WP-CLI: update WordPress plugins safely, with real commands and output

By CompatNav · Published · Last reviewed · 3 min read

Short answer

wp plugin list shows what has an update, wp plugin update --all --dry-run shows what would be updated without changing anything, and wp plugin update <name> (or --all) installs the updates. After updating, wp plugin verify-checksums confirms the files match wordpress.org’s. Back up first, update one plugin at a time when it matters, and open the site afterwards: WP-CLI tells you the update installed, not that the site still works.

Every command on this page was run on our test site (WordPress 7.1.2, WP-CLI 2.12.0) on 9 October 2026; the outputs are copied as they came. To have something to update, we first installed an older version of Hello Dolly from wordpress.org.

1. See what has an update

Terminal · WP-CLI 2.12.0 on our test site (WordPress 7.1.2), 9 October 2026; real output

$ wp plugin list --fields=name,status,version,update,update_version
name	status	version	update	update_version
acme-booking	active	2.3.0	none
acme-slider	inactive	1.0.4	none
compatnav-pro	active	1.0.0	none
compatnav-php-upgrade-checker	active	1.2.0	none
hello-dolly	inactive	1.6	available	1.7.2

update says whether an update is available; update_version which one.

2. Dry run: what would change

Terminal · same site; real output

$ wp plugin update --all --dry-run
Available plugin updates:
name	status	version	update_version
hello-dolly	inactive	1.6	1.7.2

Nothing is installed. This is the list to read before you update: a major version jump on a plugin the site depends on is one to try on a staging copy first.

3. Update one plugin, or all

Terminal · same site; real output

$ wp plugin update hello-dolly
Downloading update from https://downloads.wordpress.org/plugin/hello-dolly.1.7.2.zip...
Unpacking the update...
Installing the latest version...
Removing the old version of the plugin...
Plugin updated successfully.
name	old_version	new_version	status
hello-dolly	1.6	1.7.2	Updated
Success: Updated 1 of 1 plugins.

wp plugin update --all does the same for every plugin with an update. For a site that earns money, update the important plugins one at a time and open the site between them: if something breaks, you know which update did it.

4. Verify the files

WP-CLI can compare plugin and WordPress files with the checksums wordpress.org publishes. The command “Verifies plugin files against WordPress.org’s checksums.” (developer.wordpress.org)

Terminal · same site; real output

$ wp plugin verify-checksums hello-dolly
Success: Verified 1 of 1 plugins.
$ wp core verify-checksums
Success: WordPress installation verifies against checksums.

It only works for plugins from wordpress.org; premium and custom plugins have no published checksums. It’s also a quick test during an audit of a new client’s site: changed core files are a red flag.

5. Check that the site still works

“Success” means the files were replaced. It doesn’t mean the pages, forms and checkout still work, or that nothing new appears in the log. Open the site, try what matters, and read the log. If an update broke something, this guide takes you through getting it back.

A safe routine

  1. Backup, and know how to restore it.
  2. wp plugin list and --dry-run: read what will change.
  3. Update the important plugins one by one, the rest with --all.
  4. verify-checksums for plugins from wordpress.org.
  5. Open the site, try the key pages and forms, read the log.

Key takeaways

  • wp plugin list --fields=name,status,version,update,update_version shows every plugin and its available update.
  • wp plugin update --all --dry-run lists what would be updated, without changing anything.
  • wp plugin update <name> updates one plugin; --all updates every plugin with an update.
  • wp plugin verify-checksums and wp core verify-checksums compare files with wordpress.org’s published checksums.
  • WP-CLI reports that the update installed, not that the site still works: open it, and check the log.

Frequently asked questions

Is it safe to run wp plugin update --all?

On a site with a tested backup, and after a dry run, usually yes. For plugins the site depends on (shop, booking, forms), update them one by one and check the site in between.

Can WP-CLI update premium plugins?

Only if the plugin hooks into WordPress’s update system with a valid licence; then it shows up in wp plugin list like any other. Otherwise update it the way its seller provides.

Can I roll back an update with WP-CLI?

For plugins from wordpress.org you can install a specific earlier version with wp plugin install <name> --version=<x> --force. Your backup is the safer way back.

Check your own site before you upgrade

CompatNav is a free WordPress plugin. It reads the code of your plugins and themes on your own server and tells you, in plain words, what will break and what will only show notices on the PHP version you choose. It never changes your code. It can’t see problems that only appear while code runs with real data, so a quick check of your site after the upgrade still matters.

Get CompatNav on wordpress.org How it works

Sources

About the code examples: each output is the real output of the code shown, run with the official PHP builds, without a php.ini, with all errors reported and displayed. Only the file path was replaced by a neutral server path.