WordPress plugin auto-updates: on or off for client sites?
Short answer
On for small, low-risk plugins; off for the ones the site depends on. Since WordPress 5.5 you choose plugin by plugin. WordPress runs auto-updates twice a day and emails the site owner afterwards. That suits simple plugins with a good track record. Shop, booking, membership and page-builder plugins are better updated by hand, after a backup and a look at what changed, because a bad update there costs the client money.
How plugin auto-updates work
Since WordPress 5.5, administrators choose auto-updates plugin by plugin. The documentation: “For each plugin, there is an “Automatic update” column with an action link used to enable/disable auto-updates plugin by plugin.” (wordpress.org)
When they run: “By default WordPress runs auto-updates twice per day.” And afterwards, WordPress sends emails when “One or more plugins or themes successfully auto-updated” or “One or more plugins or themes failed to auto-update” (wordpress.org).
To see the setting of every plugin on a site at once:
Terminal · WP-CLI 2.12.0 on our test site (WordPress 7.1.2), 9 October 2026; real output
$ wp plugin auto-updates status --all
name status
acme-booking disabled
acme-slider disabled
compatnav-pro disabled
compatnav-php-upgrade-checker disabled
hello-dolly disabledA mixed approach for client sites
| Plugin | Auto-update? | Why |
|---|---|---|
| Small, single-purpose, well maintained | On | Low risk, and security fixes arrive quickly |
| Security and backup plugins | On, if well maintained | Fixes matter most here |
| Shop, booking, membership, forms that take payments | Off | A broken update costs the client money; update after a backup and a test |
| Page builders and the theme | Off | Big changes affect every page |
| Plugins other plugins build on (add-ons depend on them) | Off | Update the base and its add-ons together |
| Custom or premium plugins without wordpress.org updates | n/a | They don’t auto-update through wordpress.org |
The plugins left off go into your weekly routine: update them with WP-CLI, one by one, after a dry run.
What auto-updates don’t do
They install the new version; they don’t test it. A site can be broken for hours before anyone opens it. So, either way:
- Read the emails, or make sure the administration address forwards to you.
- Open the site after update days, or let monitoring tell you it’s down.
- Watch the log: a new version can add notices or warnings without breaking anything visible.
Auto-updates also don’t touch PHP: the host sets the PHP version. An update can make a plugin ready for the next PHP version, or bring in code that won’t run there, which is why a quarterly check for the next version belongs in the maintenance checklist. If an update did break the site, here’s how to get it back.
Key takeaways
- Since WordPress 5.5, auto-updates are switched on or off per plugin, on the Plugins screen.
- WordPress runs them twice a day and emails the site owner about successes and failures.
- Turn them on for small, well-maintained plugins; keep them off for plugins the site’s business depends on.
- Auto-updates don’t test anything: check the site and the log after updates either way.
- WP-CLI shows the auto-update status of every plugin in one command.
Frequently asked questions
Are WordPress auto-updates safe?
For most small plugins, yes. The risk is in large plugins that change a lot between versions, or that other plugins build on. Those are better updated by hand, after a backup.
Who gets the auto-update emails?
By default, the site’s administration email address. On a client site, make sure that’s an address someone reads, or that you’re told about failures.
Do auto-updates cover PHP?
No. They update plugins and themes; the PHP version is set by your host. A plugin auto-update can still make a site ready, or not ready, for the next PHP version, which is why a check for the next version belongs in the routine.
Check your own site before you upgrade
CompatNav is a free WordPress plugin. It reads the code of your plugins and themes on your own server and tells you, in plain words, what will break and what will only show notices on the PHP version you choose. It never changes your code. It can’t see problems that only appear while code runs with real data, so a quick check of your site after the upgrade still matters.
Sources
About the code examples: each output is the real output of the code shown, run with the official PHP builds, without a php.ini, with all errors reported and displayed. Only the file path was replaced by a neutral server path.