← All sessionsHomeSearch
LWP Elementor Pro Mastery·7 - Extra tips and tricks (+ 8 - Ending notes, folded in)·40:53

Section 7+8: Speed, Security, and Fleet Management — plus the Course Close

Reno Instructor — the operations chapter: the 9-point site-speed list, the layered security doctrine (hosting-first, plugin-second, triple backups), ManageWP as the fleet dashboard with scheduled updates and billable client reports — then the course close: the design→build→sell learning path, practice economics, and the certificate

Session map

THE PASSESTHE STANDING LAYERTHE EXITThe 9-point speed listeverything already taught, viewed throu…Security lives at the hosting…Three backup layers, because…ManageWP as the fleet layerlogins, scheduled updates, resellable r…The closedesign → build → sell, and the economic…
The passesThe standing layerThe exit
click a node — its card pops up (drag it anywhere, × to close)
Concept

The map reads left to right — the passes flow into the standing layer, then into the exit. Click any node to open that idea here; every timestamp jumps into the recording.

The short version

  1. Speed is a 9-point checklist, not a mystery: Hello theme, cloud hosting, fewer plugins, local fonts, compressed images (<500KB, <2560px wide), global styling, dynamic content everywhere, lazy-load backgrounds (tested), ONE host-matched optimizer plugin — and his sites 'almost always hit 90 plus.'
  2. The security revelation came from Hostinger's own people: 'security should be done on a hosting level, not on a plugin level. If you're trying to solve things with a plugin, then the hosting has already failed' — his two hacked client sites were both on obscure hosts, both WITH security plugins.
  3. Backups run triple-layered: host dailies (30-day windows are too short — hacks surface months late), a plugin pushing to your own cloud (UpdraftPlus → Dropbox/Drive), and ManageWP's free monthlies — 'maybe you think I'm going overboard... I just wanna be safe.'
  4. ManageWP is the fleet dashboard: passwordless logins, Monday-3AM scheduled plugin updates, $1/month uptime monitoring (doubling as a sales argument), and automated client reports you can resell as maintenance packages.
  5. Free security plugins only — paid ones now price above their worth ('the security should be done on a hosting level'); dead plugins (unupdated ~a year) are a risk class; SSL is table stakes; reCAPTCHA keys go in Elementor's integrations tab.
  6. The close prescribes the learning path — design first, then build, then sell — and the practice economics: rebuild admired sites on subdomains BEFORE selling, because unpracticed client work 'wastes more time inside of the projects... then you're talking about real money.'

The concepts

01

The 9-point speed list: everything already taught, viewed through the speed lens

Almost nothing in the speed episode is new — that's the point. The course's habits (Hello theme, few plugins, local fonts, sized images, global styles, dynamic content) WERE the speed strategy all along.

The list, with the speed-specific additions: (1) Hello theme — 'an empty theme... at least doesn't slow down your website'; (2) good hosting, preferably CLOUD tier (Hostinger's affordable, SiteGround's premium) — 'don't be cheap when it comes to hosting'; (3) fewer plugins — with his own confession: livingwithpixels.com runs THREE CPT systems (CPT UI + ACF + JetEngine) from years of accretion and needs a rebuild; (4) local fonts; (5) images under 500KB and under 2560px wide (WordPress errors above it); (6) styling global via site settings; (7) dynamic content everywhere — 'any content that appears in 2 places... shouldn't be saved 2 times on the server'; (8) lazy-load background images (the features toggle) — tested per site, off if animations stutter; (9) ONE optimizer plugin, matched to the host (Speed Optimizer on SiteGround, LiteSpeed Cache on LiteSpeed hosts) — stacking optimizers 'will become messy,' and some 'cheat with the Google SiteSpeed results.'

The honest framing seals it: he doesn't know how optimizers work internally and says so — the checklist is validated by outcomes (90+ PageSpeed, ~1-1.5s loads), not theory.

Worked example · from the session

The living-with-pixels self-audit: three CPT plugins doing one job, named as his own anti-pattern to rebuild — the fewer-plugins rule applied to its own author.

Why it matters

Speed is rankings (Google demotes slow sites) plus UX — and the list proves it's a byproduct of discipline, not a specialist skill.

People get this wrong

Speed optimization is a post-build specialist pass.

