This website uses cookies

Our website, platform and/or any sub domains use cookies to understand how you use our services, and to improve both your experience and our marketing relevance.

Cloudways Velocity is here. Deploy Node.js apps on managed, predictable infrastructure. Start Hosting Now →

WordPress Automatic Updates: How to Enable, Disable & Manage in 2026 (Detailed Guide)

Updated on September 15, 2026

15 Min Read

Key Takeaways

  • WordPress auto-updates minor releases by default. Major core, plugin, and theme updates require manual opt-in.
  • WordPress 6.6 added native rollback for failed plugin updates, but it only covers PHP fatal errors on the homepage.
  • Auto-updates work well for simple sites. WooCommerce stores, custom-coded sites, and agencies need a more careful approach.
  • Cloudways Site Manager automates multi-site management, updates with backups, staging, Visual Regression Testing (VRT), and automatic rollbacks.

Over 43% of all websites are powered by WordPress (W3Techs). That scale also makes it the #1 target for attacks. Outdated plugins, themes, and core files are among the most exploited entry points.

So, keeping your WordPress site updated is no longer optional. It’s a necessity. And manually going through every update isn’t the most efficient use of your time.

Updating WordPress sites was a hassle with older versions, but with the release of WordPress 3.7, automatic updates for security releases and other minor amendments have become standard. However, not everything is auto-updated by default. Major releases, plugins, and themes all require manual opt-in or configuration.

WordPress has also gotten better at handling failed updates. But as we’ll cover in this guide, native rollback still has real limits that every site owner should know about.

If you’re on Cloudways, Site Manager provides a centralized dashboard to automate the entire update process for you. More on that later.

Host WordPress Where Updates Don’t Break Your Site

Cloudways gives you managed WordPress hosting with built-in tools to keep your site fast, secure, and up to date.

What Are Automatic Updates in WordPress?

WordPress 3.7 introduced automatic updates to improve security and ease site administration. These automatic updates are enabled for all minor releases, keeping maintenance and security releases up to date without any manual involvement.

Automatic updates are enabled on most sites by default, but the level of control you have over them is much wider than most people realize.

Different Types of WordPress Automatic Updates

WordPress automatic updates are mainly divided into four types:

Core updates contain the core WordPress files. These break down into three sub-types:

  • Core development updates are only available on development or beta installations, not on live sites.
  • Minor core updates cover security patches and maintenance fixes. These are enabled by default on most WordPress installations.
  • Major core updates cover new WordPress versions and features, like moving from 6.8 to 6.9. These are not enabled by default and require a manual opt-in.

Plugin updates cover bug fixes, improvements, and new features for your installed plugins. Not auto-updated by default.

Theme updates cover changes and fixes to your installed themes. Not auto-updated by default.

Translation file updates keep your WordPress language files current. These are auto-updated by default and are low-risk since they don’t touch any core functionality.

How to Manage WordPress Automatic Updates (4 Methods)

You can manage WordPress automatic updates in several ways. The four methods below cover everything from a simple dashboard toggle to code-level control for developers. If any of the methods involve code, it’s included directly so you can copy it without needing to look it up.

Method 1: Using the WordPress Dashboard

You can directly manage WordPress automatic updates from the WP-admin dashboard. WordPress minor updates (security and maintenance releases) are enabled by default, and you can’t disable them from the dashboard. However, you may enable updates for major releases by following the steps below:

1. Go to your WordPress Dashboard > Updates.

WordPress admin sidebar menu with a red box highlighting the Updates link and a red notification bubble indicating 11 pending updates

Note that this menu item only appears in the sidebar when updates are available. Here you’ll see pending updates for Core, Plugins, and Themes.

2. Click on the Switch to Automatic Updates for Maintenance and Security Releases Only link to enable major updates.

WordPress dashboard core update information status text page showing version 6.9.4 with a red arrow pointing to the switch to automatic updates for maintenance and security releases only link

3. You’ll see the following message: “WordPress will only receive automatic security and maintenance releases from now on.”

WordPress admin notification banner with a green vertical status indicator bar stating that WordPress will only receive automatic security and maintenance releases from now on.

