tier blocks the obvious brute-force traffic.
  • Install UpdraftPlus or use a server-level backup. Nightly DB + uploads to DigitalOcean Spaces is what I default to.
  • Enable auto-updates for plugins.
  • Don’t install Jetpack. It’s become political post-2024 and most of its features are duplicated by simpler plugins.

6. The starter plugin set

  • Yoast SEO. Meta tags, sitemap, social previews. Most of the real SEO work is content, but this gets the plumbing right.
  • Akismet. Spam comments. Free for personal use.
  • Wordfence. Security as above.
  • WooCommerce. Only if you’re actually selling. Otherwise it’s overhead.
  • UpdraftPlus. Backups, unless you’re backing up at the server level.

The stuff most tutorials skip

  • Disable file editing in WP admin. Add define('DISALLOW_FILE_EDIT', true); to wp-config.php. If an admin account gets compromised, the attacker can’t inject PHP through the Plugin Editor.
  • Move the login URL. WPS Hide Login or similar. Stops 99% of brute-force traffic against /wp-login.php.
  • Set up server-level backups. DigitalOcean’s weekly backups are $1.20/month per Droplet and restore the whole VM in minutes.

That’s the whole thing. Once the DNS, TLS, and email are wired up, the site itself takes about 15 minutes. Most of the time on a real engagement goes into the theme, content, and forms. Not the plumbing.

If you want me to do the build, drop me a line.

← Back to all posts Reply to this post →