It's the course's standing habits plus three additions (lazy-load, optimizer choice, hosting tier) — mostly decided before the first page is built.

Don't be cheap when it comes to hosting.
How this exactly works, I have no idea, to be honest... But what I do know is that my websites almost always hit, like, 90 plus on the Google page speed test.
For your projects

["The 90+ PageSpeed evidence standard maps to your site-health-audit's performance checks."]

Go deeper

In one line: Speed protocol: Hello theme · cloud hosting · minimal plugins · local fonts · images <500KB and <2560px · global styling · dynamic content over duplication · lazy-load backgrounds (tested) · one host-matched optimizer. Target evidence: 90+ PageSpeed, ~1-1.5s loads.

Image ceilings: 2560px width (WordPress error threshold) and 500KB weight (l1425264 06:03)

Optimizer rules: one only; host-matched beats famous; some plugins game the metrics (l1425264 08:04)

Lazy-load caveat: 'if your images start acting weird, then I do not recommend to use this' (l1425264 08:04)

Affiliate disclosure made openly: commission on the Hostinger/SiteGround links (l1425264 04:02)

His stack humility: 'I'm also just a no code developer' — outcome-validated, not theory-validated (l1425264 10:04)

Try it now

Run PageSpeed on your slowest site and walk the 9 points as a diff — nearly every red flag maps to one of them.

▶ Watch this taught:

Check yourself

Answer from memory first — the recall attempt is what makes it stick. Then reveal.

Why does the list warn against stacking optimizer plugins?

They mostly do the same work; overlapping rewrites make 'your code become messy' — and a second optimizer adds risk, not speed.

02

Security lives at the hosting layer; plugins are the complement

Both of his hacked client sites HAD security plugins. What they didn't have was real hosting — 'if you're trying to solve things with a plugin, then the hosting has already failed.'

The doctrine, learned from Hostinger's own team and confirmed by his two client hacks (both on obscure hosts; both fixed only after moving hosts): the hosting layer (server firewalls, exploit patching) does the real security work. The plugin layer is complementary and FREE — SiteGround's Security Optimizer (free for everyone) or Solid Security's free tier (formerly iThemes; the pro tier now 'more expensive than Elementor Pro' and not worth it). The remaining points: SSL always (host-provided, or Really Simple SSL + Let's Encrypt) — non-negotiable for shops; the renamed login URL (ASE, from chapter 4); updates current everywhere, because updates ARE the patch channel; no plugins unupdated for ~a year ('there is a security risk'); per-site passwords in a real manager (1Password); reCAPTCHA keys from Google wired into Elementor's integrations tab for forms.

And the recovery path when prevention fails: Fiverr specialists who fix hacked WordPress for a living (~$100 fixed his) — cheaper than the rebuild, faster than learning incident response mid-crisis.

Worked example · from the session

The two-hack story arc: obscure hosts + security plugins → hacked twice, weird Google results, angry clients → Fiverr fix (~$100) → clients moved to real hosts → 'since then, I did not have any problems.'

Why it matters

Layer confusion wastes money in both directions: paying for plugin tiers that can't compensate for weak hosting, or trusting good hosting and skipping the cheap complements.

People get this wrong

A good security plugin secures a WordPress site.

The HOST secures the site; the plugin hardens the edges. Spending on plugin tiers while hosting is weak buys the wrong layer.

Security should be done on a hosting level, not on a plugin level. If you're trying to solve things with a plugin, then the hosting has already failed.
For your projects

['Direct kin to your security-change-procedure skill: verify at the layer that owns the control.']

Go deeper

In one line: Security stack: real hosting (firewall + exploit patching) as the foundation; free-tier security plugin as complement; SSL always; renamed login URL; current updates; no ~year-stale plugins; password manager; reCAPTCHA on forms via Elementor integrations. Recovery: WordPress hack-fix specialists (Fiverr, ~$100).

The source is the industry itself: 'I talked to people from Hostinger, and they said... security should be done on a hosting level' (l1425265 00:00)

Paid security plugins deprecated in his stack: 'I do not recommend to pay for security plugins anymore' (l1425265 04:02)

Stale-plugin heuristic: 3 months fine, ~a year is a risk flag — check 'last updated' before installing (l1425265 08:05)

WordPress's openness is the exposure: many vendors, uneven update discipline, 'holes for hackers' (l1425265 00:00)

The hack fix market exists — 'people who just do this for a living' — budget line, not shame (l1425265 00:00)

Try it now

For each site you manage: name the host's firewall/patching story. If you can't, that — not a plugin — is the gap.