4. Next, click the Enable Automatic Updates for All New Versions of WordPress link. You will see a message notifying you that the automatic updates have been enabled.

WordPress dashboard updates screen showing current version 6.9.4 with a red arrow pointing to the link to enable automatic updates for all new versions of WordPress.

Enabling Auto-Updates for Individual Plugins

WordPress 5.5 made this even easier. You can now enable auto-updates for individual plugins directly from the dashboard without touching any code.

1. Go to Dashboard > Plugins > Installed Plugins.

WordPress navigation sidebar menu with red rectangular highlights over the primary Plugins menu item showing 10 updates available and the flyout Installed Plugins link.

2. You’ll see an Automatic Updates column next to each plugin. If you don’t see it, click Screen Options at the top right of the page and enable it.

WordPress plugins list screen showing red outline boxes highlighting the individual enable auto-updates option links next to plugins like AI Engine and Akismet.

One thing to keep in mind though: don’t turn this on for every plugin at once. For plugins that affect your checkout, layout, or database, it’s better to update them manually or use Site Manager’s Safe Update mode so everything gets tested before going live.

Enabling Auto-Updates for Individual Themes

The same thing works for themes.

Go to Appearance > Themes, click on any theme, and you’ll see the Enable Auto-Updates option in the detail panel.

WordPress appearance theme details window showcasing the default Twenty Twenty-Five theme preview panel with a red box outlining the Enable auto-updates hyperlink text.

Method 2: Using the wp-config.php File

You can also manage WordPress updates using the wp-config.php file. However, you must be extra careful and correctly include the line of code. You can use FileZilla FTP Client to access the wp-config.php file. Follow the steps below:

1. Access your WordPress site’s files via FileZilla.

2. Open the public_html folder.

FileZilla FTP client interface on a desktop computer with a red arrow pointing to the public_html directory on the remote site panel.

3. Click on the wp-config.php file and download it.

Directory view within the FileZilla file transfer program looking inside the public_html path with red arrows pointing to the folder tree and the selected wp-config.php core web file.

4. Add the relevant line of code just before the /* That's all, stop editing! Happy blogging. */ line.

To enable all core updates including major releases:

define( 'WP_AUTO_UPDATE_CORE', true );

To enable minor updates only (default behavior):

define( 'WP_AUTO_UPDATE_CORE', 'minor' );

To disable all core auto-updates:

define( 'WP_AUTO_UPDATE_CORE', false );

Save the changes and re-upload the wp-config.php file to your public_html folder.

Note: The wp-config.php file is among your site’s primary and critical core files containing database connections and passwords. Even a single change can crash your site, so be careful when editing.

Method 3: Using API Filters

Another method to enable WordPress automatic updates, useful for developers, is via API filters. WordPress provides several filters that let users control the updates.

We can automate the core, plugins, themes, and translation files by returning true through the auto_update_core, auto_update_theme, auto_update_plugin, and auto_update_translation filters.

The best practice is to add the API filters in the Must-Use plugin folder, located in public_html > wp-content. These plugins do not appear on the WordPress Plugins screen, so they can’t be accidentally disabled or removed by site admins.

Here’s a look at the filters:

To disable all automatic updates:

add_filter( 'automatic_updater_disabled', '__return_true' );

To enable automatic core updates:

add_filter( 'auto_update_core', '__return_true' );

To enable automatic plugin updates:

add_filter( 'auto_update_plugin', '__return_true' );

To enable automatic theme updates:

add_filter( 'auto_update_theme', '__return_true' );

If you want to auto-update only specific plugins rather than all of them, you can do that too. Add this to your must-use plugin file and replace the slugs with the folder names of the plugins you want to target:

function my_selective_plugin_updates( $update, $item ) {
$plugins = array( 'akismet', 'wordfence' );
if ( in_array( $item->slug, $plugins ) ) {
return true;
}
return $update;
}
add_filter( 'auto_update_plugin', 'my_selective_plugin_updates', 10, 2 );

Method 4: Using Plugins

If you’d rather not touch any code, plugins are the easiest way to manage auto-updates. Easy Updates Manager is the most popular option for this, with over 700,000 active installs.

  • Install and activate the Easy Updates Manager plugin on your WordPress website.

