Keeping WordPress, themes and plugins updated is one of the highest-value habits for a healthy site. Do it on purpose — not in a rush on a Friday before a launch.
Update from the installer you already use
- Softaculous — open Softaculous Apps Installer → WordPress installations → the site → Edit Details or the toolkit-style update controls if offered. Core updates are often under the installation menu as Upgrade.
- WordPress Toolkit — open WordPress Toolkit / WordPress Manager, select the site, and use the updates control there. The toolkit can update core, plugins and themes and shows security checks.
If both icons exist, use one installer for updates and do not mix two different update flows on the same site in the same minute.
What to update
- WordPress core — Dashboard → Updates
- Plugins — only ones you still use
- Themes — especially the active theme and its parent, if any
Safe update routine
- Backup first — account backup and/or a WordPress-aware backup you can restore. See How to Back Up Your Hosting Account.
- Update plugins and themes, then core (or follow your installer’s recommended order).
- Browse the front page, a post, the contact form and checkout (if you have one).
- If something breaks, restore the backup and update items one at a time to find the culprit.
Plugin and theme caution
- Install from wordpress.org or trusted vendors — avoid random “nulled” packages.
- Remove plugins you deactivated months ago; unused code still adds risk.
- Limit “do everything” suites when a smaller plugin will do.
- Page builders and cache/security plugins sometimes conflict — change one variable at a time.
Automatic updates
Minor core updates can be automatic; major updates and plugin auto-updates are a policy choice. If you enable them, still keep backups — automation does not remove the need for a restore path.
Signs you should slow down
- The site was customised heavily years ago and never updated.
- You are on a deprecated PHP version (check cPanel → MultiPHP or Select PHP Version).
- A plugin has not been maintained in a long time — look for an alternative before a forced update.
If an update leaves a white screen or admin redirect loop, do not keep clicking. Note what you updated, restore from backup if you have one, and open a ticket with the domain and symptoms.