▶ Watch this taught:

Check yourself

Answer from memory first — the recall attempt is what makes it stick. Then reveal.

Why did the security plugins fail his hacked clients?

They were operating above a broken foundation — the obscure hosts lacked the firewall/patch layer, and no plugin can retrofit that.

03

Three backup layers, because hacks surface late

Host dailies keep 30 copies. A hack you notice in month three is therefore unrecoverable — from that layer.

The design driver is DISCOVERY LAG: 'sometimes a hack is not really visible and you find out... after a few months.' So three layers with different reaches: (1) the host's dailies (SiteGround: 30 copies; Hostinger: daily-for-7-days then weekly-for-7-weeks) — deep enough for oops, not for stealth hacks; (2) a plugin pushing OFFSITE to your own cloud — UpdraftPlus → Dropbox/Drive — 'the most safe way because then you are sure that you have it,' reaching back months; (3) ManageWP's free monthlies — with the known failure mode that a compromised site can disconnect from ManageWP, taking dashboard access to those backups with it. Cloud storage costs a few GB/month across client sites; that's the whole price of the third nine.

Worked example · from the session

The ManageWP failure mode: 'when there's a problem on your website, sometimes Manage WP disconnects and then... this whole window is not accessible anymore' — the third layer's own dependency, named honestly.

Why it matters

Each layer fails differently (retention, access, automation) — the trio covers the three failure axes for effectively no money.

People get this wrong

The host does backups, so backups are handled.

The host does SHORT backups; the discovery-lag scenario needs an offsite copy you own, months deep.

Three backup layers, because hacks surface late Hosting backups the base layer Plugin backups offsite copies Manual exports before big changes ManageWP fleet logins · updates · reports Security lives at the hosting layer; the fleet layer turns maintenance into a resellable service
Three backup layers plus the fleet layer, because hacks surface late
Maybe you think I'm going overboard with this because I have 3 layers of backups, but I just wanna be safe.
For your projects

["Feeds directly into your backup-verification skill: his three layers still need restore drills, which he notably never mentions — a genuine gap in the course's doctrine."]

Go deeper

In one line: Backup doctrine: host dailies (short retention) + plugin-to-own-cloud (UpdraftPlus → Dropbox/Drive; months of reach) + ManageWP free monthlies (with its disconnect caveat). Driver: hack-discovery lag exceeds host retention windows.

Retention math: 30 host copies < months of discovery lag — the gap layer 2 exists for (l1425265 06:04)

Own-cloud ownership: the copy YOU hold is the one no platform outage or disconnect can take (l1425265 06:04)

'Maybe you think I'm going overboard with this because I have 3 layers of backups, but I just wanna be safe' (l1425265 08:05)

Backups don't prevent or fix hacks — they price the worst case (l1425265 06:04)

Try it now

Check the retention window on your host's backups. If it's ≤30 days, the stealth-hack scenario currently has no answer.

▶ Watch this taught:

Check yourself

Answer from memory first — the recall attempt is what makes it stick. Then reveal.

Why is ManageWP alone insufficient as the offsite layer?

Its access rides the site's health — a hacked site can disconnect from ManageWP, locking the dashboard (and its backups) exactly when needed.

04

ManageWP as the fleet layer: logins, scheduled updates, resellable reports

Clients host everywhere; hosts each have their own dashboard. ManageWP is the one list where every site lives — and its $1 add-ons become maintenance revenue.

The full setup, promised since chapter 4: ManageWP Worker plugin on each site, connected by CONNECTION KEY (never credentials), one dashboard for every site regardless of host. The features he actually uses: passwordless one-click logins (guarded by the renamed login URLs — and the account itself deserves your best password, since it opens EVERYTHING); scheduled plugin updates — Monday 3AM, 'when you are sleeping beautifully' — with core updates optional-but-riskier and a monthly manual check regardless ('you're giving the power here to an automatic tool'); the free monthly backups (layer three of the triple); uptime monitoring at ~$1/month — deployed selectively on clients with weak hosting, then USED AS SALES EVIDENCE ('hey. Look. Your website went down again. Do you not wanna update now?'); and client reports — automated monthly PDFs (updates + backups + analytics) that become a billable maintenance line: 'you can ask extra money for this... some clients would love to pay that.'

