WordPress 3.7 quietly introduced automatic background updates for minor releases — no prompts, no action required. It's one of the best security decisions WordPress has made, with some genuine caveats worth understanding.
WordPress 3.7, released in October 2013, introduced automatic background updates for minor core releases. Prior to this, every WordPress update — even a minor security patch — required manual action. Site owners had to notice the update notification, click through the update process, and hope nothing broke.
With 3.7, WordPress will now automatically download and apply minor version updates (for example, updating from 3.7 to 3.7.1, or from 3.8.1 to 3.8.2) in the background, without any prompts or site owner action. You'll receive an email notification when it happens. Major version updates (3.7 to 3.8) still require manual action.
The primary motivation behind the feature is closing the window between a security patch being released and sites actually running it. Before automatic updates, that window could be weeks or months — many site owners never got around to applying updates, or didn't notice them.
The April 2013 botnet attacks demonstrated what happens when large numbers of sites run known vulnerable versions. The attackers weren't using sophisticated zero-day exploits — they were exploiting vulnerabilities that had been publicly patched, against sites that simply hadn't applied the fix.
Auto-updates for minor security releases directly address this. A site running WordPress 3.7 will automatically become a site running 3.7.1 the moment that patch is available, without any human action required.
The developer community had real objections to automatic updates, and they're worth taking seriously:
Minor WordPress releases (3.7.x, 3.8.x) are deliberately conservative — they address specific security issues and confirmed bugs without adding features or making architectural changes. The compatibility risk is genuinely low.
For most small business WordPress sites without active development workflows, automatic minor updates are the right choice. The alternative — manual updates that often don't happen — is demonstrably worse for security.
For sites under active development, or sites with complex plugin setups where any change carries meaningful compatibility risk, disabling automatic updates in favour of a controlled update process makes sense. WordPress provides constants to control this behaviour.
It's important to be clear about what the feature doesn't do. Automatic updates apply to WordPress core minor releases only. They do not automatically update plugins, themes, or major WordPress versions.
Plugin vulnerabilities have historically been a larger source of WordPress compromises than core vulnerabilities. Automatic minor core updates are a meaningful improvement, but they don't remove the need to actively maintain your plugins and themes.
At DownUnder WP, you control when WordPress core, plugin, and theme updates run from your dashboard. Updates are one click per item — you see exactly what's changing before applying it.
Australian WordPress hosting from $5/month
Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.