WordPress·2 min read

Safely update WordPress with WP-CLI (and roll back automatically)

WP-CLI update commands for WordPress core, plugins and themes, with the right PHP version and an automatic rollback for every plugin that breaks your site.

Updating from the WordPress dashboard is fine until something goes wrong. In the terminal you have more control. These are the lessons from updating WordPress sites on our servers.

The quick, safe route

A ready-made script is available on our hosting:

wp-safe-update yoursite.com --dry-run   # see first what will be updated
wp-safe-update yoursite.com             # run it

In order, it does:

  1. a full backup,
  2. plugins one by one, checking after each plugin whether the homepage still works,
  3. if the site breaks after a plugin update, it rolls that plugin back to its previous version,
  4. themes, then WordPress itself plus the database update,
  5. purges the cache and does a final check of the homepage and login page.

Claude also uses this script when you ask it to "update WordPress and all plugins".

Doing it yourself: four pitfalls

1. The wrong PHP version

wp runs on the server's default PHP. If your site uses a different version, you update and check on a different PHP than your visitors get. Call WP-CLI with the right version:

/usr/local/php84/bin/php /usr/local/bin/wp --path=$HOME/domains/yoursite.com/public_html plugin list

2. Plugins that do something on every wp call

Some plugins and themes print notices or even run actions on every WP-CLI call. We saw a site that returned "Purged all caches successfully" on every command. That pollutes your output and makes scripts unreliable.

So read and update without loading plugins and themes:

wp --skip-plugins --skip-themes plugin list --update=available
wp --skip-plugins --skip-themes plugin update contact-form-7

Only a plugin's own commands (such as wp litespeed-purge all) need the plugins loaded.

3. The "latest" WordPress version

wp core check-update can return several versions, for example a security update within your current branch and a new major version. Check which one you want before running wp core update.

4. Rolling back per plugin

If it goes wrong after a plugin update, roll back just that plugin:

wp plugin install plugin-name --version=1.2.3 --force

Still not working: wp plugin deactivate plugin-name, and only then restore a full backup.

Afterwards

  • Purge the cache: wp litespeed-purge all (LiteSpeed Cache) or wp cache flush.
  • Check the homepage and /wp-login.php: curl -s -o /dev/null -w '%{http_code}' https://yoursite.com/.
  • Two sites sharing the same database (same DB_NAME and $table_prefix in wp-config.php) affect each other. Check both.
MK
Maarten Keizer

Founder of Invoker. Over twenty years in hosting, system administration and web development; builds the Claude hosting himself and tests everything on our own servers first.

about maarten