You have probably already seen that notification in your WordPress dashboard: an update is available. Should you apply it right away? Let it happen on its own? Or wait? The question of automatic WordPress updates divides opinion, and for good reason: they protect against security flaws, but they can also break a site that was running perfectly well the day before.

For a business owner who does not have time to review every update one by one, the temptation is to automate everything and stop thinking about it. That is sometimes the right call, sometimes a bad idea, depending on what is being updated, how critical the site is to your business, and how the site is managed day to day.

The answer is not the same for WordPress core, the theme, or the plugins: minor security updates can almost always be automated safely, while major updates deserve more caution.

What WordPress already automates by default

For several years now, WordPress has automatically enabled minor security updates, with no action needed from you. This is an excellent default setting: these patches are usually targeted, tested, and fix specific flaws without changing how the site behaves. These automatic security updates have blocked a very large number of attacks before they could even happen.

Major updates (going from version 6.4 to 6.5, for example), on the other hand, are not automatic by default. This is a deliberate choice by WordPress, since these releases can change behaviour and create incompatibilities.

The case of plugins and themes

This is where things get genuinely tricky. A plugin can release an update that deeply changes how it works, or that becomes incompatible with your theme or another plugin. Blindly automating every plugin update means accepting a risk of breakage with every release, with no control over it.

On the other hand, never updating your plugins exposes you to known security flaws that are actively being exploited, which is statistically the more serious risk. Automated bots scan the web around the clock looking for exactly these unpatched flaws, so the window between a patch being released and your site applying it matters more than most owners realise. Between the two extremes, the best approach is a compromise:

  • Automate minor security updates for all plugins
  • Apply major updates manually (or after checking), especially for critical plugins (payments, forms, page builders)
  • Always have a recent backup before a major update

Why an update can break a site

An update "breaks" a site when the new code conflicts with another part of the site: a theme that has not kept up with the same standards, a third-party plugin calling a function removed in the new version, or hosting running a PHP version too old for the new update. It is an ecosystem problem, not a flaw in the update itself. Our page /en/relax/site-casse-apres-mise-a-jour-wordpress/ explains how to roll back if this happens to you.

The opposite risk: never updating at all

At the other extreme, some owners simply disable updates altogether out of fear of breaking the site. This is an even riskier strategy over time: every month that passes without a security update widens exposure to flaws that are already documented and exploited by automated bots. A site that never updates almost always ends up compromised sooner or later.

If you find yourself stuck and unable to update WordPress, our page /en/relax/impossible-mettre-a-jour-wordpress/ explains the most common causes of that kind of block.

A simple method to apply

For a site managed without a dedicated technical team, a reasonable method is to:

  • Leave minor security updates on automatic, for WordPress, the theme, and plugins
  • Check pending major updates once a week or two
  • Test major updates on a copy of the site (a staging environment) if traffic or business activity justifies it
  • Always have a recent backup before any non-automatic update

When to call in a professional

Setting up a staging environment, securing a low-risk update process, or fixing a site that broke after an update, are tasks that require technical experience. If your business depends heavily on your site (online sales, bookings, brand image), it becomes worth handing this monitoring to a professional rather than managing updates on an ad hoc basis.

Frequently asked questions

Should every update be automated, without exception? No. Minor security updates can be automated safely. Major updates deserve to be checked, especially on an active site or one generating revenue.

What should I do if an automatic update broke my site? Restore your last clean backup, then identify the plugin or theme responsible before reapplying updates one at a time.

Is it risky to stay on an old version of WordPress? Yes, very much so. Old versions no longer receive security patches, which makes them a prime target for automated attacks that constantly scan the web.

Do automatic updates need any supervision at all? Yes, even automated ones. Checking your site briefly after a batch of updates, and keeping an eye on your backup schedule, catches the rare cases where something silently went wrong.

To go further on security and maintenance, our guide on securing your WordPress site and our WordPress maintenance checklist are good next reads.

Worried about your updates, or has one already broken your site? Relax by Yumea handles your site's updates safely, with a backup before every step. Request my free diagnosis at /en/relax/