Should you click 'Update All' on your WordPress plugins?

Mostly yes. The people warning you to be careful have cost more sites than the updates ever did. There is still a right way to go about it.

You log into WordPress and a red circle sits next to Plugins with a number in it. Fourteen. It has been there a while.

Somebody told you once that updating plugins can break the site, so you left it. That advice is half right, and on balance it has cost far more sites than it has saved.

Waiting carries the bigger risk

Here is the part the “be careful with updates” advice leaves out.

When a developer fixes a plugin vulnerability, the fix gets published. Not quietly: it goes into public databases with a description of what was wrong and which versions carry it. Security researchers write it up. That is how the system should work, and it beats the alternative.

The side effect is that the moment a fix exists, so does a public description of the hole. Scanners pick it up within hours and start sweeping the internet for sites still running the old version.

An un-updated plugin is not neutral. Each day it sits there, more tools know about it. The window between a published fix and a working automated exploit now runs to hours rather than weeks.

Meanwhile the thing you were avoiding, an update breaking your layout, is real, visible, reversible, and happens on a Tuesday morning while you are looking at it. A hack is invisible, permanent, and happens at 3am.

Given a risk you can see and undo against one you cannot, take the visible one.

The ten-minute routine

You do not need staging environments and version control to do this safely. You need a backup and a sensible order.

Take a backup first, then check it exists. Files and database. Not “the host does backups”: go and look at the actual backup file, with today’s date on it, sitting somewhere that is not the same server as the site. That is ninety per cent of your safety.

Do WordPress core last. Plugin authors update against the current core version, so updating core first can strand a plugin behind it. Plugins, then themes, then core.

Update the big structural ones on their own. Anything that shapes the whole site gets updated by itself, followed by a look at the front end: a page builder, a theme framework, WooCommerce, a caching plugin. The rest can go in one batch.

Then check the site properly. Not the dashboard. The public site, in a private browsing window so you are not logged in:

  • Home page loads and looks right
  • One interior page
  • The contact form, and submit it, then confirm the email arrives
  • If you sell things, add something to the basket and get as far as the payment page
  • One page on your phone

People skip the contact form test, and it is the one that matters most. A form that quietly stopped sending is the most expensive failure a small business website has. No error message, no clue. Your enquiries dry up and you put it down to a quiet month.

Write down what you did. Date, and what you updated. Three weeks later, when something odd surfaces, that note is the difference between five minutes and a lost afternoon.

When caution is warranted

A narrower version of the caution advice is correct:

  • A plugin somebody modified. If a developer edited the plugin’s own files rather than doing it properly, updating wipes those edits. You find out when something that worked stops working. The real fix is to stop having modified plugin files.
  • Major version jumps, 4.x to 5.x. Those carry deliberate breaking changes. Read the changelog for that one.
  • Anything touching payments, mid-campaign. Not because the update is dangerous, but because if it does go wrong you want to be at your desk rather than asleep.
  • A plugin last updated over a year ago. The update is not the problem here. The absence of one is. An abandoned plugin is a vulnerability with a delivery date, and it needs replacing rather than updating.

Should you turn on automatic updates?

For most small business sites, yes, for plugins, on two conditions.

First, you have working automatic backups that live off the server. Automatic updates without backups gives you faster breakage.

Second, something checks the site still works afterwards. Uptime monitoring will not catch this: a site with a broken layout or a dead contact form is still “up”. You need something that looks at the page, or somebody who does.

With both in place, automatic plugin updates are the right default. The maths is not close. An update breaks your layout perhaps one time in fifty. An unpatched, publicly documented vulnerability on a site that stays online for years gets found.

The realistic version

Running a business, you are not going to do this weekly. Few people do.

So either set a recurring reminder, the first Tuesday of the month, half an hour, backup and updates and the five checks above, or hand it to somebody. What fails is the thing most sites do: nothing for eighteen months, followed by a panic.

Handing it over is what our Care & Hosting covers: updates, backups that live somewhere other than your server, and a person looking at the site afterwards, for £49 a month. Moving an existing site over costs nothing.

Would you rather somebody sorted this for you?

We look after websites for £49 a month — hosting, updates, backups, security and small changes. Moving an existing site over is free. Or get a free review first and we will tell you what is actually wrong with the one you have.

Get a free website review See Care & Hosting