WordPress Auto-Updates: Should You Turn Them On for Core, Plugins and Themes?
What WordPress auto-update settings for core, plugins and themes do, the real risks, a sensible middle ground, and when to test updates on staging first.

On this page
- Leave minor core updates and small, well-maintained plugins on auto-update, but update page builders, WooCommerce and your theme by hand after testing.
- Auto-updates only roll back fatal errors, so broken layouts, silent form failures and expired premium licences still need backups, uptime monitoring and a weekly check.
- Use a staging site for stores, major versions and PHP changes, and switch off auto-updates for any plugin you want to test first.
WordPress can update itself in the background: core, plugins, themes and translations. It sounds like the perfect way to stay secure without effort, and for some parts of your site it is. For others, an update that arrives at 3am can break a layout, a form or your checkout before anyone notices. Here's what each setting does and how to decide what to switch on.
This article is about the auto-update settings themselves. For the hands-on process of updating by hand, see how to update WordPress safely.
What each auto-update setting does
| Setting | Where to find it | What it does |
|---|---|---|
| Minor core updates | On by default | Installs maintenance and security releases (for example 6.x.1 to 6.x.2) automatically |
| Major core updates | Dashboard > Updates | Moves your site to new major versions of WordPress without asking |
| Plugin auto-updates | Plugins screen, per plugin | Installs each new version of that plugin as soon as WordPress picks it up |
| Theme auto-updates | Appearance > Themes, in the theme details | Updates that theme automatically |
| Translations | Automatic | Keeps language files for core, plugins and themes current |
A few details worth knowing:
- Auto-updates run through WordPress's built-in scheduler, which relies on site visits, so on quiet sites they can happen later than you expect.
- WordPress emails the site's admin address after auto-updates. If that address is an old developer's inbox, nobody hears about failures.
- Some hosts manage updates themselves or hide these toggles. Developers can also control core updates in wp-config.php. If a setting is missing or greyed out, check with your host or developer.
The case for turning them on
Outdated plugins are one of the most common ways WordPress sites get hacked. When a security fix is released, auto-updates get it onto your site within hours rather than whenever someone remembers to log in. They make most sense when:
- Nobody on your team logs into the dashboard every week
- The site is a simple brochure site with a handful of well-maintained plugins
- The plugin in question is small and single-purpose, from an established developer
The risks
Breaking changes
Major versions of page builders, WooCommerce and themes sometimes change how things work. Theme templates that override WooCommerce can go out of date, and a new version may need a newer PHP version than your hosting runs.
Silent breakage
Recent WordPress versions can roll back a plugin auto-update that causes a fatal error. But a misaligned layout, a contact form that stops sending emails or a checkout bug isn't a fatal error, so nothing rolls back, and you may not notice for days.
Bad timing
An update can land in the middle of a festival sale or a paid ad campaign, exactly when a broken page costs you most.
Premium plugins that don't auto-update
Premium plugins and themes update through their own licence system. If the licence has expired, no updates arrive at all, even with the toggle switched on. Plugins bundled with a premium theme often only update when the theme itself does. Auto-updates give a false sense of security if you never check these.
A sensible middle ground
For most business websites, a mix works better than all-on or all-off:
| Part of the site | Auto-update? | Why |
|---|---|---|
| Minor core releases | Yes, leave on | Small security and bug fixes that rarely break anything |
| Major core releases | Usually manual, after a short wait | Gives plugin and theme authors time to fix compatibility issues |
| Small, well-maintained plugins | Often yes | Low risk, and security fixes arrive quickly |
| Page builder, WooCommerce and its extensions, booking or membership plugins | Manual, after testing | They control layouts, payments and customer data |
| Your active theme | Manual | Theme updates can change layouts and styling |
| Unused plugins and themes | Delete them | Inactive code can still be a security risk |
| Translations | Yes | Very low risk |
Write the list down, so whoever looks after the site knows which plugins update themselves and which are done by hand.
Safety nets to put in place first
Auto-updates are only safe if you can spot a problem quickly and undo it:
- Daily automatic backups stored away from your hosting account, so you can restore yesterday's site. See the backup and restore guide.
- Uptime monitoring that alerts you when the site goes down. It catches outages and fatal errors, not broken layouts. See uptime monitoring explained.
- Update emails going to a real inbox that someone reads.
- A quick weekly check: open the homepage on your phone, send a test enquiry through the contact form and, for stores, add something to the cart.
When to use staging instead
A staging site is a private copy of your website where you can test updates before they touch the live site. It's worth using when:
- You run a WooCommerce store or take bookings and payments
- A major version of your page builder, WooCommerce or theme is released
- You're changing the PHP version on your hosting
- The site has custom code or a long list of plugins
- A big campaign or sale is coming up
One catch: auto-updates on the live site don't wait for your staging tests. For any plugin you want to test first, switch its auto-update off on the live site. See staging sites explained for how to set one up.
Make it someone's job
Whatever you choose, someone should own it. Once a month, review which plugins are set to auto-update, check that premium licences are active, delete anything unused and read through the update emails for failures. The WordPress maintenance checklist shows where this fits alongside backups, security and speed checks.
Rather not manage updates yourself? See WordPress maintenance for help with updates, backups and testing.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.


