On a Flashcloud install, the safest setup is core auto-updates on, plugin and theme auto-updates on for anything you trust and check rarely, and manual updates for anything that touches checkout, payments, or custom code. WordPress updates itself by default: core minor releases install automatically, and plugins or themes only update automatically if you turn that on per-item. You control all of this from wp-admin → Dashboard → Updates and from the Plugins and Themes screens.
You already have a safety net if an auto-update goes wrong. Daily server-level backups run automatically, and every WordPress install gets our cache stack pre-configured. Neither replaces good judgment about what to auto-update and what to review by hand.
Core updates
WordPress core ships three kinds of releases: major (new features), minor (security and bug fixes), and security-only. By default, WordPress auto-installs minor and security releases but not major ones. Leave this on. Minor core updates are low-risk, frequent, and often patch real vulnerabilities. Delaying them is one of the most common ways sites get compromised.
Major core updates are a different story. They can change block editor behavior, deprecate functions, or interact badly with an older theme. Update those manually: back up first, test on staging if the site is business-critical, then update live. See Backing up your WordPress site and Using WordPress staging.
To force major releases to auto-update too, add this to wp-config.php above the line that says "That's all, stop editing":
define( 'WP_AUTO_UPDATE_CORE', true );
Most sites shouldn't do this. It's useful for a low-traffic brochure site nobody's actively maintaining, not for a store or a site with custom theme code.
Plugin and theme updates: block editor first
You don't need a plugin to manage this. WordPress core has built-in per-item auto-update toggles since version 5.5, and that's the right starting point for most sites.
- Go to
Plugins → Installed Plugins. - Look at the "Automatic Updates" column on the right of each row.
- Click
Enable auto-updatesorDisable auto-updatesper plugin. - Repeat for themes under
Appearance → Themes, using the same toggle on each theme's detail view.
A sane default: enable auto-updates for plugins with a small, stable feature set (SEO tools, utility plugins, simple form plugins). Disable auto-updates for anything with deep integration into your site: page builders (Elementor, Divi), WooCommerce and its extensions, and any plugin with custom code hooked into it. Those deserve a human looking at the changelog before the version changes under you.
If you're running a store, treat every plugin update as a staging-first update, whether it's set to auto-update or not. A broken checkout costs real orders, and the fastest way to catch that before customers do is testing the update on a copy first. Running a WooCommerce store covers this in more detail.
When to reach for a plugin instead
The built-in toggles are all-or-nothing per item: a plugin either auto-updates on every release, or it doesn't update automatically at all. If you want more control, a management plugin adds:
- Scheduled update windows (e.g., only run updates at 3am, not during business hours).
- Update notifications by email before or after an auto-update runs.
- Selective version pinning, skipping a specific release known to cause issues while still taking later ones.
- Staging-aware workflows, where updates apply to a staging copy first and only promote to live after a check.
Popular options: Easy Updates Manager (free, focused purely on update control) or a broader site management plugin if you're already using one for other tasks. Install from Plugins → Add New, same as any other plugin. Don't stack more than one update-management plugin; they fight over the same WordPress hooks.
Protect yourself from a bad update
Whichever approach you use, two habits matter more than the toggle settings themselves:
- Keep backups current. Server-level daily backups already run in the background, but if you're about to update something risky, a fresh manual backup right before gives you a clean, recent restore point. See Backing up your WordPress site for how plugin-level and server-level backups differ and when to use each.
- Use staging for anything that isn't routine. Major core updates, theme switches, and plugin updates on a store all belong on a staging copy first. See Using WordPress staging for the workflow.
If a plugin auto-update does break something visible, first check Plugins → Installed Plugins for a version mismatch against what you expected, then deactivate the plugin to confirm it's the cause. If deactivating fixes the issue, roll that one plugin back to the previous version from the developer's site, or restore from your most recent backup if you need the whole site back to a known-good state.
When to contact support
If an update breaks the site and you can't isolate which plugin or theme caused it, or a backup restore doesn't bring things back cleanly, open a ticket from the portal (Support → New ticket). You'll reach a real person, not a bot, and they can restore from server-level backups or help track down the conflict directly.