Maintenance

WordPress Auto-Updates: Should You Turn Them On for Core, Plugins and Themes?

What WordPress auto-update settings for core, plugins and themes do, the real risks, a sensible middle ground, and when to test updates on staging first.

WordPress Auto-Updates: Should You Turn Them On for Core, Plugins and Themes?
On this page
  1. What each auto-update setting does
  2. The case for turning them on
  3. The risks
  4. A sensible middle ground
  5. Safety nets to put in place first
  6. When to use staging instead
  7. Make it someone's job
Key takeaways
  • Leave minor core updates and small, well-maintained plugins on auto-update, but update page builders, WooCommerce and your theme by hand after testing.
  • Auto-updates only roll back fatal errors, so broken layouts, silent form failures and expired premium licences still need backups, uptime monitoring and a weekly check.
  • Use a staging site for stores, major versions and PHP changes, and switch off auto-updates for any plugin you want to test first.

WordPress can update itself in the background: core, plugins, themes and translations. It sounds like the perfect way to stay secure without effort, and for some parts of your site it is. For others, an update that arrives at 3am can break a layout, a form or your checkout before anyone notices. Here's what each setting does and how to decide what to switch on.

This article is about the auto-update settings themselves. For the hands-on process of updating by hand, see how to update WordPress safely.

What each auto-update setting does

SettingWhere to find itWhat it does
Minor core updatesOn by defaultInstalls maintenance and security releases (for example 6.x.1 to 6.x.2) automatically
Major core updatesDashboard > UpdatesMoves your site to new major versions of WordPress without asking
Plugin auto-updatesPlugins screen, per pluginInstalls each new version of that plugin as soon as WordPress picks it up
Theme auto-updatesAppearance > Themes, in the theme detailsUpdates that theme automatically
TranslationsAutomaticKeeps language files for core, plugins and themes current

A few details worth knowing:

  • Auto-updates run through WordPress's built-in scheduler, which relies on site visits, so on quiet sites they can happen later than you expect.
  • WordPress emails the site's admin address after auto-updates. If that address is an old developer's inbox, nobody hears about failures.
  • Some hosts manage updates themselves or hide these toggles. Developers can also control core updates in wp-config.php. If a setting is missing or greyed out, check with your host or developer.

The case for turning them on

Outdated plugins are one of the most common ways WordPress sites get hacked. When a security fix is released, auto-updates get it onto your site within hours rather than whenever someone remembers to log in. They make most sense when:

  • Nobody on your team logs into the dashboard every week
  • The site is a simple brochure site with a handful of well-maintained plugins
  • The plugin in question is small and single-purpose, from an established developer

The risks

Breaking changes

Major versions of page builders, WooCommerce and themes sometimes change how things work. Theme templates that override WooCommerce can go out of date, and a new version may need a newer PHP version than your hosting runs.

Silent breakage

Recent WordPress versions can roll back a plugin auto-update that causes a fatal error. But a misaligned layout, a contact form that stops sending emails or a checkout bug isn't a fatal error, so nothing rolls back, and you may not notice for days.

Bad timing

An update can land in the middle of a festival sale or a paid ad campaign, exactly when a broken page costs you most.

Premium plugins that don't auto-update

Premium plugins and themes update through their own licence system. If the licence has expired, no updates arrive at all, even with the toggle switched on. Plugins bundled with a premium theme often only update when the theme itself does. Auto-updates give a false sense of security if you never check these.

A sensible middle ground

For most business websites, a mix works better than all-on or all-off:

Part of the siteAuto-update?Why
Minor core releasesYes, leave onSmall security and bug fixes that rarely break anything
Major core releasesUsually manual, after a short waitGives plugin and theme authors time to fix compatibility issues
Small, well-maintained pluginsOften yesLow risk, and security fixes arrive quickly
Page builder, WooCommerce and its extensions, booking or membership pluginsManual, after testingThey control layouts, payments and customer data
Your active themeManualTheme updates can change layouts and styling
Unused plugins and themesDelete themInactive code can still be a security risk
TranslationsYesVery low risk

Write the list down, so whoever looks after the site knows which plugins update themselves and which are done by hand.

Safety nets to put in place first

Auto-updates are only safe if you can spot a problem quickly and undo it:

  • Daily automatic backups stored away from your hosting account, so you can restore yesterday's site. See the backup and restore guide.
  • Uptime monitoring that alerts you when the site goes down. It catches outages and fatal errors, not broken layouts. See uptime monitoring explained.
  • Update emails going to a real inbox that someone reads.
  • A quick weekly check: open the homepage on your phone, send a test enquiry through the contact form and, for stores, add something to the cart.

When to use staging instead

A staging site is a private copy of your website where you can test updates before they touch the live site. It's worth using when:

  • You run a WooCommerce store or take bookings and payments
  • A major version of your page builder, WooCommerce or theme is released
  • You're changing the PHP version on your hosting
  • The site has custom code or a long list of plugins
  • A big campaign or sale is coming up

One catch: auto-updates on the live site don't wait for your staging tests. For any plugin you want to test first, switch its auto-update off on the live site. See staging sites explained for how to set one up.

Make it someone's job

Whatever you choose, someone should own it. Once a month, review which plugins are set to auto-update, check that premium licences are active, delete anything unused and read through the update emails for failures. The WordPress maintenance checklist shows where this fits alongside backups, security and speed checks.

Rather not manage updates yourself? See WordPress maintenance for help with updates, backups and testing.

Need help with your website?

I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.

Found this useful? Share it:
Contact

Let's build your next website

Available for freelance projects, agency white-label work and long-term maintenance. Feel free to pass this along to your team or company.

Your details are emailed to me, then WhatsApp opens so we can chat right away.

Chat now