Updating from the WordPress dashboard is fine until something goes wrong. In the terminal you have more control. These are the lessons from updating WordPress sites on our servers.
The quick, safe route
A ready-made script is available on our hosting:
wp-safe-update yoursite.com --dry-run # see first what will be updated
wp-safe-update yoursite.com # run it
In order, it does:
- a full backup,
- plugins one by one, checking after each plugin whether the homepage still works,
- if the site breaks after a plugin update, it rolls that plugin back to its previous version,
- themes, then WordPress itself plus the database update,
- purges the cache and does a final check of the homepage and login page.
Claude also uses this script when you ask it to "update WordPress and all plugins".
Doing it yourself: four pitfalls
1. The wrong PHP version
wp runs on the server's default PHP. If your site uses a different version, you update and check on a different PHP than your visitors get. Call WP-CLI with the right version:
/usr/local/php84/bin/php /usr/local/bin/wp --path=$HOME/domains/yoursite.com/public_html plugin list
2. Plugins that do something on every wp call
Some plugins and themes print notices or even run actions on every WP-CLI call. We saw a site that returned "Purged all caches successfully" on every command. That pollutes your output and makes scripts unreliable.
So read and update without loading plugins and themes:
wp --skip-plugins --skip-themes plugin list --update=available
wp --skip-plugins --skip-themes plugin update contact-form-7
Only a plugin's own commands (such as wp litespeed-purge all) need the plugins loaded.
3. The "latest" WordPress version
wp core check-update can return several versions, for example a security update within your current branch and a new major version. Check which one you want before running wp core update.
4. Rolling back per plugin
If it goes wrong after a plugin update, roll back just that plugin:
wp plugin install plugin-name --version=1.2.3 --force
Still not working: wp plugin deactivate plugin-name, and only then restore a full backup.
Afterwards
- Purge the cache:
wp litespeed-purge all(LiteSpeed Cache) orwp cache flush. - Check the homepage and
/wp-login.php:curl -s -o /dev/null -w '%{http_code}' https://yoursite.com/. - Two sites sharing the same database (same
DB_NAMEand$table_prefixinwp-config.php) affect each other. Check both.