Every maintenance article says to keep WordPress updated, as though updating were one activity. It is three, they carry different risks, and treating them the same is why update day sometimes ends badly.
Understanding WordPress core plugin and theme updates separately is what turns a nervous monthly job into a routine one.
Core updates: the safest of the three
WordPress core is maintained by a large team with an enormous installed base, and backward compatibility is taken seriously. Minor releases — the security and bug-fix ones — are applied automatically by default and this is a sensible default that should generally be left alone.
Major releases occasionally change how something behaves and are worth applying a week or two after release rather than on the day, by which time any significant issue is widely reported. When a core update does break something it is almost never core itself; it is a plugin that was relying on behaviour core has changed.
Plugin updates: where nearly all the risk is
This is the category that breaks sites, and it is worth knowing why. Plugins are written by thousands of different developers to wildly different standards. Two plugins that each work perfectly can conflict with each other. A plugin update can change a setting, add a feature, or drop support for something you were relying on.
The risk is not evenly spread. Higher: page builders, security plugins, caching plugins, anything touching checkout or payments, and anything with a premium licence. Lower: small single-purpose plugins that add one shortcode and touch nothing else.
Which is why the useful habit is batching by risk rather than updating everything at once. Do the low-risk ones together, then the higher-risk ones one at a time with a check in between. When something breaks you know immediately what caused it — and our note on a website slow after an update covers the version of this where nothing breaks but everything gets slower.
Theme updates: rare, and occasionally destructive
Themes update less often, and the danger is specific: if customisations were made directly to the theme files, a theme update overwrites them. Not “might” — that is what updating replaces the files means.
If you are using a child theme, your changes live separately and survive. If somebody edited the parent theme directly, an update erases that work, and it is often work nobody remembers was done. This single distinction decides whether a theme update is routine or a rebuild.
Before any theme update on a site you did not build, find out which situation you are in. It takes a minute and it is the difference between a small job and a bad day.
Are WordPress auto updates safe?
A reasonable default for most small business sites: leave core minor updates automatic, turn automatic updates on for a handful of low-risk plugins you trust, and keep everything else manual.
Full automation is tempting and it has one specific failure mode. An automatic update that breaks the site does so at three in the morning, with nobody watching, and the site stays broken until somebody notices. Automation without monitoring is not maintenance — it is unattended change. If you do automate broadly, put uptime monitoring on the site so a break is reported rather than discovered.
The WordPress update order that avoids most problems
- Back up first, and confirm the backup completed. Not after the update — before.
- Core minor releases, which are usually already done automatically.
- Low-risk plugins in one batch. Check the site loads.
- Higher-risk plugins one at a time, checking between each.
- Theme last, and only after confirming the child theme situation.
- Then test what matters — the contact form, the checkout, the site on a phone.
That last step is the one that gets skipped, and it is the one that catches the silent failures. An update that breaks a form does not announce itself; you find out from the enquiries that stop arriving.
Why this is monthly rather than occasional
Updates applied monthly are small, quick and individually low-risk. Updates left for a year become a project where everything moves at once and nothing can be isolated.
The work does not go away by being postponed — it accumulates, and the version done later is harder. That is the whole argument for a monthly update routine, and our website maintenance checklist is the version to work from if you would rather do it yourself.