WordPress plugin search results directory showing the Easy Updates Manager card with a red box highlighting its blue Activate button next to a File Manager plugin block.

  • Once activated, you’ll see the Updates Options menu in your admin bar.

WordPress admin bar dropdown menu under Updates showing options for General, Plugins, Themes, Logs, Advanced, and Premium.

  • From here, you can configure automatic WordPress updates for your site’s core, plugins, and themes individually.

WordPress plugin update options manager page showing settings to allow or block updates for individual plugins like AI Engine, Akismet Anti-spam, and Better Search Replace.

Easy Updates Manager lets you disable and enable all updates with one click.

You can also deeply customize your update settings, configure email notifications, and a lot more.

What Happens When a WordPress Auto-Update Fails?

Setting up auto-updates is the easy part. Knowing what happens when one goes wrong is just as important.

WordPress 6.6’s Built-In Rollback

WordPress 6.6 (July 2024) added automatic rollback for plugin auto-updates that trigger a PHP fatal error on the front page (WordPress.org). Before 6.6, this safety check only existed for manual plugin updates, introduced in WordPress 6.3. Now it covers automatic updates too.

When a plugin update causes a fatal error, WordPress rolls it back automatically and emails the site admin with the details.

What the Native Rollback Doesn’t Cover

Native rollback is a step forward, but it has real limits. It only checks for PHP fatal errors on the homepage. It won’t catch:

  • A broken layout or visual shift
  • A JavaScript error
  • A WooCommerce checkout failure
  • Issues on inner pages or in the admin area
  • A drop in page speed

Auto-updates also run via WordPress Cron, which fires roughly every 12 hours. So an update could go live at 2am, and if something breaks that isn’t a PHP fatal error, it may sit unnoticed until morning.

Worried About Updates Breaking Your Site?

Site Manager tests every update in a staging environment before it touches your live site.

Should You Enable WordPress Automatic Updates?

Sure, auto-updates save you time and keep your WordPress site secure, but they’re not a one-size-fits-all answer. And enabling them depends fully on the kind of site you’re running.

When to Enable Auto-Updates

On most standard WordPress installations, all minor core updates and security patches are auto-updated by default. And the risk of NOT patching a known vulnerability is higher than the risk of a minor update breaking something.

If you own a simple site like a blog, a portfolio, or a brochure site with few plugins and no custom code, your site is a good candidate for full auto-updates.

And if you don’t have time for regular manual maintenance, auto-updates are better than letting your site go weeks without updates.

Patchstack revealed that 50% of critical WordPress vulnerabilities are actively exploited within 24 hours of public disclosure (Patchstack). So never delay your updates.

When to Be Cautious

There are situations where enabling auto-updates can backfire. Avoid them if you own a WooCommerce store or any site with a checkout flow. Because a plugin auto-update may break your payment page, go unnoticed for hours, and cost you real money.

Also be cautious if your site has multiple interconnected plugins. When multiple plugins update simultaneously and something breaks, figuring out which one caused it becomes a real struggle.

Have a site with custom code or a custom theme? Plugin auto-updates don’t always play well with custom-built functionality.

For agencies managing client sites, if an update breaks a client site at 3am and nobody notices until morning, that’s a support problem.

Finally, it doesn’t work well for developers who need to review changelogs before applying updates, especially for plugins that touch the database or affect user data.

The point isn’t to scare you away from auto-updates. It’s to help you make the right call for your specific situation. And if you want the best of both worlds, automated updates that are also tested before going live, that’s exactly what Site Manager does.

How to Disable WordPress Automatic Updates

Even though auto-updates are great for security, there are valid reasons to disable them. If your site has custom code, complex plugins, or a checkout flow you can’t afford to break, taking manual control makes sense. You can do it in two ways.

Disabling Automatic WordPress Updates Using Code

Earlier, I demonstrated using the wp-config.php file to activate automatic updates. You can disable them using the same steps and making the code changes below:

define( 'WP_AUTO_UPDATE_CORE', false );

You can also disable updates using filters. To disable theme and plugin updates, add the following filters in your theme’s functions.php file:

add_filter( 'auto_update_theme', '__return_false' );
add_filter( 'auto_update_plugin', '__return_false' );

Disabling Automatic WordPress Updates Using a Plugin

Another way to disable automatic WordPress updates is by using a plugin. You can use the same Easy Updates Manager plugin used earlier to automate updates.

