Knowledge base

Keeping WordPress updated across every site

Where to see versions and vulnerabilities for the whole estate, and how updates are made safe.

The WordPress screen lists every WordPress site you host with its core, plugin and theme versions, and flags anything with a known vulnerability.

Updating

Select the sites and apply. Before each update we take a backup, and after it we check the site still answers. If it does not, the update is rolled back and you are told which site and which plugin — you do not find out from a customer.

Automatic or manual

Both, per site. Security releases of core can be left automatic with very little risk; major plugin versions are worth doing deliberately, in a batch you are watching. The screen lets you set that per site rather than forcing one policy on the estate.

Vulnerabilities

A flagged plugin is one with a published advisory against the version installed. That is a statement about the version, not about whether you have been attacked. Update it, and if no update exists, the honest options are to replace the plugin or to accept the risk knowingly — we will tell you which sites are affected either way.

Staging first, for the ones that matter

For a shop or anything else where an hour of breakage costs money, promote through staging instead. Sites → your site → Staging, update there, click round, promote.

The screen that matters most here is the vulnerability list, not the update count. A site three minor versions behind is untidy; a site with an exploitable plugin is a problem.

Still stuck?

Support is included on every plan and answers in your own language.

Contact support All articles
Keeping WordPress updated across every site