Automatic updates and plugin policy
What updates automatically, what waits for you, and which plugins are not allowed on the platform.
Out-of-date software is the most common way a WordPress site is compromised. The platform updates what it can safely update and leaves you in control of the rest.
What updates on its own
- WordPress security releases, applied within hours of publication.
- Plugins with a published security advisory, patched on the same schedule.
- The server stack: operating system, PHP patch releases, the web server and the database.
What you decide
- WordPress major versions.
- Routine plugin and theme updates, which you can set to automatic per site.
- Premium plugins that update through their own licence server.
Plugins that are blocked
| Category | Why |
|---|---|
| Full-page caching plugins | They conflict with the platform cache. |
| Backup plugins | They fill the disk and duplicate off-site backups. |
| Security scanners that run continuously | They consume the CPU the site needs; the WAF already runs at the edge. |
| Database "optimisers" that rewrite tables on a schedule | They lock tables during traffic and cause timeouts. |
| Mail-sending plugins that bypass authentication | Mail from them is rejected by recipients. |
Already installed one?
Blocked plugins are deactivated automatically, and you get an email explaining which and why. Nothing is deleted.
