All posts
August 2010·5 min read

Why you should update WordPress the moment a new version drops

Running an old version of WordPress is one of the most common reasons sites get hacked. Updates aren't optional maintenance — they're active security patches.

Most hacked WordPress sites are running old versions

When a WordPress security release comes out, the vulnerability it patches is made public — often within days. That means every site still running the old version is now a known target. Automated scanners catalogue vulnerable WordPress installs across the internet and attack them at scale. The gap between "update released" and "attacks begin" is measured in hours, not weeks.

The WordPress 2.8.x series had several serious vulnerabilities patched in rapid succession through 2009 and into 2010. Sites that didn't keep pace were compromised in bulk — not by skilled attackers targeting them specifically, but by automated tools running the same exploit against thousands of sites simultaneously.

What attackers actually do with a compromised WordPress site

The goal isn't usually to deface your homepage. A compromised site is more valuable to attackers if you don't know it's compromised. Common outcomes:

  • Hidden links injected into your pages to boost other sites in search engines (SEO spam)
  • Your site used to serve malware to your visitors without your knowledge
  • Your server used to send spam email
  • Your database mined for email addresses to sell
  • Backdoor files planted for persistent access, even after you update

By the time you notice something is wrong — a Google warning, a hosting suspension, a customer complaint — the damage has often been running for weeks.

The update process in 2010

Unlike today, WordPress didn't have a one-click update system until version 2.7 (December 2008). Even then, many hosting environments required FTP credentials to apply updates, and plenty of site owners had set up WordPress and never looked at it again.

The manual update process — downloading the zip, uploading via FTP, running the database upgrade script — was enough friction that a large portion of sites never updated at all. By mid-2010, there were significant numbers of live WordPress sites running versions two or three major releases behind, with publicly known exploit code available for all of them.

Updating safely: what to check first

The risk of an update going wrong is real but manageable. Before every update:

  • Back up your database. Export it via phpMyAdmin or your host's control panel. A WordPress database backup takes seconds and is the most important thing you can restore if something goes wrong.
  • Back up your wp-content folder. Download it via FTP. Your themes, plugins, and uploaded files live here.
  • Check your theme and plugin compatibility. The WordPress changelog and the plugin forum threads will tell you if there are known issues with the new version before you update.

With a fresh backup in hand, a WordPress core update is low risk. An incompatible plugin can usually be deactivated to restore a working site while you wait for an updated version. A working backup means the worst case is always recoverable.

Minor versions vs major versions

WordPress version numbers follow a pattern: 3.0, 3.0.1, 3.0.2, and so on. The minor versions (3.0.1, 3.0.2) are almost always security or bug fix releases. They should be applied immediately with no hesitation — they don't add features that could break things.

Major versions (3.0 to 3.1) may include new features and database changes. The compatibility risk is slightly higher, but the security improvements are more significant. Apply them within a few days of release, not months.

The sites that don't get hacked

There's no such thing as a perfectly secure website, but the sites that don't get hacked are overwhelmingly the ones that are kept current. Attackers are lazy by design — they run automated tools against millions of sites and harvest the easy ones. A site running the current WordPress version with updated plugins is simply not in that category.

The single most effective thing you can do for your WordPress site's security is also the simplest: keep it updated. Not quarterly. Not when you remember. Every time a new version is released.


At DownUnder WP, WordPress core, plugin, and theme updates are available with one click from your dashboard. You control when they run — no surprises, no auto-updates you didn't ask for.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.