Get started
Website care

Our WordPress Update Routine, Step by Step

How we apply WordPress updates: what happens before, during and after, how the routine changes by plan, what we do when an update goes wrong, and a one-page version you can print.

WebXSentry guide: our WordPress update routine

Updates keep a WordPress site secure, but an update can also break a page, a form or a checkout. The way to get the benefit without the risk is a routine that you follow every time. This is ours, in plain words. Use it for your own site, or compare it with what any provider tells you they do.

Before you start

  1. Make sure a recent backup exists and that you know how to restore it.
  2. Pick a quiet time for a store or a busy site.
  3. Note what the site looks like now: your home page, a key page and your main form, so you can compare.

The routine

  1. Test on a copy where you can. A staging copy is a private clone of your site. Updates run there first.
  2. Update WordPress core first. Everything else depends on it.
  3. Update the theme next, then check the pages.
  4. Update plugins in small groups. Check the site after each group, not only at the end.
  5. Test what matters. Your key pages, your contact or booking form, and, on a store, a test order.
  6. Release. Apply the same updates to the live site, or release the staging copy.
  7. Look again. A short recheck after release catches what only shows up on the live site.

How it differs by plan

StepEssentialBusinessPriority
Recent backup confirmed firstYesYesYes
Tested on a staging copyNo, updated liveYesYes
Engineer checks every updateNoNoYes
Test order on a storeNoMonthlyMonthly

What to do when an update breaks something

  1. Do not panic and do not click around. Note exactly what is wrong and where.
  2. Undo the last change. If you updated plugins in groups, you know which group to roll back.
  3. Restore from the backup if undoing is not enough.
  4. Find the cause before trying again. Often it is a plugin that has not kept pace with WordPress, or two plugins that clash.
  5. Write down what happened. It makes the next update safer.

The updates we do not apply blindly

A plugin that its maker has not updated for a long time, or a heavily customised theme, can break when touched. In those cases we tell you what we found, what the risk is and what we suggest, and we wait for your yes before changing it.

Why updates go wrong

  • Plugin conflicts. Two plugins that worked together stop doing so after one of them changes.
  • Old code. A plugin or theme that has not kept pace with WordPress breaks on a newer version.
  • Customisations. Changes made directly to a theme or plugin are overwritten by an update.
  • Hosting limits. A server with too little memory or an old PHP version fails mid-update.
  • Skipping versions. Updating after a long gap means several changes land at once.

Security updates and feature updates

Not every update is equally urgent. A security fix should be applied promptly, because the weakness it closes becomes public knowledge once the fix is released. A feature update can wait for a convenient moment and a staging test. A good routine separates the two, and does not leave security updates sitting for weeks.

Automatic updates: yes or no?

ForAgainst
Let WordPress update itselfSecurity fixes arrive quickly, and nothing is forgottenAn update can break the site with nobody watching, and you only find out later
Update by hand on a scheduleYou check the result each timeIt depends on someone remembering

A middle path is common: let small security releases apply on their own, and handle larger updates by hand after a backup and a check.

What to watch on a store

On a WooCommerce store an update that breaks the checkout costs orders. Before updating, pick a quiet hour. After updating, place a test order from the cart to the confirmation email, and look at an order in the admin to be sure it was recorded. If you cannot test on a copy, keep the window short and the backup recent.

Keep a record

Write down what you updated, when, and what you checked. When something breaks next month, a short log of what changed is the fastest way to find the cause.

A sample update log

DateWhat was updatedWhat was checkedResult
First TuesdayWordPress core, themeHome page, contact formPassed
First TuesdayPlugin group A: forms and SEOContact form sent a test messagePassed
First TuesdayPlugin group B: store and paymentsTest order from cart to confirmationOne issue found, rolled back, reported

This is an example of the kind of record that makes the next update easier. A short log like this also helps whoever looks after the site next.

When not to update

  • Right before a sale or a launch.
  • When no recent backup exists. Take one first.
  • On a Friday evening, if nobody can fix a problem over the weekend.
  • When you cannot test the result and the site is important.

How to explain updates to someone else

If you report to a manager or a client, keep it simple: what was updated, why it matters, what was checked and whether anything needs a decision. A short note is more useful than a long list of version numbers.

Preparing a staging copy

A useful staging copy is a recent clone of the site, not an old one. It needs the files, the database and the same theme and plugin versions. It should not send real emails or take real payments, so check that email and payment settings are in test mode. After testing, remember that changes made on staging do not appear on the live site unless you repeat them or release the staging copy.

Rolling back in more detail

  1. Stop. Note the time and exactly what changed.
  2. Deactivate the plugin you updated last, and test the site.
  3. If the site recovers, roll that plugin back to its previous version, or leave it off while you find a fix.
  4. If it does not recover, restore the files and the database from the backup taken before the update.
  5. Test again, and only then put the site back in service.

The first day after an update

  • Look at your form submissions and order emails for anything unusual.
  • Watch your uptime and error alerts.
  • Ask whoever uses the site daily whether anything feels different.

A word on the PHP version

WordPress sites run on a version of PHP chosen by the host. Old versions stop receiving security fixes. Moving to a newer one can break old plugins, so test it on a staging copy first, and do it as a separate step from your regular updates.

Get the one-page version

Print the routine as a single page and keep it next to your desk: the WordPress update checklist. To see how this fits into the rest of the work, read what we handle on a WordPress site.

Keep reading

Website care

How to Put a Shopify Store in Maintenance Mode

Shopify calls it private mode. Here are the exact steps to close your store, what visitors and search engines see while it is closed, how to open it again, and a safer way to make changes without closing at all.

Jul 22, 2026 · 6 min read

Add-ons

Add-ons you may find useful

Fixed-price add-ons, bought separately from a plan.

Security

WordPress Security Optimisation Service

One-time deep security hardening for your WordPress or WooCommerce website

$99 per site, one-time

Security

Website Firewall Hardening Service (WAF Setup)

One-time WAF setup on Cloudflare Pro that blocks attacks before they reach your website

$249 per site, one-time

Speed and search

WordPress Speed Optimisation Service

Faster pages on mobile and desktop: caching, image, database and render-blocking fixes, with a before and after PageSpee...

$149 per site, one-time

See all add-ons

Straight answers

Questions this article answers

In what order should I update WordPress?

Core first, then themes, then plugins, one group at a time. That way, if something breaks, you know which group caused it.

Should I update everything at once?

No. Batching everything into one click makes a problem hard to trace. Update in small groups and check after each.

Is it safe to update on a live site?

It carries a small risk. A recent backup makes it recoverable, and a staging copy removes most of the risk for busy sites and stores.

Website care for businesses in every country

This guide applies wherever your business is. Pick your country to see how we work with your time zone.

All countries and time zones

Want someone to look after your website?

Pick a plan and a real person takes over the updates, security and backups, with hours for the changes you ask for. Month to month, and a 30-day money-back guarantee.

  • From $99/mo with hours included
  • Month to month
  • 30-day money-back guarantee
From $99/mo · hours included See plans