WordPress·3 min read

Automatic WordPress updates with backup, health check and rollback (free script)

A free script that updates your WordPress site weekly: a backup first, then a health check, automatic rollback if something breaks, and an email report.

You built your website yourself, but keeping track of which plugin needs an update takes time you don't have. WordPress can update itself, but it doesn't check whether your site still works afterwards. This script does.

We wrote it together with Claude for one of our own WordPress sites, tested it, and turned it into a general version you're free to use.

Download: wp-auto-update-en.sh (MIT license, free to use)

What does the script do?

  1. Checks whether your site works right now. If it's already broken, it changes nothing and notifies you.
  2. Makes a backup. On our hosting through the built-in backups, otherwise a database export plus an archive of wp-content.
  3. Updates everything: WordPress, plugins, themes and translations.
  4. Checks again: the homepage, your latest post, the login page and any pages you specify. Two attempts, with the cache purged, to avoid false alarms.
  5. Rolls back if there's a problem. First only the updated components, back to their old versions. If that doesn't fix it, the files from the backup.
  6. Emails you a report, with exactly what was updated or what went wrong.

It recognises real error pages (WordPress's "critical error" message, PHP errors, a half-loaded page), not just the word "error" in an article.

The fastest way: let Claude install it

On our hosting, type this into the Invoker Link assistant:

Install the WordPress update script from invoker.nl/scripts/wp-auto-update-en.sh for my website. Put it outside the website, send reports to you@yoursite.com, run it every Monday at 06:00 and do a dry run first.

Claude fills in the settings, sets up the cron job and shows you the result of the dry run. You'll find more instructions like this under Prompts.

Installing it yourself

1. Put the script outside your website

mkdir -p ~/maintenance/yoursite.com
curl -o ~/maintenance/yoursite.com/wp-auto-update-en.sh https://www.invoker.nl/scripts/wp-auto-update-en.sh
chmod 700 ~/maintenance/yoursite.com ~/maintenance/yoursite.com/wp-auto-update-en.sh

Never put a maintenance script in public_html. It makes database exports, and those don't belong anywhere that could be reachable from the web.

2. Fill in the settings

At the top of the script:

Setting What to fill in
SITE_URL https://yoursite.com
WP_PATH the folder containing wp-config.php
REPORT_TO your email address
MAIL_FROM a sender on your own domain
EXTRA_URLS extra pages to check, e.g. "/contact/ /shop/"
MAIL_ON_SUCCESS yes to also get an email when everything went fine
RESTORE_DB see below

3. Choose: restore the database automatically or not?

This is the most important choice. Restoring a database throws away everything that changed since the backup.

  • Brochure site or blog without orders or forms: RESTORE_DB="yes" is fine.
  • Web shop, bookings, forms or members: keep RESTORE_DB="no". Then the script only restores files and notifies you. That way you won't lose an order placed at 05:58.

4. Test

bash ~/maintenance/yoursite.com/wp-auto-update-en.sh --test-mail   # does the email arrive?
bash ~/maintenance/yoursite.com/wp-auto-update-en.sh --dry-run     # what would be updated?

5. Automatically every week

crontab -e

Add (every Monday at 06:00):

0 6 * * 1 /bin/bash $HOME/maintenance/yoursite.com/wp-auto-update-en.sh >/dev/null 2>&1

On DirectAdmin hosting you can also do this through DirectAdmin → Cron Jobs.

How do you read the report?

Subject starts with Meaning
OK everything updated and the site works
STOPPED nothing was changed, for example because the site was already broken
RECOVERED an update broke the site and the script rolled it back. Check which plugin it was.
EMERGENCY the rollback didn't work: take action straight away or get in touch with us

The log of every run is kept in ~/maintenance/yoursite.com/logs/ and cleaned up after 60 days.

What do you need?

  • WP-CLI (wp) and curl on the server, and mail for the report.
  • SSH or terminal access to set it up once.
  • On our hosting everything is in place, and the script automatically uses the built-in backups.
MK
Maarten Keizer

Founder of Invoker. Over twenty years in hosting, system administration and web development; builds the Claude hosting himself and tests everything on our own servers first.

about maarten