WP-CLI is the official command-line tool for WordPress. With it you can update plugins, back up the database, change your site's address, reset a password or rescue a broken site in seconds -- even when the WordPress dashboard won't load. WP-CLI is already installed on Instant Access Internet Services servers. This guide shows you how to manage WordPress from the command line with WP-CLI, with ready-to-use commands for the jobs site owners do most.
Why use WP-CLI?
- It works when wp-admin doesn't. A plugin that crashes your dashboard can be switched off from the command line.
- It's fast. Updating twenty plugins is one command, not twenty clicks.
- It handles WordPress data properly. Changing a domain with
wp search-replaceis safe; doing it with a text editor on a database export often breaks widgets and theme settings. - It can be scheduled. Any WP-CLI command can run as a cron job.
If you prefer point-and-click, WP Toolkit in cPanel (Domains > WordPress Management) does many of the same jobs. WP-CLI is for when you want speed, precision, or a way in when nothing else works.
Getting started
- Open a command line: in cPanel go to Advanced > Terminal, or connect with SSH from your computer using your cPanel username.
- Go to the folder where WordPress is installed. For most sites that's:
If WordPress is in a subfolder or a subdomain,cd ~/public_htmlcdinto that folder instead. You'll know you're in the right place whenlsshowswp-config.php. - Check WP-CLI can see your site:
You should see your WordPress version number. If you see an error instead, check the troubleshooting section below.wp core version
Run wp --info to see the WP-CLI version and the PHP version it's using. Every command has built-in help: wp help plugin, wp help plugin update and so on.
You can also run commands from anywhere by adding --path:
wp plugin list --path=/home/username/public_html
Back up before you change anything
Make a quick database export first. It takes seconds and gives you an instant way back:
wp db export ~/db-before-changes.sql
This saves the file in your home directory, outside public_html, so it can't be downloaded from the web. To restore it later:
wp db import ~/db-before-changes.sql
Delete old exports when you're finished with them -- they use disk space. For a full backup of files and database, WP Toolkit's backup or JetBackup 5 are the right tools.
Updating WordPress, plugins and themes
| Command | What it does |
|---|---|
wp core check-update | Shows whether a WordPress update is available. |
wp core update | Updates WordPress itself. |
wp core update-db | Runs any database update after a core update (the "Database update required" step). |
wp plugin list | Lists plugins with their status, version and whether an update is available. |
wp plugin update --all --dry-run | Shows which plugins would be updated, without changing anything. |
wp plugin update --all | Updates every plugin. |
wp plugin update woocommerce | Updates one plugin (use the name from the list's first column). |
wp theme update --all | Updates every theme. |
After updating, open your site in a private window and check the homepage, a form and (for stores) the checkout. Premium plugins that update through their own licence system may not update this way; update those from the dashboard.
Rescuing a broken site
If a plugin or theme update has crashed your site ("There has been a critical error on this website" or a white screen), WP-CLI can switch it off even though wp-admin is unreachable.
- Try listing plugins while skipping all plugin and theme code, so the broken one can't crash WP-CLI too:
wp plugin list --skip-plugins --skip-themes - Deactivate the one you suspect (often the one you just updated):
wp plugin deactivate plugin-name --skip-plugins --skip-themes - If you're not sure which one, deactivate them all, then reactivate one at a time and reload the site after each:
wp plugin deactivate --all --skip-plugins --skip-themes wp plugin activate plugin-name - If the theme is the problem, switch to a default theme (install it first if needed):
wp theme list --skip-plugins --skip-themes wp theme activate twentytwentyfive --skip-plugins --skip-themes
The site's error_log file usually names the file that failed, which tells you which plugin or theme to start with: tail -n 30 ~/public_html/error_log.
Installing and removing plugins and themes
wp plugin install litespeed-cache --activate
wp plugin delete hello
wp theme install twentytwentyfive
wp theme delete twentytwentythree
Use the plugin's "slug" -- the last part of its address on wordpress.org, for example wordpress.org/plugins/litespeed-cache/ becomes litespeed-cache. Only install from wordpress.org or the developer's own site. Never install "nulled" premium plugins from download sites; they're a common source of malware.
Managing users
| Command | What it does |
|---|---|
wp user list --role=administrator | Lists every administrator. Check for accounts you don't recognize. |
wp user create pat pat@example.com --role=editor | Creates a user and prints a random password. |
wp user update pat --user_pass="New-Long-Passphrase-2026" | Sets a new password for a user. |
wp user reset-password pat --show-password | Sets a new random password and shows it on screen. Without --show-password, the user is emailed a notice and can choose their own with "Lost your password?". |
wp user delete olduser --reassign=1 | Deletes a user and gives their posts to user ID 1. |
Setting a password on the command line saves it in your shell history. Afterwards, run history -c to clear it -- or use wp user reset-password --show-password instead, which never puts the password in your history.
