Automatic updates were introduced to WordPress with the 3.7 Basie release, but the debate about them has been re-ignited as they recently came into effect for a large number of users who found their websites moved from 3.8 to 3.8.1 without any prior notification.
As much as I like and respect his WP knowledge, I’m forced to disagree somewhat with Rhys Whynne’s article, which says they’re an unqualified good thing, and side with the view he references from Marj Wyatt. The way that automatic upgrades have been implemented without any easy controls for website owners means that many people will need to either install an extra plugin or add code manually to stop their sites from being changed without their knowledge.
WordPress Auto Updates: The Benefits
There are several positives to having automatic upgrades for security reasons and minor releases. The first is that many, many people around the world are using outdated versions of WordPress and associated plugins which is a major security risk for them. Outdated software is a great way to invite hackers to easily get into your site, particularly if it allows them to use widely accessible and known vulnerabilities which can be hit in bulk.
And having worked with the large number of sites we develop, host and manage for clients, I can say that most are updated infrequently at best.
It also means that users aren’t paralysed by fear when given the option to upgrade. It also saves the cost of paying for anyone to simply have the confidence to perform a site back up and click yes to upgrade (Which is why we’ve always installed auto-backup tools for clients).
In terms of connectivity, even if the WordPress server has issues during the upgrade process, it won’t affect your site. If it fails, the site falls back to the normal state anyway.
And although I personally like to have as much control over any software updates and upgrades, in terms of trusting the intentions of WordPress, I’m more comfortable with an open source and fairly open organisation having the right aims than many of the other software platforms and products we all use on a daily basis.
WordPress Auto Updates: The Problems
So why wouldn’t I just recommend everyone lets Automatic Updates do their job?
Firstly, there is an ownership issue. Although I accept Rhys’s point that auto updates will reduce security issues for which WordPress could incorrectly be blamed, the fact is that the websites being updated are not the property of WordPress, are not on WordPress owned servers, and aren’t the responsibility of WordPress. Unless they’re also intending to come and help if I make a mistake while I’m tweaking some CSS as well?
But more importantly from a day-to-day practice is that minor updates can have major consequences. Although plugins and extensions should be designed and built in a way which means minor updates don’t affect them, that’s asking third party developers to predict the future. And the further you extend WordPress, the more risky it is.
Plus the time, resource and financial cost of ensuring everything is working can be problematic. It requires every third party supplier to be ready for every beta test and notification of an impending update, and to be able to test every single product they list prior to the update occurring.
Having worked with plugins like Jigoshop, that means not only the Jigoshop core plugin, but potentially checking tens of themes and hundreds of extensions, which have been created by a large number of suppliers.
The majority of people involved in that project, and many others, are making that effort, but it takes time and co-ordination – with an almost infinite combination of hosting, server setup, conflicting plugins and extensions etc.
And when we update a site, we always schedule it for the time which causes least disruption to site owners and their customers. That’s difference for every business, so there’s no way for WordPress to achieve this without looking at the website analytics for 1 million+ websites at a time.
That’s why I believe it’s wrong to have introduced Automatic Updates without any manual controls for a user or administrator which don’t require either coding or installing yet another plugin.
WordPress Auto Updates: Our Advice
One thing we can all agree on – make back ups of your site often. Rhys recommends once per day, which we’d recommend for sites which are critical to you and your business, although it’s really a question of how much you’re prepared to loss in a disaster versus the cost of storage space.
If your site is fairly simple, using core WordPress functionality and a handful of plugins, then Auto Updates are pretty much fine. For instance, I have no issue with having them enabled on www.danthornton.net as it’s a personal blog with very few tweaks or plugins.
If your site is complex, and uses substantial plugins or extensions, then we’d recommend turning off Auto Updates, which is what we’ve done for various clients. We’re not willing to let anything be changed on those sites without the opportunity to test and double check it.
If your site access is essential for your business, then we’d recommend turning off Auto Updates. Although maintenance mode passes very quickly, you want to be able to experience any issues at a time when you least disrupt customers and you’re on hand to fix any issues, rather than while you’re in a meeting, on holiday or sleeping.
WordPress Auto Updates: Turning them off
There are two ways to re-assert your control if you want to disable or restrict the automatic updates. The first is to edit the code on your site, and the instructions are available on the WordPress Codex. The second is to use one of the various plugins which have sprung up to offer similar functionality, such as ‘Update Control‘.
So far we’ve yet to test the plugin options, and have installed the manual option across a range of client sites to avoid adding plugins which shouldn’t be necessary. Essentially you’re then updating an additional plugin to cope with the update functionality WordPress introduced to avoid having to update so often.

Recent Comments