  1. Go to Dashboard > Updates Options > General
  2. Choose the Disable All Updates option

General settings tab of Easy Updates Manager outlined with a red box, showing a master switch section with a red box highlighting the white Disable all updates button.

Note: It is not recommended to disable all updates permanently. Outdated plugins and themes are among the leading causes of WordPress security issues. Instead, explore each option individually, like WordPress core updates, plugin updates, and theme updates, and configure each one accordingly.

Want Updates Without the Risk?

Site Manager handles backups, testing, and rollbacks automatically. No manual work needed.

Cloudways Site Manager — Centralized WordPress Management & Updates

Tired of manually updating multiple WordPress sites and want a centralized system that performs bulk operations free of risks? Cloudways Site Manager is the answer.

Hero banner for Cloudways Site Manager: 'Your WordPress, Managed in One Place' with a right-side dashboard mockup

Site Manager provides a centralized dashboard to automate WordPress maintenance, multi-site updates, and monitoring. You can use the Basic plan for free, or upgrade to the Pro plan for Visual Regression Testing and automated Safe Updates starting at $3/month per app (up to 5 apps), dropping to $2/month for 6 or more.

How Does Site Manager’s Safe Update Process Work?

Using Site Manager’s Pro plan, it actively monitors your WordPress applications to detect updates. When Safe Updates are triggered, Site Manager follows the steps below to ensure updates are bug-free:

  1. It takes your app’s backup for rolling back if the updates are aborted.
  2. It creates a staging application temporarily and executes the updates in the staging environment.
  3. It takes a snapshot of your staging environment and performs unit testing, HTML checks, browser console monitoring, and network error detection to ensure the application works fine.
  4. Once updates are completed, Site Manager takes a snapshot and performs unit testing.
  5. It compares the before and after screenshots using proprietary Visual Regression Testing (VRT) algorithms.
  6. Once the testing is successful, Site Manager updates the production application.

Why Should We Use Site Manager?

Using Site Manager for your WordPress and WooCommerce sites offers massive time savings and centralized control:

  • Saves you from the manual hassles of updating everything on your WordPress site. All you need is a few clicks.
  • It has been tested on more than 100 top WordPress plugins.
  • Automatically creates your site’s backup for rolling back if you’re not happy with the updates.
  • Updating the core, themes, and plugins gives your site the much-needed performance boosts.
  • Takes care of bug fixes, preventing hackers from exploiting vulnerabilities in older versions.
  • Saves you a lot of time and risk via automation.
  • Agencies and developers report saving over 42 hours of WordPress maintenance every month using Site Manager’s bulk operations.
  • Offers a risk-free way to update your website.

How to Automate Your WordPress Updates via Site Manager

Activating and configuring Site Manager is a breeze. Here’s how you can automate your WordPress updates via Site Manager in minutes.

Activating Site Manager

  • Log in to the Cloudways Platform using your credentials.
  • From the home screen, hover over Integrations and then click Site Manager.

Cloudways dashboard: left menu shows Integrations; Site Manager card highlighted in the main panel.

  • Click on Get Started Free button.

Site Manager product page hero with a blue 'Get Started Free' button and supporting text on the left; right shows a soft illustration graphic.

  • Select WordPress apps to add to Site Manager.

Step 1 of 2: Select Applications. WordPress Application is selected; there’s a search field labeled 'Search Applications...' and a note about excluding staging apps and stopped servers.

  • Choose Site Manager Free or Pro plan and then enable it.

Plan selection screen comparing Basic (Free) and Pro ($3/app/month) WordPress plans, with Pro highlighted as recommended.

  • Once Site Manager is activated, you can manage it via the centralized dashboard to configure update schedules and on-demand actions.

Site Manager dashboard showing WordPress Application on Pro plan with 0 updates and 100% performance.

Configuring Site Manager

Site Manager simplifies your workflow with a centralized dashboard. You can manually push pending updates or set up fully automated schedules tailored to your risk tolerance.

