A half-built website can create confusion long before it creates trust. If your team is still reviewing service details, staff information, intake instructions, or page design, learning how to make WordPress site private until launch gives you time to prepare carefully. For a healthcare or family-focused practice, that extra control helps ensure visitors see clear, accurate, welcoming information when the site is ready.
The right approach depends on who needs access during the build. A designer may need to share progress with your team, while the public and search engines should see nothing at all. WordPress offers a few ways to manage this, but they do not all provide the same level of privacy.
Start by deciding what “private” needs to mean
Before changing a setting, identify your launch-stage goal. If you simply want to prevent the public from seeing unfinished pages, a maintenance or coming-soon screen is usually enough. If you need to limit access to a small internal team, password protection or sitewide authentication may be more appropriate.
There is an important distinction here: hiding a page from search results is not the same as protecting it from visitors. Likewise, a password on one page does not secure every file or page on your site. Choose a method based on the information involved and the people who genuinely need access.
For a clinic website, avoid using a staging site or a public WordPress page to store client information, assessment records, forms containing protected health information, or other confidential documents. A website privacy setting is not a substitute for compliant clinical systems, secure storage, or your organization’s privacy procedures.
Use a maintenance or coming-soon page for most launches
For many small businesses and clinics, a maintenance or coming-soon page is the most practical choice. Visitors who type in your domain see one simple, intentional message instead of draft content, broken navigation, or empty service pages. Meanwhile, administrators and approved team members can continue building behind the scenes.
This option works especially well when the website is nearly ready but still needs final edits. You can keep the message brief: let visitors know the site is being prepared and provide a general contact method if one is already approved for public use. Do not publish health claims, pricing, insurance details, or scheduling promises until they have been reviewed for accuracy.
WordPress itself does not include a full coming-soon mode in every installation, so many site owners use a reputable maintenance-mode plugin. When selecting one, look for the ability to let logged-in administrators bypass the screen, set a clear launch status, and control search-engine visibility. Keep plugins updated, use only the features you need, and remove unused plugins after launch.
Test it while logged out
A common mistake is assuming a site is private because it looks private to an administrator. Your browser may keep you logged in, allowing you to see pages that regular visitors cannot.
Open an incognito or private-browsing window, then visit your domain. You can also ask a team member who does not have a WordPress account to check. Confirm that the maintenance screen appears on key URLs, including the home page, service pages, blog pages, and any pages that may have been created as drafts.
Make individual WordPress pages private when only a few are unfinished
If your website is already live and only one or two pages need work, changing the visibility of those specific pages may be the better choice. In the WordPress editor, find the page’s visibility setting and select Private. Private pages are generally visible only to logged-in users with the appropriate WordPress permissions.
This is useful for internal review. For example, a leadership team may want to review a new staff page or an updated program description before it goes public. It is less useful if outside reviewers need access, because each reviewer would need an appropriate login and user role.
WordPress also offers password-protected pages. This can work for a temporary preview, but it has limits. Anyone who receives the password can share it, and the page title or other information may still be exposed in certain site areas depending on your theme and settings. Use a unique password, share it only with the people who need it, and remove the protection or the page when the review period ends.
Consider sitewide password protection for a true private preview
If no part of the website should be public yet, sitewide password protection is often stronger than marking pages private one by one. This approach places a password gate in front of the site, so visitors cannot browse its content without approval.
Your hosting provider may offer this through a control panel, sometimes called directory privacy or password protection. A plugin may also provide sitewide access control. Hosting-level protection is often a sensible choice for a development or staging environment because it can block access before WordPress loads.
There are trade-offs. A password gate can interfere with website previews, third-party services, and search-engine crawling. That is usually acceptable before launch, but it means you should plan a deliberate transition when the site is ready. Remove the password gate, test the public site again, and verify that only the content intended for visitors is available.
Do not rely on search-engine settings as privacy protection
WordPress includes a setting that asks search engines not to index a site. You can find it under Settings, then Reading, as a checkbox commonly labeled “Discourage search engines from indexing this site.” It is helpful during development, but it does not make the site private.
A person who knows the web address can still visit pages unless another access restriction is in place. Search engines may also take time to respond to the request, particularly if the site has already been crawled or linked elsewhere. Think of this setting as an indexing preference, not a lock on the door.
Use it alongside a maintenance page or password protection while you build. When your site launches, revisit the setting. If you want families in Centennial, Littleton, and the South Denver area to find accurate information about your services, search engines need permission to index the pages you want to appear in results.
Create a careful launch checklist
Privacy is only one part of a healthy launch. Before making the site public, review it with the same care you would bring to any family-facing communication. A polished site should be easy to understand, accurate, and respectful of the decisions families are making.
Check that your contact details, location information, service descriptions, forms, and staff credentials are current. Read every page on a phone as well as a desktop computer. Make sure menus work, images have helpful alternative text, and any intake or contact process directs families to an appropriate secure channel.
You should also review user accounts. Remove temporary developer accounts that are no longer needed, confirm that each remaining user has the lowest permission level necessary, and use strong, unique passwords with two-factor authentication where available. Update WordPress, themes, and plugins before launch, then create a backup you can restore if needed.
Finally, check the site as a first-time visitor. Are there draft pages in navigation? Does the search function reveal unfinished posts? Are old sample pages, default comments, or placeholder text still visible? These details can make a new website feel unfinished even when its core pages are ready.
A private build supports a more confident public launch
There is no single best way to make a WordPress site private until launch. A coming-soon screen is often ideal for a public-facing site that is still being polished. Page-level privacy works for limited internal review, while sitewide password protection is better when the entire build needs to remain behind closed doors.
Give your team room to review the details, protect confidential information through appropriate systems, and publish only what is ready to serve families well. When visitors finally arrive, they should find a site that feels clear, supportive, and prepared for the next step.


