WordPress plugin auto-updates: on or off for client sites?

By CompatNav · Published · Last reviewed · 2 min read

Short answer

On for small, low-risk plugins; off for the ones the site depends on. Since WordPress 5.5 you choose plugin by plugin. WordPress runs auto-updates twice a day and emails the site owner afterwards. That suits simple plugins with a good track record. Shop, booking, membership and page-builder plugins are better updated by hand, after a backup and a look at what changed, because a bad update there costs the client money.

How plugin auto-updates work

Since WordPress 5.5, administrators choose auto-updates plugin by plugin. The documentation: “For each plugin, there is an “Automatic update” column with an action link used to enable/disable auto-updates plugin by plugin.” (wordpress.org)

When they run: “By default WordPress runs auto-updates twice per day.” And afterwards, WordPress sends emails when “One or more plugins or themes successfully auto-updated” or “One or more plugins or themes failed to auto-update” (wordpress.org).

To see the setting of every plugin on a site at once:

Terminal · WP-CLI 2.12.0 on our test site (WordPress 7.1.2), 9 October 2026; real output

$ wp plugin auto-updates status --all
name	status
acme-booking	disabled
acme-slider	disabled
compatnav-pro	disabled
compatnav-php-upgrade-checker	disabled
hello-dolly	disabled

A mixed approach for client sites

PluginAuto-update?Why
Small, single-purpose, well maintainedOnLow risk, and security fixes arrive quickly
Security and backup pluginsOn, if well maintainedFixes matter most here
Shop, booking, membership, forms that take paymentsOffA broken update costs the client money; update after a backup and a test
Page builders and the themeOffBig changes affect every page
Plugins other plugins build on (add-ons depend on them)OffUpdate the base and its add-ons together
Custom or premium plugins without wordpress.org updatesn/aThey don’t auto-update through wordpress.org

The plugins left off go into your weekly routine: update them with WP-CLI, one by one, after a dry run.

What auto-updates don’t do

They install the new version; they don’t test it. A site can be broken for hours before anyone opens it. So, either way:

  • Read the emails, or make sure the administration address forwards to you.
  • Open the site after update days, or let monitoring tell you it’s down.
  • Watch the log: a new version can add notices or warnings without breaking anything visible.

Auto-updates also don’t touch PHP: the host sets the PHP version. An update can make a plugin ready for the next PHP version, or bring in code that won’t run there, which is why a quarterly check for the next version belongs in the maintenance checklist. If an update did break the site, here’s how to get it back.

Key takeaways

  • Since WordPress 5.5, auto-updates are switched on or off per plugin, on the Plugins screen.
  • WordPress runs them twice a day and emails the site owner about successes and failures.
  • Turn them on for small, well-maintained plugins; keep them off for plugins the site’s business depends on.
  • Auto-updates don’t test anything: check the site and the log after updates either way.
  • WP-CLI shows the auto-update status of every plugin in one command.

Frequently asked questions

Are WordPress auto-updates safe?

For most small plugins, yes. The risk is in large plugins that change a lot between versions, or that other plugins build on. Those are better updated by hand, after a backup.

Who gets the auto-update emails?

By default, the site’s administration email address. On a client site, make sure that’s an address someone reads, or that you’re told about failures.

Do auto-updates cover PHP?

No. They update plugins and themes; the PHP version is set by your host. A plugin auto-update can still make a site ready, or not ready, for the next PHP version, which is why a check for the next version belongs in the routine.

Check your own site before you upgrade

CompatNav is a free WordPress plugin. It reads the code of your plugins and themes on your own server and tells you, in plain words, what will break and what will only show notices on the PHP version you choose. It never changes your code. It can’t see problems that only appear while code runs with real data, so a quick check of your site after the upgrade still matters.

Get CompatNav on wordpress.org How it works

Sources

About the code examples: each output is the real output of the code shown, run with the official PHP builds, without a php.ini, with all errors reported and displayed. Only the file path was replaced by a neutral server path.