Manage Updates

The Manage Updates tab gives you a real-time overview of your application’s status and allows you to push updates manually if needed.

  • Select your application on the Cloudways Platform and click Site Manager.
  • Navigate to the Manage Updates tab.
  • If your site is fully current, you will see a “You’re All Up to Date!” message. If there are pending updates for your core, themes, or plugins, you can select and apply them directly from this screen.

Status screen showing 'You're All Up to Date!' with a small illustration and the message 'No pending updates. You're running the latest versions of everything.'

Auto Updates (Scheduled)
  • Scheduling your application updates removes the hassle of manually triggering anything, which is where Site Manager really shines.
  • Navigate to the Auto Updates tab in Site Manager.

Site Manager Auto Updates page with no schedule; illustration of a document and clouds, and a blue 'Set Auto Update Schedule' button.

  • Click the Set Auto Update Schedule button.
  • Under Set Auto Update Schedule, choose your Update Frequency (e.g., Weekly), Day of Week, and Schedule Time (in UTC).

UI for Set Auto Update Schedule: choose Weekly updates, Friday, 00:00–05:59 UTC, with WordPress Application selected.

  • Select the applications you want this specific schedule to apply to.
  • In the Configure Update List section, select exactly what you want to automate: WordPress Core, specific Plugins, and specific Themes.

UI for creating an auto-update schedule: sections to configure update lists with checkboxes for WordPress Core, Plugins (multiple plugins selected), and Themes (multiple themes selected); a Quick Update option selected in the Update Type dropdown; Critical Updates toggle enabled.

  • Choose your Update Type. You can select Quick Update (faster, but no backups or compatibility checks) or Safe Update (creates a backup, tests in staging, and uses Visual Regression Testing).

UI for creating an auto-update schedule: sections to select WordPress Core, Plugins, and Themes with multiple plugins listed, and a Update Type dropdown showing Quick Update and Safe Update options; a Set AutoUpdate Schedule button at bottom.

  • If you select Safe Update, you can customize the Visual Regression Sensitivity (Critical, Standard, or Low) depending on how strict you want the visual check to be.
  • You can also enable Smart Skip for Plugin/Theme Update Failures so that if one plugin fails, the rest of the queue still updates safely.

Auto-update schedule settings: Core, Plugins, and Themes selected; Update Type: Safe Update; Visual Regression and critical update toggles visible; Set AutoUpdate Schedule.

  • Toggle Critical Updates on to automatically push vulnerability patches for WordPress core, themes, and plugins to safeguard your site from potential exploits.
  • Click the Set AutoUpdate Schedule button at the bottom right to save your configuration.

Viewing Update History

The History tab displays the full history of updates, both successful and aborted, executed via Site Manager. It’s a quick way to stay on top of what’s been updated and catch anything that needs attention.

History page for Site Manager showing no history yet; logs appear after automatic or scheduled updates.

How to Deactivate Site Manager

You can deactivate Site Manager via the Cloudways Platform at any point.

  • Click your Application on the Cloudways Platform.
  • Click Site Manager > Go to Dashboard.

Screenshot of a web app admin dashboard: left navigation menu with items, and a highlighted 'Go to Dashboard' button at bottom left; main area shows Overview and App Summary panels.

  • Select your application, click on three dost and click Manage plan.

Screenshot of Site Manager overview showing the Actions menu with 'Manage Plan' highlighted (WordPress app icon, 'Site Manager' header, and plan details).

  • Next, simply click Unsubscribe.

Manage Plan dialog showing Free plan on the left and Pro plan on the right, with feature lists and a highlighted Unsubscribe action.

  • You’ll see a notification that Site Manager has been unsubscribed.

Success notification: You have unsubscribed from the Site Manager Plan in WordPress Application with a green check icon.

Start Automating Your WordPress Updates

Centralized, tested, and automated. Site Manager Pro keeps your sites up to date for as low as $2/month (plus a free Basic tier).

