All posts
November 2013·5 min read

WordPress automatic updates: should you let them run?

WordPress 3.7 quietly introduced automatic background updates for minor releases — no prompts, no action required. It's one of the best security decisions WordPress has made, with some genuine caveats worth understanding.

What changed in WordPress 3.7

WordPress 3.7, released in October 2013, introduced automatic background updates for minor core releases. Prior to this, every WordPress update — even a minor security patch — required manual action. Site owners had to notice the update notification, click through the update process, and hope nothing broke.

With 3.7, WordPress will now automatically download and apply minor version updates (for example, updating from 3.7 to 3.7.1, or from 3.8.1 to 3.8.2) in the background, without any prompts or site owner action. You'll receive an email notification when it happens. Major version updates (3.7 to 3.8) still require manual action.

The security argument for auto-updates

The primary motivation behind the feature is closing the window between a security patch being released and sites actually running it. Before automatic updates, that window could be weeks or months — many site owners never got around to applying updates, or didn't notice them.

The April 2013 botnet attacks demonstrated what happens when large numbers of sites run known vulnerable versions. The attackers weren't using sophisticated zero-day exploits — they were exploiting vulnerabilities that had been publicly patched, against sites that simply hadn't applied the fix.

Auto-updates for minor security releases directly address this. A site running WordPress 3.7 will automatically become a site running 3.7.1 the moment that patch is available, without any human action required.

The legitimate concerns

The developer community had real objections to automatic updates, and they're worth taking seriously:

  • Plugin and theme compatibility. Even minor WordPress updates can break compatibility with specific plugins or themes, particularly older or poorly maintained ones. An automatic update at 2am could take a site down without anyone knowing until morning.
  • Loss of control. Site owners and developers reasonably expect to control when changes happen to a production site. Background changes without explicit approval run counter to standard deployment practices.
  • Staging environment divergence. Development workflows that maintain staging and production environments can be disrupted by automatic updates that apply to one but not the other.

The practical reality

Minor WordPress releases (3.7.x, 3.8.x) are deliberately conservative — they address specific security issues and confirmed bugs without adding features or making architectural changes. The compatibility risk is genuinely low.

For most small business WordPress sites without active development workflows, automatic minor updates are the right choice. The alternative — manual updates that often don't happen — is demonstrably worse for security.

For sites under active development, or sites with complex plugin setups where any change carries meaningful compatibility risk, disabling automatic updates in favour of a controlled update process makes sense. WordPress provides constants to control this behaviour.

What auto-updates don't cover

It's important to be clear about what the feature doesn't do. Automatic updates apply to WordPress core minor releases only. They do not automatically update plugins, themes, or major WordPress versions.

Plugin vulnerabilities have historically been a larger source of WordPress compromises than core vulnerabilities. Automatic minor core updates are a meaningful improvement, but they don't remove the need to actively maintain your plugins and themes.


At DownUnder WP, you control when WordPress core, plugin, and theme updates run from your dashboard. Updates are one click per item — you see exactly what's changing before applying it.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.