WP-CLI: update WordPress plugins safely, with real commands and output
Short answer
wp plugin list shows what has an update, wp plugin update --all --dry-run shows what would be updated without changing anything, and wp plugin update <name> (or --all) installs the updates. After updating, wp plugin verify-checksums confirms the files match wordpress.org’s. Back up first, update one plugin at a time when it matters, and open the site afterwards: WP-CLI tells you the update installed, not that the site still works.
Every command on this page was run on our test site (WordPress 7.1.2, WP-CLI 2.12.0) on 9 October 2026; the outputs are copied as they came. To have something to update, we first installed an older version of Hello Dolly from wordpress.org.
1. See what has an update
Terminal · WP-CLI 2.12.0 on our test site (WordPress 7.1.2), 9 October 2026; real output
$ wp plugin list --fields=name,status,version,update,update_version
name status version update update_version
acme-booking active 2.3.0 none
acme-slider inactive 1.0.4 none
compatnav-pro active 1.0.0 none
compatnav-php-upgrade-checker active 1.2.0 none
hello-dolly inactive 1.6 available 1.7.2update says whether an update is available; update_version which one.
2. Dry run: what would change
Terminal · same site; real output
$ wp plugin update --all --dry-run
Available plugin updates:
name status version update_version
hello-dolly inactive 1.6 1.7.2Nothing is installed. This is the list to read before you update: a major version jump on a plugin the site depends on is one to try on a staging copy first.
3. Update one plugin, or all
Terminal · same site; real output
$ wp plugin update hello-dolly
Downloading update from https://downloads.wordpress.org/plugin/hello-dolly.1.7.2.zip...
Unpacking the update...
Installing the latest version...
Removing the old version of the plugin...
Plugin updated successfully.
name old_version new_version status
hello-dolly 1.6 1.7.2 Updated
Success: Updated 1 of 1 plugins.wp plugin update --all does the same for every plugin with an update. For a site that earns money, update the important plugins one at a time and open the site between them: if something breaks, you know which update did it.
4. Verify the files
WP-CLI can compare plugin and WordPress files with the checksums wordpress.org publishes. The command “Verifies plugin files against WordPress.org’s checksums.” (developer.wordpress.org)
Terminal · same site; real output
$ wp plugin verify-checksums hello-dolly
Success: Verified 1 of 1 plugins.
$ wp core verify-checksums
Success: WordPress installation verifies against checksums.It only works for plugins from wordpress.org; premium and custom plugins have no published checksums. It’s also a quick test during an audit of a new client’s site: changed core files are a red flag.
5. Check that the site still works
“Success” means the files were replaced. It doesn’t mean the pages, forms and checkout still work, or that nothing new appears in the log. Open the site, try what matters, and read the log. If an update broke something, this guide takes you through getting it back.
A safe routine
- Backup, and know how to restore it.
wp plugin listand--dry-run: read what will change.- Update the important plugins one by one, the rest with
--all. verify-checksumsfor plugins from wordpress.org.- Open the site, try the key pages and forms, read the log.
Key takeaways
wp plugin list --fields=name,status,version,update,update_versionshows every plugin and its available update.wp plugin update --all --dry-runlists what would be updated, without changing anything.wp plugin update <name>updates one plugin;--allupdates every plugin with an update.wp plugin verify-checksumsandwp core verify-checksumscompare files with wordpress.org’s published checksums.- WP-CLI reports that the update installed, not that the site still works: open it, and check the log.
Frequently asked questions
Is it safe to run wp plugin update --all?
On a site with a tested backup, and after a dry run, usually yes. For plugins the site depends on (shop, booking, forms), update them one by one and check the site in between.
Can WP-CLI update premium plugins?
Only if the plugin hooks into WordPress’s update system with a valid licence; then it shows up in wp plugin list like any other. Otherwise update it the way its seller provides.
Can I roll back an update with WP-CLI?
For plugins from wordpress.org you can install a specific earlier version with wp plugin install <name> --version=<x> --force. Your backup is the safer way back.
Check your own site before you upgrade
CompatNav is a free WordPress plugin. It reads the code of your plugins and themes on your own server and tells you, in plain words, what will break and what will only show notices on the PHP version you choose. It never changes your code. It can’t see problems that only appear while code runs with real data, so a quick check of your site after the upgrade still matters.
Sources
About the code examples: each output is the real output of the code shown, run with the official PHP builds, without a php.ini, with all errors reported and displayed. Only the file path was replaced by a neutral server path.