←back to Blog

WordPress auto updates guide: which plugins and core updates to auto-update and which to test on staging

WordPress Auto Updates: Should You Turn Them On? (The Real Answer)

Turn on WordPress auto updates for everything and one day a plugin update will quietly break your checkout at 3 AM. Turn them off for everything and your site ends up running a plugin with a publicly known security hole for weeks. Neither extreme is the right answer.

The real answer to “should I enable WordPress auto updates?” is: yes, but selectively. Some parts of a WordPress site should update themselves the moment a fix ships. Other parts should never update without someone testing them first. This guide shows exactly where to draw that line, and how to set it up with the dashboard toggles or a few lines of code.

Should You Turn On WordPress Auto Updates?

For most WordPress sites, you should turn on auto updates for WordPress core minor releases, translations, and small, well-maintained plugins, and keep manual control over major core releases, page builders, WooCommerce, and any plugin that handles payments or memberships. This split gets security patches in fast while keeping the risky, site-wide updates under human control.

The reason this matters is speed. According to Patchstack’s State of WordPress Security in 2026 report, the weighted median time from public disclosure to first exploitation for heavily targeted vulnerabilities was just 5 hours, and roughly half of high-impact vulnerabilities were exploited within 24 hours. If you only log in to update plugins once a week, attackers have days of head start.

The same Patchstack report found that 91% of the 11,334 new WordPress vulnerabilities discovered in 2025 were in plugins, 9% were in themes, and only 6 were in WordPress core. Plugins are where the risk lives, which is exactly why a blanket “never auto-update plugins” rule is a bad idea.

What WordPress Updates Automatically by Default

Out of the box, WordPress automatically installs minor core releases (for example, 6.9.1 to 6.9.2) and translation files, but it does not auto-update plugins, themes, or major core versions. Plugin and theme auto-updates are opt-in, controlled per item from the Plugins and Themes screens.

Minor core releases are security and maintenance fixes, and they almost never break anything. Leave WordPress core minor auto updates on. Disabling them is one of the more common hardening “tips” online, and it does the opposite of hardening.

Major core releases (for example, 6.9 to 7.0) are different. They ship new editor features, API changes, and sometimes deprecations that older plugins and themes trip over. Major WordPress releases deserve a staging test first, which is covered in the guide to creating a WordPress staging site.

Which Plugins Are Safe to Auto-Update?

Plugins that are safe to auto-update are small, single-purpose plugins from active developers that don’t control your layout, checkout, or user accounts. Plugins that should stay on manual updates are the ones whose failure would take down revenue or the entire front end, such as WooCommerce, page builders, and payment gateways.

A useful test: ask “if this plugin’s update breaks, what does a visitor see?” If the answer is “nothing much, maybe a missing feature,” auto-update it. If the answer is “a broken homepage” or “a checkout that doesn’t take money,” keep it manual.

ComponentAuto-update?Why
WordPress core minor releasesYes (default)Security and bug fixes only, very low risk
WordPress core major releasesNo, test on stagingNew features and API changes can break older plugins
Small single-purpose pluginsYesLow blast radius, fast security patches
WooCommerce, page builders, payment and membership pluginsNo, test on stagingA broken update hits revenue or the whole layout
TranslationsYes (default)Text files only, effectively zero risk

Themes sit in the middle. A lightweight, well-maintained parent theme with all customizations kept in a child theme is usually fine to auto-update. A heavily customized theme edited directly is not, because an update will overwrite those edits.

What Happens If a WordPress Auto Update Breaks Your Site?

Since WordPress 6.6, if a plugin auto-update causes a PHP fatal error, WordPress automatically rolls the plugin back to its previous version and emails the site administrator. This rollback protection removed the biggest historical risk of plugin auto-updates: waking up to a white screen.

The WordPress rollback feature has a real limit, though. According to the merge proposal on make.wordpress.org, WordPress checks for a fatal error by making a loopback request to the site’s home page after the update. That means the rollback only catches PHP fatal errors that show up on the home page.

Auto-update rollback will not catch:

  • A broken layout or missing styles (no PHP error, so nothing to detect)
  • JavaScript errors that stop a form, slider, or cart button from working
  • Fatal errors that only happen on the checkout, a product page, or inside wp-admin
  • Logic bugs, like a payment gateway that loads fine but fails to process orders

That gap is exactly why WooCommerce and page builders stay on manual updates. Rollback is a safety net for the home page, not a full test suite. If a fatal error does slip through, the WordPress critical error fix guide walks through recovery step by step, and a recent backup turns a bad update into a five-minute restore. If you don’t have automated backups yet, start with the best WordPress backup plugin breakdown.

How to Enable Auto Updates for WordPress Plugins (Dashboard Method)

To enable auto updates for a WordPress plugin, go to Plugins > Installed Plugins and click “Enable auto-updates” in the Automatic Updates column next to that plugin. Themes work the same way from Appearance > Themes, by opening a theme’s details and clicking “Enable auto-updates.”

