Hacked, redirecting or showing a blank page? We clean and restore WordPress sites in 24 hours.

Get emergency help
WP Site Kept.
All guides

Maintenance

How often should you update WordPress plugins?

29 August 2026 · 6 min read

On this page

The two common answers are both wrong. "Immediately, always" breaks sites. "When I get round to it" gets them hacked. The useful answer depends on what kind of release it is.

The short version

  • Security releases: within 24–72 hours. No exceptions.
  • Everything else: weekly, in one batch.
  • Major version jumps: on staging first, whenever you can.

That is the whole policy. The rest of this explains why the first line is not negotiable and the third is not paranoia.

Why security releases cannot wait

A security release is not only a fix. It is an announcement.

When a plugin patches a vulnerability, the changelog and the disclosure tell everybody the flaw exists — including the people writing automated scanners. Within days, bots are sweeping the internet for the unpatched version. They are not looking for your site specifically; they are looking for a version number.

So the window between a patch shipping and mass exploitation is frequently measured in days. Updating in three days is fine. Updating in three months is how most hacked sites get hacked.

The practical problem is knowing which updates are security updates. WordPress does not tell you in the admin — everything looks identical. Options: read changelogs, subscribe to a vulnerability feed, or use something that watches for you.

Why everything else should wait a bit

Non-security updates carry the opposite risk. Occasionally a plugin ships a release that breaks something, and the developer patches it within a day or two once users report it.

Waiting a few days for feature releases costs you nothing and avoids being the person who finds the bug. Batching them weekly also means one testing pass instead of five, which is the real time saving.

Major versions deserve more care

A jump from 5.x to 6.x usually means changed behaviour, not just fixes. Page builders, form plugins and anything touching WooCommerce checkout are the ones that bite.

For those: staging first if you have it, backup always, and read the changelog for the words "breaking", "removed" or "requires".

If you run WooCommerce, treat every update as a major one. A broken checkout is silent — the site looks fine and orders simply stop. More on that here.

The weekly routine that works

  1. Back up — before, not after
  2. Update core first, then plugins, then themes
  3. Load your key pages — homepage, a service or product page, contact form, checkout
  4. Submit the contact form — WordPress email breaks silently and often
  5. Roll back immediately if anything looks wrong, then investigate

Fifteen to thirty minutes for most sites. The checking afterwards is the part people skip, and it is the part that turns "we updated" into "we know it still works".

When not to update

  • The week before your busy season. Black Friday, your annual sale, a launch. The risk is asymmetric: a small improvement against a lost trading day.
  • On a Friday afternoon, unless you plan to be around.
  • When the plugin is abandoned. If it has not been updated in over a year there is nothing to install, and that is its own problem — replace it.

Auto-updates: yes, but selectively

WordPress can update plugins automatically, and for simple, well-maintained, low-risk plugins that is genuinely better than a human who forgets.

Turn them on for: small utility plugins, anything from a developer with a good track record, and WordPress core security releases.

Leave them off for: page builders, WooCommerce and its extensions, anything with custom code depending on it, and anything that has broken your site before.

The danger of blanket auto-updates is not that they update — it is that nothing checks the site afterwards. An automatic update that breaks your checkout at 2am is worse than a manual one you tested.

What this costs you

Done properly, half an hour a week, every week, forever. It is not difficult work. It is work that reliably does not get done, because nobody feels the benefit of a plugin updated on time.

That is what our care plans are for — the same routine above, run weekly by someone whose job it is, with the site checked afterwards and rolled back if anything moves. From $79 a month.

Share this

Would rather not do it yourself?

We keep WordPress sites updated, backed up and fixed.

Weekly updates with a backup taken first and the site checked afterwards, daily off-site backups, malware monitoring with free cleanup, and engineers who answer. From $79 a month, covered within 24 hours.