Changing your site's address (search and replace)
WordPress stores its full address throughout the database -- in settings, post content and plugin data. When you switch from http:// to https://, move from a staging subdomain, or change domains, wp search-replace updates every copy safely, including data WordPress stores in "serialized" format that a plain text edit would corrupt.
- Back up the database:
wp db export ~/before-search-replace.sql - Do a dry run to see how many changes would be made:
wp search-replace 'http://example.com' 'https://example.com' --skip-columns=guid --dry-run - If the numbers look sensible, run it for real by removing
--dry-run:wp search-replace 'http://example.com' 'https://example.com' --skip-columns=guid - Clear caches:
wp cache flush, and purge LiteSpeed Cache if you use it (below).
Leave off trailing slashes, and be specific: replacing example.com on its own could also change shop.example.com or email addresses. To check the two main address settings:
wp option get siteurl
wp option get home
Caches, maintenance mode and other housekeeping
| Command | What it does |
|---|---|
wp litespeed-purge all | Purges the whole LiteSpeed Cache (when the LiteSpeed Cache plugin is active). |
wp cache flush | Clears WordPress's object cache. |
wp rewrite flush | Rebuilds permalinks -- the fix when every page except the homepage shows a 404. |
wp transient delete --expired | Clears out expired temporary data from the database. |
wp maintenance-mode activate | Shows visitors a "briefly unavailable" message. Use deactivate to turn it off and status to check. |
wp db size --tables | Shows the size of each database table, to find what's making the database large. |
wp db optimize | Optimizes the database tables. |
wp cron event list | Shows scheduled WordPress tasks and when they'll next run. |
Checking for tampered files
WP-CLI can compare your files against the official copies on wordpress.org:
wp core verify-checksums
wp plugin verify-checksums --all
"Success" means the files match. Warnings about files that "should not exist" or "doesn't verify against checksum" in core folders are a red flag, especially after a hack. Premium plugins that aren't on wordpress.org can't be checked this way. If you find modified core files, see the hacked-site guides below before deleting anything.
Running WP-CLI from a cron job
Cron jobs need full paths. Find WP-CLI's location with which wp, then use it in Advanced > Cron Jobs. For example, to run WordPress's scheduled tasks every 15 minutes:
cd /home/username/public_html && /path/from/which/wp cron event run --due-now --quiet
If you do this, you can stop WordPress running cron on page visits by adding define( 'DISABLE_WP_CRON', true ); to wp-config.php, above the line that says "That's all, stop editing!".
Troubleshooting
"Error: This does not seem to be a WordPress installation."
You're in the wrong folder. Run pwd and ls; go to the folder containing wp-config.php, or add --path=.
"Error establishing a database connection"
WP-CLI reads the database details from wp-config.php, just like your site. If both fail, the database name, user or password in that file is wrong, or the user isn't assigned to the database. See the database connection guide below.
A PHP fatal error appears instead of the result
A plugin or theme is crashing as WordPress loads. Add --skip-plugins --skip-themes and try again, then deactivate the culprit as shown above.
WP-CLI shows a different PHP version from my site
The command line and your website can use different PHP versions. That's normally fine for WP-CLI. If a command fails because of it, open a ticket and tell us which command and PHP version you need.
"wp: command not found"
Open a ticket -- WP-CLI should be available on every account with shell access.
Common questions
Is WP-CLI safe to use?
It's the official tool, but it does exactly what you tell it, with no "Are you sure?" on most commands. Export the database first and use --dry-run where it's offered.
Will WP-CLI changes show in WP Toolkit?
Yes. Both work on the same WordPress files and database. WP Toolkit may take a moment to refresh its view.
Can I use WP-CLI on a staging copy?
Yes -- cd into the staging site's folder first, or use --path. Always double-check which folder you're in before running updates or search-replace.
Related guides
- How to Use SSH, SSH Keys and Terminal in cPanel
- WordPress "Critical Error on This Website": How to Fix It
- How to Fix "Error Establishing a Database Connection" in WordPress
- How to Reset Your WordPress Admin Password
- How to Set Up a Cron Job in cPanel
- What to Do If Your WordPress Site Is Hacked
Still stuck? Open a support ticket and the Instant Access Internet Services team will help.
