Most hacked WordPress sites were running an out-of-date plugin with a known vulnerability. Updates are the single most effective security measure.
The safe routine
- Back up first. How to back up WordPress
- Go to Dashboard → Updates.
- Update plugins, then themes, then WordPress core. (For major core releases, check your key plugins support it.)
- Visit the front end and test forms, checkout and logins.
Automatic updates
- WordPress applies minor core security releases automatically by default.
- In Plugins, select Enable auto-updates for plugins you trust. Auto-updating well-maintained plugins is safer for most people than forgetting to update.
- Keep major core updates and complex plugins (shop, membership, page builders) manual if a breakage would be costly.
PHP version
WordPress and plugins increasingly need newer PHP. Staying current on PHP is part of updating. Choosing the right PHP version for WordPress
If an update breaks the site
- ”There has been a critical error”: “There has been a critical error on this website”
- Stuck “Briefly unavailable for scheduled maintenance”: WordPress stuck on “Briefly unavailable for scheduled maintenance”
- A plugin broke something: rename its folder in
wp-content/pluginsusing the File Manager to deactivate it, then restore the previous version or contact its developer.
Not hosting with Traxio yet? WordPress hosting from 99p a month is free for 30 days with no card, then £0.99 a month.