You built your website yourself, but keeping track of which plugin needs an update takes time you don't have. WordPress can update itself, but it doesn't check whether your site still works afterwards. This script does.
We wrote it together with Claude for one of our own WordPress sites, tested it, and turned it into a general version you're free to use.
Download: wp-auto-update-en.sh (MIT license, free to use)
What does the script do?
- Checks whether your site works right now. If it's already broken, it changes nothing and notifies you.
- Makes a backup. On our hosting through the built-in backups, otherwise a database export plus an archive of
wp-content. - Updates everything: WordPress, plugins, themes and translations.
- Checks again: the homepage, your latest post, the login page and any pages you specify. Two attempts, with the cache purged, to avoid false alarms.
- Rolls back if there's a problem. First only the updated components, back to their old versions. If that doesn't fix it, the files from the backup.
- Emails you a report, with exactly what was updated or what went wrong.
It recognises real error pages (WordPress's "critical error" message, PHP errors, a half-loaded page), not just the word "error" in an article.
The fastest way: let Claude install it
On our hosting, type this into the Invoker Link assistant:
Install the WordPress update script from invoker.nl/scripts/wp-auto-update-en.sh for my website. Put it outside the website, send reports to you@yoursite.com, run it every Monday at 06:00 and do a dry run first.
Claude fills in the settings, sets up the cron job and shows you the result of the dry run. You'll find more instructions like this under Prompts.
Installing it yourself
1. Put the script outside your website
mkdir -p ~/maintenance/yoursite.com
curl -o ~/maintenance/yoursite.com/wp-auto-update-en.sh https://www.invoker.nl/scripts/wp-auto-update-en.sh
chmod 700 ~/maintenance/yoursite.com ~/maintenance/yoursite.com/wp-auto-update-en.sh
Never put a maintenance script in public_html. It makes database exports, and those don't belong anywhere that could be reachable from the web.
2. Fill in the settings
At the top of the script:
| Setting | What to fill in |
|---|---|
SITE_URL |
https://yoursite.com |
WP_PATH |
the folder containing wp-config.php |
REPORT_TO |
your email address |
MAIL_FROM |
a sender on your own domain |
EXTRA_URLS |
extra pages to check, e.g. "/contact/ /shop/" |
MAIL_ON_SUCCESS |
yes to also get an email when everything went fine |
RESTORE_DB |
see below |
3. Choose: restore the database automatically or not?
This is the most important choice. Restoring a database throws away everything that changed since the backup.
- Brochure site or blog without orders or forms:
RESTORE_DB="yes"is fine. - Web shop, bookings, forms or members: keep
RESTORE_DB="no". Then the script only restores files and notifies you. That way you won't lose an order placed at 05:58.
4. Test
bash ~/maintenance/yoursite.com/wp-auto-update-en.sh --test-mail # does the email arrive?
bash ~/maintenance/yoursite.com/wp-auto-update-en.sh --dry-run # what would be updated?
5. Automatically every week
crontab -e
Add (every Monday at 06:00):
0 6 * * 1 /bin/bash $HOME/maintenance/yoursite.com/wp-auto-update-en.sh >/dev/null 2>&1
On DirectAdmin hosting you can also do this through DirectAdmin → Cron Jobs.
How do you read the report?
| Subject starts with | Meaning |
|---|---|
| OK | everything updated and the site works |
| STOPPED | nothing was changed, for example because the site was already broken |
| RECOVERED | an update broke the site and the script rolled it back. Check which plugin it was. |
| EMERGENCY | the rollback didn't work: take action straight away or get in touch with us |
The log of every run is kept in ~/maintenance/yoursite.com/logs/ and cleaned up after 60 days.
What do you need?
- WP-CLI (
wp) andcurlon the server, andmailfor the report. - SSH or terminal access to set it up once.
- On our hosting everything is in place, and the script automatically uses the built-in backups.