Pros and Cons of WordPress Auto-Updates

Pros Cons
Keeps your site protected against known vulnerabilities without manual effort Updates can conflict with existing plugins, themes, or custom code
Reduces workload, especially for anyone managing multiple sites When multiple plugins update at once, identifying what broke becomes harder
Security patches are applied as soon as they’re available Native rollback only catches PHP fatal errors, not visual or functional breakage
Saves time Auto-updates run on a schedule, so breakage can go unnoticed for hours
Keeps your site relevant with the latest performance improvements Risk of data loss if a backup isn’t in place before updates run

Final Thoughts

You must keep your sites updated to remain protected against threats. Ever since the release of WordPress 6.6, automatic updates have improved significantly. However, native auto-updates still have many gaps, and any site that’s not a simple blog needs more than just a rollback for PHP fatal errors.

And manually updating plugins, themes, and core isn’t really practical. But centralized tools like Cloudways Site Manager make the job a lot easier, requiring minimal to no manual intervention. It gives you backups, staging, VRT, rollbacks, on-demand and automatic updates, and a lot more.

So, if you want to remain carefree about your site’s updates, an automated tool is the way to go. Use your time doing other things that actually drive your business.

Q1: Does WordPress have automatic updates?

Yes. WordPress automatically installs new minor releases on your site to improve security. However, you need to manually opt in for major core updates, and individual plugin and theme auto-updates are off by default.

Q2: What is the WordPress auto-update rollback feature?

Introduced in WordPress 6.6, the auto-update rollback automatically reverts a plugin to its previous version if an update triggers a PHP fatal error on the front page. It also sends the site admin an email with the details. Keep in mind it only catches PHP fatal errors on the homepage and won’t detect broken layouts, JavaScript errors, or WooCommerce checkout failures.

Q3: How do I stop WordPress from automatically updating?

You can stop WordPress auto-updates by adding the following code to your wp-config.php file:

define( 'WP_AUTO_UPDATE_CORE', false );

You can also use a plugin like Easy Updates Manager to disable automatic updates without touching any code.

Q4: How often should WordPress be updated?

Security and minor updates should be applied as soon as they’re available. Given that 50% of critical WordPress vulnerabilities are actively exploited within 24 hours of disclosure, delays carry real risk. For major core updates, test in a staging environment first before pushing to production.

Q5: How do you check for WordPress updates?

Go to your WordPress Dashboard > Updates. You’ll see all available updates for core, plugins, and themes. You can also click the Check Again button to manually trigger a check.

Q6: Should I enable auto-updates on WordPress?

For most sites, yes. But the right answer depends on your site. Simple blogs and informational sites are good candidates for full auto-updates. For WooCommerce stores, sites with custom code, or anyone managing multiple client sites, it’s worth pairing auto-updates with a tested deployment process using Site Manager’s Safe Updates.

Q7: What is Cloudways Site Manager?

Site Manager is a centralized WordPress management tool on Cloudways. Beyond bulk plugin/theme management, its Pro tier automates updates with a full safety workflow: it backs up your site, runs updates in a staging environment, performs Visual Regression Testing, and deploys to production only if everything passes. The Basic tier is free, while the Pro tier starts at $3/month per app.

Q8: Does Site Manager work with premium plugins?

Yes. Site Manager works with all free plugins

Q9: Is Site Manager available on Cloudways Autonomous?

Site Manager is currently available on Cloudways Flexible plans.

Share your opinion in the comment section. COMMENT NOW

Share This Article

[email protected]

Sarim Javaid is a Sr. Content Marketing Manager at Cloudways, where his role involves shaping compelling narratives and strategic content. Skilled at crafting cohesive stories from a flurry of ideas, Sarim's writing is driven by curiosity and a deep fascination with Google's evolving algorithms. Beyond the professional sphere, he's a music and art admirer and an overly-excited person.

×

Webinar: How to Get 100% Scores on Core Web Vitals

Join Joe Williams & Aleksandar Savkovic on 29th of March, 2021.

Do you like what you read?

Get the Latest Updates

Share Your Feedback

Please insert Content

Thank you for your feedback!

Do you like what you read?

Get the Latest Updates

Share Your Feedback

Please insert Content

Thank you for your feedback!

Want to Experience the Cloudways Platform in Its Full Glory?

Take a FREE guided tour of Cloudways and see for yourself how easily you can manage your server & apps on the leading cloud-hosting platform.

Start my tour