Why we do not let updates run automatically

A WordPress website is made of four parts with their own updates. We install each update sepa­rately, with a backup before and a check after.

  • What gets updatesWhich parts of a website get their own updates
  • RisksWhy automatic updates can cause damage unno­ticed
  • OrderIn what order and with what safeguards we update
Backup confirmed One update at a time Shop on staging
your-website.com
Menu
Home page
Form
Checkout
Login
Cache cleared, checked in a fresh browser.

Which parts get updates and how risky they are

Each part gets its own updates. We test risky ones on staging first.

CoreWordPress itself
Themethe look
PluginsForms, shop, page builder
PHPLanguage on the server
low riskhigh risk

Low

  • Core secu­rity updates
  • Minor core versions
  • Helper plugins with no visible output
backed up, checked

Medium

  • Minor versions of page builders
  • Form and translation plugins
  • Themes without announced breaks
Staging if in doubt

High

  • Major versions: shop, page builder, theme
  • Updates that migrate data
  • Payment plugins
  • Every PHP change
Staging required
Security updates take priority WordPress auto-updates: off Host auto-updates: off

What goes wrong when updates simply run through

Often everything looks fine right after the update. The damage only shows later, or only for your visi­tors.

In the developer's browserDeveloper
your-website.com looks fine
For your visi­torsVisitor
your-website.com broken
Theme update: on the live website, a cache was still holding on to the old stylesheets. Since then, we clear every cache layer and check in a fresh browser.
Two more cases from our work
  • Page builder updated straight on live: four hours of down­time
  • PHP raised by the host: the admin area would not open
Each case became a fixed rule.

Cases from our work, treated confi­den­tially.

How we install updates

Every update has a fixed order, a time window and a way back.

Order

  1. 1WordPress core
  2. 2Premium plugins
  3. 3Their add-ons, theme
  4. 4Free plugins
  5. 5Shop plugins last

Depen­den­cies first: translation before theme, shop system before payment modules. We check after every update.

Time window

Mo
Tu
We
Th
Fr
Sa
Su
  • Monday to Thursday
  • Not on Friday after­noons
  • Not before public holi­days
  • Not during your sales peaks

An update on Friday evening that nobody looks at until Monday is exactly the risk we avoid.

Way back

An update breaks some­thing
Backup restored, state as before
Find the cause on staging
Keep the plugin on its version

We then assess security notices for this version one by one, and a review date is set.

Steps per update the same every time
  1. 01Backup, confirmed
  2. 02Rate the risk
  3. 03High risk: staging
  4. 04Install one at a time
  5. 05Check pages and checkout
  6. 06Security scan
  7. 07Clear cache, check fresh
  8. 08If problems: roll back
PHP change planned
  • Supported version
  • Not on day one
  • Plugins checked before­hand
  • On staging, with a log
  • At most 6 months after end of support
  • 24 hours of moni­toring

Questions clients ask about updates

  • WordPress updates itself, so why do I need you?

    WordPress can install updates itself, but with no backup before, no check after and mostly at night. If something goes wrong, it only shows when a visitor notices. We install the same updates, with a backup, a check and at a time when we are watching.

  • My host offers automatic updates. Isn't that the same?

    The host's system presses the same update button, just from outside. It does not know which plugins on your website work together, and afterwards it does not check whether form, checkout and layout still work. So we switch this automa­tion off.

  • How often do you update, and will I notice?

    Regularly, not only when asked. Security updates take priority and do not wait for the next round; major versions follow after a compat­i­bility check. If all goes well, you notice nothing. If there is a problem, you get a short note on what was found and fixed.

  • Why is my PHP not on the very latest version?

    On purpose. Your website runs on a supported version, but not on the one that has just come out. In the first months, the makers of WordPress and the plugins are still finding their bugs. The switch comes as soon as your website's plugins are ready for it, at the latest six months after support for the old version ends.

Ready for dependable care?

Book a call
30 minutes by phone or video. You pick an open slot in the calendar.
Send a message
Briefly describe what you need. You will get a reply within 24 hours on working days.