Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

For a normal maintenance run, back up your site, update WordPress core, complete any prompted database upgrade, then review and update plugins and themes. Check each plugin’s compatibility information and changelog before installing it. This is the general order taught by Learn WordPress; a specific plugin may need priority when its release notes identify a concrete security or compatibility reason.

Why core usually comes before plugins

Updating WordPress core first gives you a clear baseline for checking plugins against the version they will run on. WordPress’s training material gives the usual sequence as backup, core, then plugins and themes. The order is a practical default, not a guarantee that every site has identical dependencies.

WordPress’s core update guidance recommends keeping WordPress current and completing the database upgrade promptly if the update prompts for one. Plugin documentation also recommends having a current backup before updating plugins.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Safest update order, step by step

  1. Record the starting state. Note your WordPress version, PHP/runtime environment, active theme, critical plugins, and planned maintenance window. This gives you a reference point if something stops working.
  2. Make a rollback-capable backup. Back up both the database and WordPress files. The Advanced Administration Handbook treats them as one backup set and describes backing up the database before the files. Keep the copies together and know how to restore them; a backup that cannot be restored is not a dependable rollback plan.
  3. Update WordPress core. Use the dashboard, a controlled deployment process, or WP-CLI. For WP-CLI, wp core update updates to the latest core version by default; the command also supports specifying a version or requesting a minor-only update.
  4. Complete the database upgrade. If WordPress prompts you to upgrade the database after replacing core files, complete that step before proceeding.
  5. Review plugins one at a time. Check each plugin’s compatibility indicator and version details or changelog. Look for stated WordPress and PHP requirements, dependencies, and any known issue affecting your site.
  6. Update plugins, then themes. For a high-risk or business-critical site, update one component at a time rather than applying every change together. This makes it easier to identify which change caused a problem.
  7. Check the site and clear caches. Test the parts visitors and staff rely on, such as the front end, login, forms, checkout, search, email, and scheduled jobs. Clear caches so the updated files and pages are visible, then monitor error logs and uptime.

When a plugin should be updated first

Use a plugin-first exception only when there is a specific reason, such as release notes that address a security issue or compatibility requirement for the currently installed core, host guidance, or a staging test that establishes the necessary order. Check the plugin’s documented compatibility information and version details before deciding. One plugin’s urgent release is not a reason to update every plugin before core.

What automatic updates change—and what they do not

WordPress supports automatic minor core updates and provides per-plugin and per-theme auto-update controls. Plugin and theme auto-updates were introduced in WordPress 5.5. Major core releases generally still require a deliberate update action, while plugin and theme updates are commonly initiated manually unless auto-updates are enabled or WordPress’s security process triggers an update.

Automation changes when updates are applied; it does not remove the need for current backups, compatibility review, monitoring, or a rollback plan. Enable unattended updates only if you can detect failures and restore the site when necessary.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

If an update breaks the site

Start by identifying whether the failure followed a core, plugin, theme, or database change. If a failed automatic core upgrade has left WordPress in maintenance mode, the WordPress core guide documents removing the leftover .maintenance file. If the site remains broken, restore the known-good database and file backup together, or restore the previous release files when appropriate. Avoid restoring only one part of the backup set when the database and files have changed together.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.