A WordPress website is made of four parts with their own updates. We install each update separately, with a backup before and a check after.
Each part gets its own updates. We test risky ones on staging first.
Often everything looks fine right after the update. The damage only shows later, or only for your visitors.
Cases from our work, treated confidentially.
Every update has a fixed order, a time window and a way back.
Dependencies first: translation before theme, shop system before payment modules. We check after every update.
An update on Friday evening that nobody looks at until Monday is exactly the risk we avoid.
We then assess security notices for this version one by one, and a review date is set.
WordPress can install updates itself, but with no backup before, no check after and mostly at night. If something goes wrong, it only shows when a visitor notices. We install the same updates, with a backup, a check and at a time when we are watching.
The host's system presses the same update button, just from outside. It does not know which plugins on your website work together, and afterwards it does not check whether form, checkout and layout still work. So we switch this automation off.
Regularly, not only when asked. Security updates take priority and do not wait for the next round; major versions follow after a compatibility check. If all goes well, you notice nothing. If there is a problem, you get a short note on what was found and fixed.
On purpose. Your website runs on a supported version, but not on the one that has just come out. In the first months, the makers of WordPress and the plugins are still finding their bugs. The switch comes as soon as your website's plugins are ready for it, at the latest six months after support for the old version ends.