Keeping website software updated

Why updates are the most important security task, what needs updating beyond the CMS itself, and a routine that keeps a small site current.

How-to guideBeginner2 min readUpdated

When a vulnerability is fixed, the fix is published — and so, effectively, is how to exploit sites that haven’t updated. Automated attacks follow within days.

What needs updating

ComponentHow
Your CMS core (WordPress, Joomla, etc.)Its admin dashboard, or Softaculous
Plugins, extensions and modulesThe CMS admin
Themes and templatesThe CMS admin, or the supplier
Composer and npm dependenciesRebuild locally and redeploy
PHP versionDirectAdmin (How to change the PHP version in DirectAdmin)
Your own devices and browsersAutomatic updates

The server’s operating system, web server and database are maintained by Traxio.

A simple routine

  • Weekly: log in to the CMS and apply updates (or let auto-updates run for trusted plugins)
  • Before updating: take a backup
  • After updating: check key pages and forms
  • Every few months: review plugins and remove any abandoned ones; check the PHP version is still supported

Softaculous installs

Softaculous can notify you of updates for apps it installed, and some apps can be set to update automatically from its installation settings.

Abandoned software

A plugin or app that no longer receives updates will eventually have an unfixed vulnerability. Replace it while it’s still working, not after it’s exploited.

Popular

Tip: press / to search from any pageSee all results