  1. Go to Plugins > Installed Plugins.
  2. Find the “Automatic Updates” column on the right.
  3. Click Enable auto-updates for each low-risk plugin.
  4. Leave WooCommerce, your page builder, and payment or membership plugins on manual.
  5. Make sure the admin email under Settings > General is one you actually read, because update and rollback notices go there.

Premium plugins bought from marketplaces often won’t show the toggle, or won’t update at all, until a license key is activated. That deserves attention: Patchstack’s 2026 report found premium WordPress components had three times more known exploited vulnerabilities than free ones. An unlicensed premium plugin that can’t update is a security liability.

How to Control WordPress Auto Updates With Code

WordPress auto updates can be controlled with code using the WP_AUTO_UPDATE_CORE constant in wp-config.php for core, and the auto_update_plugin filter for plugins. Code-based rules are useful on client sites, because a dashboard toggle can be switched off by anyone with admin access.

To keep WordPress core on minor-only auto updates (the safe default), add this to wp-config.php:

// Minor core releases only (recommended)
define( 'WP_AUTO_UPDATE_CORE', 'minor' );

// Other options:
// true  = all core updates, including major releases
// false = no core auto updates (not recommended)

To block auto updates for specific high-risk plugins while still respecting the dashboard toggles for everything else, create a must-use plugin at wp-content/mu-plugins/auto-update-rules.php:

<?php
/**
 * Plugin Name: Auto Update Rules
 * Description: Never auto-update high-risk plugins.
 */
add_filter( 'auto_update_plugin', function ( $update, $item ) {
    $never_auto_update = array(
        'woocommerce',
        'elementor',
    );

    if ( isset( $item->slug ) && in_array( $item->slug, $never_auto_update, true ) ) {
        return false;
    }

    return $update; // everything else follows the dashboard toggle
}, 10, 2 );

Swap the slugs for the plugins on your own site. The slug is the plugin’s folder name inside wp-content/plugins/. Because the filter returns $update for everything else, the “Enable auto-updates” toggles in the dashboard keep working normally.

Why Auto Updates Sometimes Run Late

WordPress auto updates are triggered by WP-Cron, which checks for updates roughly twice a day but only runs when someone visits the site. On a low-traffic site, or one where WP-Cron is disabled without a real server cron job set up, auto updates can run hours late or not at all. The WP-Cron fix guide explains how to replace WP-Cron with a real cron job so updates run on time.

Auto Updates Are Not a Maintenance Plan

WordPress auto updates reduce the window of exposure, but they do not replace monitoring, backups, or manual testing of major updates. Patchstack found that 46% of WordPress vulnerabilities disclosed in 2025 did not have a developer fix available by the time of public disclosure, so in those cases there was simply no update to install, automatic or not.

A sensible setup looks like this: auto updates for core minor releases and low-risk plugins, daily off-site backups, a staging site for major updates, and someone checking the site after big releases. That combination is what separates a site that survives a bad update from one that goes down for a day. If you’d rather hand this off entirely, the WordPress maintenance plan pricing guide shows what a proper plan should cover and cost.

The Bottom Line

Turn WordPress auto updates on where a failure is cheap and off where a failure is expensive. Core minor releases, translations, and small plugins should update themselves. WooCommerce, page builders, payment plugins, and major WordPress releases should go through staging first. Set it up once today, and your site gets security patches in hours instead of whenever you next remember to log in.

Frequently Asked Questions

WordPress automatic updates are safe for core minor releases, translations, and small single-purpose plugins, and since WordPress 6.6 a plugin auto-update that causes a PHP fatal error is rolled back automatically. Major core releases, WooCommerce, page builders, and payment plugins are safer updated manually after testing on a staging site.

No, WordPress does not auto-update plugins or themes by default. Only minor core releases and translations update automatically out of the box, and plugin auto-updates must be enabled per plugin from the Plugins screen or with the auto_update_plugin filter.

If a plugin auto-update causes a PHP fatal error on the home page, WordPress 6.6 and later rolls the plugin back to its previous version and emails the site admin. Problems the rollback can’t detect, such as broken layouts or a failing checkout, need to be fixed by restoring a backup or rolling the plugin back manually.

WordPress checks for automatic updates about twice a day through WP-Cron. Because WP-Cron only runs when the site gets a visit, low-traffic sites or sites with WP-Cron disabled can see auto updates delayed unless a real server cron job is configured.

Auto updates for WooCommerce are generally not recommended, because a WooCommerce update can change checkout, payment, or database behavior in ways the WordPress rollback feature won’t detect. Update WooCommerce manually after testing on a staging site, ideally during a low-traffic period.

Leave a Reply

Your email address will not be published. Required fields are marked *