Multi-account hygiene closes it: separate accounts (test sites vs client sites) bridged by the switch-account feature via collaborate.

Worked example · from the session

The Monday-3AM schedule set live, then the uptime-monitor-as-sales-argument: the downtime numbers shown to the client as the case for moving to his hosting.

Why it matters

Fleet tooling converts per-site maintenance chores into one dashboard's worth of scheduled automation — and two of its features convert directly into recurring revenue.

People get this wrong

Site maintenance is unbillable overhead.

Packaged (reports + uptime + updates), it's a maintenance product with ~$1 marginal cost — the chapter prices it out loud.

Every Monday, for example, at 3 AM in the night... all of the plugins will be updated automatically... which is when you are sleeping beautifully.
For your projects

["The uptime-evidence-as-sales-argument move is a general pattern: instrument first, then let the client's own numbers make the case."]

Go deeper

In one line: Fleet layer: ManageWP Worker per site via connection keys; one dashboard for cross-host logins; scheduled updates (Mon 3AM; core optional; monthly manual check); free monthly backups; ~$1 uptime monitoring as selective diagnostic + sales evidence; automated client reports resold as maintenance packages; separate accounts per estate with switch-account.

Connection keys not credentials — the s04/s05 pattern completed with full setup (l1425267 02:00)

The one concentrated risk, named: 'only if people would hack my Manage WP account, then they would have access to all of my websites' — best password in the vault (l1425267 00:00)

Scheduled updates ≠ abdication: 'nothing is waterproof, so I still recommend to check your clients' websites every month' (l1425267 04:01)

The report + uptime features are BUSINESS features wearing ops clothes — priced examples given ($5-10/mo markup on a $1 cost) (l1425267 06:01)

It's free — the paid tiers (daily backups per-site) explicitly skipped in his setup (l1425267 04:01)

Try it now

Count the dashboards you'd need to log into to update every site you touch. If it's more than one, this layer is missing.

▶ Watch this taught:

Check yourself

Answer from memory first — the recall attempt is what makes it stick. Then reveal.

Why does he still do monthly manual checks with automation on?

Scheduled updates are power handed to a tool — better than not updating, but automation failures are silent, so a human pass bounds the damage window.

05

The close: design → build → sell, and the economics of practice

The course's last lesson isn't technical — it's sequencing: 'you first learn how to design, then you learn how to build. And after that... you learn how to sell.'

The outro sets the learning path and its economics. The PATH: this course taught build; design (theory + Figma, 'mainly focused on process' — tool mechanics are free on YouTube, designer THINKING isn't) and business/selling are the flanking courses (waitlists live at recording). The PRACTICE ECONOMICS: before selling, rebuild — old projects or admired sites, on subdomains, into the portfolio — because 'if you don't practice websites enough and you start already selling to clients, then you will probably waste more time inside of the projects... then you're talking about real money.' Practice wastes only your time; unpracticed client work wastes money and reputation.

Two housekeeping notes complete the record: his YouTube deliberately teaches the SIMPLE versions ('I'm not gonna use all the techniques... the whole site settings, the clamps, the padding, the classes' — course-only depth, stated openly as the content strategy); and the certificate lands on completion — positioned honestly ('I am very biased') with the agency-hiring anecdote: many working Elementor professionals 'don't even know all the features I've discussed.'

Worked example · from the session

The rebuild prescription: pick a site you admire, rebuild it on a subdomain, portfolio it — design skill optional, build skill compounding.

Why it matters

The sequencing claim is the course's final judgment: skill order determines whether early client money costs more than it pays.

People get this wrong

Finish the course, start charging.

Finish the course, rehearse on subdomains until the method runs without the videos — THEN charge. The tuition of practice is your own time; the tuition of premature clients is money and reputation.

