🏷️ Category: Stability & Systems
“Keep WordPress updated” used to feel like simple advice.
Good advice. Sensible advice. The kind of advice you could give a client without needing a risk matrix, a staging site, and a calming cup of tea.
And to be clear, it is still good advice.
But it is no longer quite the whole advice.

Recently, WordPress.org introduced a temporary 24-hour cooldown around new plugin and theme releases. Officially, the change was framed as a way to slow down auto-updates so new releases have more time for review before they are pushed widely across the ecosystem.
The reason is understandable. Recent supply-chain concerns have shown that speed is not always the safest option, especially if a compromised update can spread before anyone has had enough time to spot the problem.
But the practical effect has been messier. The delay does not only affect automatic updates. It also affects one-click manual updates through the WordPress dashboard. So a site owner may see that a plugin update exists, read the changelog, click the update link, and then find that WordPress cannot yet retrieve the package file.
To a client, that looks like a broken system.
Their host may handle updates differently. A managed platform may have its own update process. Alternative repository projects, such as the distributed FAIR Package Manager repository, also show that plugin delivery is becoming a larger part of the infrastructure conversation.
To a freelancer, it is a reminder that the update button is no longer just a button. It is a judgement call.
I remember when updates felt like one of the easier things to explain to clients.
“Yes, WordPress needs updating.”
“Yes, plugins need updating.”
“No, please don’t ignore those red circles forever.”
“Yes, that plugin from 2016 called Ultimate Mega Slider Supreme Deluxe may be a concern.”
Simple enough.
But over time, the meaning behind “update the website” has quietly changed.
It is no longer only about whether the latest version is installed. It is also about where the update came from, how urgent it is, who released it, whether it should be tested first, whether the vendor is still trustworthy, and what happens if something breaks afterwards.
That is the part clients rarely see.
They see the button.
We see the small crowd of invisible gremlins standing behind it.
Backups. Staging sites. Plugin conflicts. Abandoned vendors. Changed ownership. Broken forms. Checkout failures. White screens. Caching. Security patches. Host-level update systems. And that one plugin nobody remembers installing, but everyone is now apparently emotionally attached to (yes, that happens more often than you would think!).
Lovely.
This is where the challenge shows up for freelance WordPress businesses.
Not because freelancers are careless. Not because clients are being difficult.
But because the language around updates has stayed very simple, while the reality underneath has become more complicated.
Clients often think of updates like phone app updates. Tap the button. Get the new thing. Grab another cup of tea and move on with life.
Freelancers know a website is different. A WordPress site is not one app. It is a collection of moving parts built by different people and vendors, running on different hosting environments, often supporting forms, payments, memberships, bookings, email marketing, SEO, analytics, and business operations.
So when a client asks, “Is the site updated?”, the technically accurate answer may be more complex than a simple yes or no.
A better question might be:
“Do we have a clear process for how updates are handled?”
That is the useful reframe. The value is not just in clicking the button. The value lies in the judgement about when to click the button, how to handle it, and who is responsible if something does not go according to plan.
That does not mean every freelancer needs to become a security researcher, infrastructure expert, or professional paranoia goblin, although, let’s be honest, some of us are already halfway there. It simply means we need to be clearer about how updates are handled on client sites.
One calm way to do that is to create a simple update policy.
Nothing dramatic. Not a 47-page PDF with a stock photo of a padlock on the cover.
Just a short note that explains who is responsible for updates, which updates are automatic, which updates are manual, whether updates are tested first, and how urgent security updates are handled.
It should also explain what happens if an update appears in the dashboard but is not yet available, what the client should do if they see update notices, and, perhaps most importantly, what they should not do at 4:55 pm on a Friday.
Because the safest update strategy is not always “click everything immediately”.
Sometimes speed reduces risk. Sometimes speed creates it. The skill is knowing the difference.
That is the shift I think freelancers need to pay attention to.
Updating WordPress used to look like a technical task. Increasingly, it is becoming a trust decision.
For freelancers, that is both annoying and useful. Annoying because it gives us one more invisible thing to explain. Useful because it gives us a better way to talk about responsible website support without making it sound like a boring list of chores.
Not:
“I click the update buttons for you.”
More like:
“I help make sure the right updates happen in the right way, with the least amount of avoidable chaos.”
That is not as snappy as “monthly updates included”. But it is much closer to what clients actually need and what most of us freelancers actually provide.
Pause for a second and ask yourself:
If a client asked you today, “How are updates handled on my site?”, would your answer feel clear?
Not perfect. Just clear.
Because clarity usually arrives before confidence.
Your Thoughts
Hit reply with one word:
Clear or Fuzzy
No explanation needed.
Wil.