Insights Care and maintenance

WordPress updates: why clicking update can break your site, and how to update safely

Skipping WordPress updates leaves security holes open and blind updates can break forms or checkout. Here is a safe routine for core, plugins, themes and PHP.

AI-generated image

Log into almost any WordPress site that's been left alone for a while and you'll see it: a little red number next to "Updates." Maybe it says 3. Maybe it says 27. Most owners do one of two things. They ignore it for months, or they click "Update All" on a Friday afternoon and hope. Both can hurt you.

Skipping WordPress updates leaves known security holes open, and clicking update blindly can break your layout, your forms or your checkout. The safe way is a routine: take a fresh backup, test updates on a staging copy, update in a sensible order, check the pages that make you money and have a way to roll back. The routine is simple. It just takes time and attention every month.

What actually needs updating

A WordPress site is several pieces of software stacked on top of each other, and each one gets its own updates:

  • WordPress core: the main software that runs the site.
  • Plugins: add ons that give your site features, like contact forms, booking or a store. It's common to see a dozen or more.
  • Your theme: the design layer that controls how everything looks.
  • PHP: the programming language WordPress runs on, which lives on your hosting server.

These pieces are made by different people on different schedules. That's the root of the problem. An update to one piece can clash with another piece that hasn't caught up yet.

Why skipping updates is risky

Many updates fix security holes. Once a fix is published, the hole is public knowledge, and sites that haven't updated are the easy targets. I see this a lot: a site nobody has touched in a couple of years, running plugins with known problems, and an owner who had no idea.

PHP is the one people forget, because it lives on the server instead of in the WordPress dashboard. The PHP project is clear about old versions. Its supported versions page describes an end of life release this way: "Users of this release should upgrade as soon as possible, as they may be exposed to unpatched security vulnerabilities." As of today, PHP 8.2's security support runs until December 31, 2026, so sites still on 8.2 have a few months to plan the move. WordPress itself recommends "PHP version 8.3 or greater."

Why clicking update blindly is risky too

Updates break things for ordinary reasons. A plugin changes how it works and your theme doesn't expect it. Two plugins that got along fine now step on each other. A PHP upgrade exposes old code in a theme that hasn't been maintained. The result might be a scrambled page, a contact form that stops sending or a checkout that errors out.

The worst part is that the site often still loads. The homepage looks fine, so nobody checks the form. That's how a broken update turns into weeks of missing leads. I wrote more about that in silent website failures.

What WordPress updates on its own

WordPress does some updating automatically, and it's worth knowing exactly what. According to the WordPress documentation, "Existing installations receive minor core updates by default." Those are the small maintenance and security releases. It also says "Fresh installations created on WordPress 5.6 or later receive both minor and major core updates by default."

Plugins and themes are different. The same page says "By default, automatic background updates only happen for plugins and themes in special cases, as determined by the WordPress.org API response, which is controlled by the WordPress security team for patching critical vulnerabilities." You can turn on auto updates plugin by plugin, a feature WordPress added in version 5.5.

So auto updates help, but they don't test anything. They don't check your form afterward. And they don't touch PHP at all. Turning them on for well maintained plugins can be reasonable. Turning them on for your store plugin without anyone watching is a gamble.

A safe update routine

Here's the process I'd follow on any WordPress site that matters to the business:

A safe WordPress update routine Seven step routine for updating a WordPress site without breaking it. 1 Take a fresh backup of files and database, stored somewhere other than the site's own server. 2 Update a staging copy first, a private copy customers never see. 3 Read the changelogs before a major version change. 4 Update in a sensible order, one or a few at a time, so you know which update caused a problem. 5 Test what makes you money. 6 Repeat the same updates and tests on the live site. 7 Have a rollback plan: know how you would restore the backup and who would do it. A side panel shows the update order: plugins first, then the theme, then WordPress core. A second panel lists what to test after updating: submit every form, confirm the email arrives, run a test purchase or booking, log in as a user, and load key pages on a phone. A safe WordPress update routine Test before the live site. Know how to roll back. 1 Take a fresh backup Files and database, stored off the server 2 Update a staging copy first A private copy customers never see 3 Read changelogs for big jumps Look before a major version change 4 Update in a sensible order A few at a time, so you know the cause 5 Test what makes you money See the checklist on the right 6 Repeat on the live site Same updates, same tests 7 Have a rollback plan Know how to restore, and who does it UPDATE ORDER 1 Plugins 2 Theme 3 WordPress core TEST AFTER UPDATING Submit every form Confirm the email arrives Test purchase or booking Log in as a user Load key pages on a phone
Back up, test on staging, update in order and check the pages that make you money before you touch the live site.
  1. Take a fresh backup first. Files and database, stored somewhere other than the site's own server. WordPress's own upgrade guide warns that "without a backup of your entire site and your database, made prior to your upgrade attempt, a successful rollback is near impossible." And make sure it's a backup you know how to restore. Here's why many backups don't.
  2. Update a staging copy first. Staging is a private copy of your site where you can try changes without customers seeing anything. If it breaks there, nothing is lost.
  3. Read the changelogs for big jumps. A changelog is the list of what changed in an update. A major version change deserves a look before you click.
  4. Update in a sensible order. Plugins first, one or a few at a time, then the theme, then WordPress core. Going slowly means you know which update caused a problem.
  5. Test what makes you money. Submit every form and confirm the email arrives. Run a test purchase or booking. Log in as a user. Load key pages on a phone.
  6. Repeat on the live site. Once staging checks out, apply the same updates to the real site and run the same tests again.
  7. Have a rollback plan. Know exactly how you'd restore the backup from step one, and who would do it, before you start.

PHP upgrades follow the same idea. Test on staging, check for errors, then switch the live server.

Doing it yourself: what it takes

Plenty of owners handle their own updates, and a simple site with a few plugins is very doable. Be honest with yourself about what the routine needs:

  • Time: usually an hour or two a month for a small site, more when a big update lands or something breaks.
  • Tools: a reliable backup setup and a staging environment. Some hosts include staging. Some don't.
  • Skills: comfort in the WordPress dashboard and your hosting panel, and enough patience to troubleshoot when a plugin fights your theme.
  • The risk: if an update breaks checkout on a Monday morning and you're with clients all day, the site stays broken until you get to it.

If you enjoy that kind of work and have the hours, you can do it well. If you'd rather never think about the red number again, that tells you something too. And if you're still deciding whether WordPress is the right fit at all, read WordPress or a custom website.

Handing it off

This routine is the core of our care plan. We handle updates and security patches, keep daily backups with restores we actually test, watch for downtime and broken forms, and do a monthly check that everything still works. We also run the servers, so PHP upgrades are planned alongside WordPress instead of sprung on you. For sites we build on WordPress, our WordPress service keeps the plugin list lean so there's less to go wrong. No one can promise an update will never cause a problem. What a good routine does is catch it quickly and put things back. You get the exact monthly price in writing before you sign.

If that little red number has been sitting there a while, ask us about a care plan.

Find out what your website is leaking.

Send us your site. We’ll check your forms, your phone speed and how Google sees you, then tell you plainly what’s worth fixing. If the answer is “nothing much”, we’ll say that too.

Get my free Lead Leak Check

No cost. No obligation. A real person replies within one business day.