You first learn how to design, then you learn how to build. And after that, the last step is that you learn how to sell.
If you're just doing some test projects here and there, then you're not wasting any time for your clients. You're just wasting your own time, which is not that bad because things take time to learn.
For your projects

['His free-YouTube-vs-paid-course depth split is a working example of the content-tiering question that recurs in your own course-site and SEO projects.']

Go deeper

In one line: Course close: learning path design → build → sell (companion courses waitlisted); practice-before-selling via subdomain rebuilds of admired sites; YouTube = simplified versions by declared strategy, the course = the full system; certificate on completion; review requested via Google Form with photo for marketing.

The design course merges tool and process because process 'is not easy to find on YouTube' — the paywall line drawn openly (l1425269 00:01)

Practice economics verbatim: test projects waste 'your own time, which is not that bad because things take time to learn' (l1425269 02:01)

The certificate's real evidence: agency staff who know less than course completers — positioned with declared bias (l1425271 00:00)

Review pipeline: Google Form, private-feedback lane, photo for the social-proof wall (l1425270 00:00)

Live-demo honesty to the last: 'for some reason, my Internet is not working... Oh, now it starts loading' (l1425269 02:01)

Try it now

Price your last learning-on-the-job mistake in hours. That's the argument for the subdomain rehearsal.

▶ Watch this taught:

Check yourself

Answer from memory first — the recall attempt is what makes it stick. Then reveal.

Why does the design course precede business in his sequence?

Selling amplifies whatever skill exists — selling unpracticed work converts skill gaps into client-facing, paid-for failures. Skill first makes the selling compound instead of expose.

Every concept, three clicks deep

The same concepts as a quick reference: the closed row is the glance, open is the study card, and every timestamp jumps into the recording.

01The 9-point speed list: everything already taught, viewed through the speed lensSpeed protocol: Hello theme · cloud hosting · minimal plugins · local fonts · images <500KB and <2560px · g…

Speed protocol: Hello theme · cloud hosting · minimal plugins · local fonts · images <500KB and <2560px · global styling · dynamic content over duplication · lazy-load backgrounds (tested) · one host-matched optimizer. Target evidence: 90+ PageSpeed, ~1-1.5s loads.

Image ceilings: 2560px width (WordPress error threshold) and 500KB weight (l1425264 06:03)

Optimizer rules: one only; host-matched beats famous; some plugins game the metrics (l1425264 08:04)

Lazy-load caveat: 'if your images start acting weird, then I do not recommend to use this' (l1425264 08:04)

Affiliate disclosure made openly: commission on the Hostinger/SiteGround links (l1425264 04:02)

His stack humility: 'I'm also just a no code developer' — outcome-validated, not theory-validated (l1425264 10:04)

02Security lives at the hosting layer; plugins are the complementSecurity stack: real hosting (firewall + exploit patching) as the foundation;

Security stack: real hosting (firewall + exploit patching) as the foundation; free-tier security plugin as complement; SSL always; renamed login URL; current updates; no ~year-stale plugins; password manager; reCAPTCHA on forms via Elementor integrations. Recovery: WordPress hack-fix specialists (Fiverr, ~$100).

The source is the industry itself: 'I talked to people from Hostinger, and they said... security should be done on a hosting level' (l1425265 00:00)

Paid security plugins deprecated in his stack: 'I do not recommend to pay for security plugins anymore' (l1425265 04:02)

Stale-plugin heuristic: 3 months fine, ~a year is a risk flag — check 'last updated' before installing (l1425265 08:05)

WordPress's openness is the exposure: many vendors, uneven update discipline, 'holes for hackers' (l1425265 00:00)

The hack fix market exists — 'people who just do this for a living' — budget line, not shame (l1425265 00:00)

03Three backup layers, because hacks surface lateBackup doctrine: host dailies (short retention) + plugin-to-own-cloud (UpdraftPlus → Dropbox/Drive;

Backup doctrine: host dailies (short retention) + plugin-to-own-cloud (UpdraftPlus → Dropbox/Drive; months of reach) + ManageWP free monthlies (with its disconnect caveat). Driver: hack-discovery lag exceeds host retention windows.

