How to manage 100 WordPress websites
without five dashboards and a spreadsheet.
A repeatable operating system for a growing client portfolio — inventory, ownership, access, updates, backups, monitoring and client reporting. Built for agency owners, growing agencies, freelance developers and operations leads managing multiple client WordPress sites.
Last reviewed 17 August 2026 by the Stack2 team — we run our own agency hosting operation the same way.
The tools that worked at 10 sites actively hurt you at 50.
No single source of truth
Ten clients means five host dashboards. Fifty clients means you've genuinely lost track of which sites exist, who owns them, and which plan they're on — until a client asks and you have to go looking.
Manual minutes compound
Fifteen minutes of manual update-checking per site is nothing at 10 sites. At 100 sites it's 25 hours a month — over three full working days, every month, before any actual client work starts.
Risk hides in the gaps
The sites that go three months without a check are rarely the ones you're worried about — they're the ones nobody's looking at. An outage or a compromised plugin surfaces as a client phone call, not a dashboard alert.
Margin erodes quietly
Every hour spent on manual admin is an hour not billed to a project. Care plans priced without accounting for real delivery time look profitable on paper and lose money in practice.
None of this is a headcount problem. It's a systems problem — and it's fixable with seven specific systems, not more hours in the day.
The seven systems every managed portfolio needs.
Score your own portfolio against these seven right now — the gaps are usually obvious once they're named.
1. Inventory
A single list of every site you're responsible for, with host, domain owner, PHP version and status — not spread across memory and old emails.
2. Ownership
Every site has one named internal owner and a documented service tier. "The team" isn't an owner — a specific person is.
3. Access
Credentials stored centrally, not in a spreadsheet or a shared note, with a clean way to revoke access when someone leaves.
4. Updates
Core, plugin and theme updates applied on a schedule you control — not "whenever someone remembers" or "when the client complains".
5. Backups
Automated backups before every change, with a tested restore path — a backup nobody has ever restored from is a hope, not a system.
6. Monitoring
Uptime and error alerts that reach a person, not a dashboard nobody opens — so you find out before the client does.
7. Client reporting
Evidence of the work delivered, sent on a schedule — the difference between a care plan clients renew and one they quietly cancel.
Missing two or three of these is normal at 15 sites. Missing them at 60 is where margin and reputation start leaking. The rest of this guide builds out each one.
Portfolio tiers: not every site needs the same attention
Treating every client site identically is the single biggest cause of wasted hours in a growing portfolio. A three-tier model matches effort to actual risk and revenue:
- Monitoring only — low-traffic, low-risk sites (a client's old brochure site, a project on hold). Uptime and vulnerability alerts, nothing else. Near-zero ongoing effort.
- Protect-level care — active client sites on a paid care plan. Scheduled updates, pre-change backups, uptime monitoring and an automated white-label report. This is where most of your portfolio should sit.
- Hands-on service — high-complexity or high-value sites (e-commerce, custom integrations, high traffic). Everything in Protect, plus a human reviewing changes before and after they go live.
Score every site into one of these three tiers before you touch tooling. It's the fastest way to see that most of your portfolio doesn't need — and shouldn't be billed for — hands-on attention.
Team roles and escalation paths
Once you're past a one-person operation, ambiguity about who handles what is where things start slipping. A minimal role structure that scales past 100 sites:
- Site owner — the named person accountable for a client relationship and its service tier. One owner per site, always.
- Maintenance operator — runs the weekly update cycle and handles routine exceptions (failed update, plugin conflict).
- Escalation lead — the person a maintenance operator hands a genuine incident to: a hacked site, extended downtime, or a client threatening to leave.
A one-line escalation rule removes most of the ambiguity: if a routine task turns into anything client-facing, unusual, or past 30 minutes of troubleshooting, it goes to the escalation lead — not back into the queue.
The weekly and monthly operating rhythm
A portfolio doesn't need daily attention on every site — it needs a predictable rhythm the whole team can run without being told:
| Cadence | What happens |
|---|---|
| Daily | Check for failed backups, downtime alerts and critical vulnerability notices only. Two minutes, every business day. |
| Weekly | Review pending updates, run scheduled updates for Protect-tier sites, handle rollback exceptions. |
| Monthly | Client reports go out, open tickets get reviewed, and every care plan gets a five-minute profitability check. |
| Quarterly | Access review, a real restore test on a sample of sites, PHP/plugin compatibility sweep, and a care-plan scope and price review. |
The capacity model: manual minutes vs. automated workflow
This is the number that actually determines how far one person can scale. Assumptions below: manual handling averages 45 minutes per site per month (updates, checks, ad hoc reporting, admin); an automated workflow — scheduled updates with an automated report — drops that to roughly 8 minutes per site per month for exception handling only.
| Portfolio size | Manual hours / month | Automated hours / month | Hours recovered |
|---|---|---|---|
| 15 sites | ~11.3 hrs | ~2 hrs | ~9.3 hrs |
| 50 sites | ~37.5 hrs | ~6.7 hrs | ~30.8 hrs |
| 100 sites | ~75 hrs | ~13.3 hrs | ~61.7 hrs |
Worked example only — label your own assumptions and adjust for your team's actual update cadence and site complexity. Not a guarantee of time saved; treat it as a planning estimate, not a customer outcome. Want your own numbers? Run them through the pricing calculator.
Migration plan: moving from scattered tools to one system
Don't attempt a big-bang cutover. Migrate in tiers, over two to four weeks depending on portfolio size:
- Week 1 — inventory first. Build the master list before changing any tooling. You can't migrate what you haven't counted.
- Week 1-2 — connect for visibility. Add sites to monitoring/inventory without changing update behaviour yet. This alone usually surfaces sites nobody remembered were live.
- Week 2-3 — migrate access. Move credentials out of spreadsheets and shared notes into a proper vault, tier by tier.
- Week 3-4 — turn on automation. Start with your lowest-risk tier, confirm updates and reports are working as expected, then extend to the rest of the portfolio.
How Stack2 maps to this operating system
Every system above corresponds to something live in the Stack2 Platform today:
- Inventory → Website inventory and sync, included free on every Core subscription.
- Ownership & access → Password vault and secure client collection links, with role-based team access.
- Updates & backups → AutoCare — scheduled core/plugin/theme updates with an automated backup before every change.
- Monitoring → Uptime monitoring and vulnerability checks across every connected site.
- Client reporting → Automated white-label reports emailed to the client after every update run — no manual screenshotting.
Connect your first sites and replace the manual inventory with a live dashboard.
Everything in the seven systems above — inventory, access, updates, backups, monitoring and reporting — running in one Australian dashboard, not five separate tools.
14 days free. No credit card required.
Keep going.
The WordPress Agency Maintenance SOP: Daily, Weekly, Monthly and Quarterly
A complete maintenance rhythm your whole team can follow — daily checks through quarterly reviews — plus an editable SOP pack with escalation fields.
The 30-Minute Client Website Portfolio Audit
Score ownership, access, maintenance, protection and risk across every client site to find the gaps before a client — or an incident — finds them for you.