Retention math: 30 host copies < months of discovery lag — the gap layer 2 exists for (l1425265 06:04)

Own-cloud ownership: the copy YOU hold is the one no platform outage or disconnect can take (l1425265 06:04)

'Maybe you think I'm going overboard with this because I have 3 layers of backups, but I just wanna be safe' (l1425265 08:05)

Backups don't prevent or fix hacks — they price the worst case (l1425265 06:04)

04ManageWP as the fleet layer: logins, scheduled updates, resellable reportsFleet layer: ManageWP Worker per site via connection keys;

Fleet layer: ManageWP Worker per site via connection keys; one dashboard for cross-host logins; scheduled updates (Mon 3AM; core optional; monthly manual check); free monthly backups; ~$1 uptime monitoring as selective diagnostic + sales evidence; automated client reports resold as maintenance packages; separate accounts per estate with switch-account.

Connection keys not credentials — the s04/s05 pattern completed with full setup (l1425267 02:00)

The one concentrated risk, named: 'only if people would hack my Manage WP account, then they would have access to all of my websites' — best password in the vault (l1425267 00:00)

Scheduled updates ≠ abdication: 'nothing is waterproof, so I still recommend to check your clients' websites every month' (l1425267 04:01)

The report + uptime features are BUSINESS features wearing ops clothes — priced examples given ($5-10/mo markup on a $1 cost) (l1425267 06:01)

It's free — the paid tiers (daily backups per-site) explicitly skipped in his setup (l1425267 04:01)

05The close: design → build → sell, and the economics of practiceCourse close: learning path design → build → sell (companion courses waitlisted);

Course close: learning path design → build → sell (companion courses waitlisted); practice-before-selling via subdomain rebuilds of admired sites; YouTube = simplified versions by declared strategy, the course = the full system; certificate on completion; review requested via Google Form with photo for marketing.

The design course merges tool and process because process 'is not easy to find on YouTube' — the paywall line drawn openly (l1425269 00:01)

Practice economics verbatim: test projects waste 'your own time, which is not that bad because things take time to learn' (l1425269 02:01)

The certificate's real evidence: agency staff who know less than course completers — positioned with declared bias (l1425271 00:00)

Review pipeline: Google Form, private-feedback lane, photo for the social-proof wall (l1425270 00:00)

Live-demo honesty to the last: 'for some reason, my Internet is not working... Oh, now it starts loading' (l1425269 02:01)

Tools referenced

ToolCoverageMomentContext
ElementordemonstratedreCAPTCHA integration tab; lazy-load feature toggle; features screen
WordPressdemonstratedPlugin audit, last-updated checks, the three-CPT-plugin confession
Hostinger / SiteGrounddemonstratedCloud tiers, backup retention windows, security documentation, optimizer plugins — the chapter's spine
ACF (Advanced Custom Fields)mentionedOne of the three overlapping CPT systems on his own site; contender in the open rebuild decision

Session materials

Archived locally on V: — click to open. Companion pages link to the LMS.

Action items

Resources mentioned

Resources
  • docSite speed tips page (the 9-point list, with links) — new page on his site, added to the course resources page
  • docSecurity tips page (companion list incl. the reCAPTCHA tutorial link)
  • docSoftware recommendations page — hosting links (affiliate, disclosed) + periodic discount codes
  • docPlugin references: Speed Optimizer (SiteGround), LiteSpeed Cache, Security Optimizer, Solid Security, Really Simple SSL, UpdraftPlus, ManageWP Worker
  • docCourse review Google Form (public review + private feedback + photo)
  • docCompanion course waitlists: Figma/design course + business course (discount promised to alumni)

Extraction notes

This page was built from an auto-generated transcript, which garbles product and people's names. Those were corrected silently in everything above and logged here for transparency. The warnings flag claims that were true on the recording day but change fast.

Transcript corrections applied

The transcript saysThe trainer actually means
Synchron Cloud HostingSiteGround cloud hosting
empty team / your teamempty theme / your theme
repos websiteWordPress website
iTeams / ifhemesiThemes (now Solid Security)
Google SiteSpeed / page speed test websitesGoogle PageSpeed Insights
Living 1 Pixel's / living 1 pixels / Living on PixelsLiving With Pixels (his brand)
Managee WP / Manage WPManageWP
hosting a promiseHostinger promises
backed (website will be backed)backed up
few page featuresfew paid features
certificates (plural, course completion)certificate
set the name Manage WPsaid the name ManageWP
25602560px (the WordPress big-image threshold)

True on recording day — verify before relying