Updates keep WordPress safe, but an update can also break a page, a form or a checkout. WP Toolkit in cPanel has two features that take much of the risk out of this: Smart Updates, which tests updates on a copy of your site before touching the real one, and vulnerability scanning, which warns you when a plugin or theme you use has a known security hole. This guide shows how to turn on and use WP Toolkit Smart Updates, how to read the Smart Update report, and what to do when WP Toolkit flags a vulnerability.
For the basics of running updates and setting auto-updates, see How to Update WordPress, Plugins and Themes (and Turn On Auto-Updates). This guide goes deeper on the two safety features.
How Smart Updates work
With Smart Update switched on for a site, every update -- manual or automatic -- goes through these steps:
- WP Toolkit makes a temporary clone of your site (files and database) inside your account.
- It checks the clone and takes "before" screenshots of your pages.
- It installs the updates on the clone only.
- It checks the clone again and takes "after" screenshots.
- It compares the two, looking for PHP errors, HTTP error codes (such as 500 or 404), changed page titles, visual differences and other problems. It also notes problems that already existed before the update, so you can tell old issues from new ones.
What happens next depends on how the update was started:
| Update type | What Smart Update does |
|---|---|
| Manual (you clicked Update) | Shows you the report and screenshots, gives its forecast of whether the update is safe, and waits for you to choose Apply Updates or Discard. |
| Automatic | Applies the update to your live site only if it found no new issues. If it found even one issue caused by the update, the live site is left alone. |
Either way, you get an email with the results and a link to the before-and-after report. WP Toolkit sends it to your account's contact email, so make sure that's current -- see How to Update Your Contact Email and Notifications in cPanel.
Afterwards, the clone is deleted.
Before you turn it on: check your disk space
Smart Update needs room for a full temporary copy of your site. If your site uses 3 GB, you need a bit more than 3 GB free while the update runs. Check Disk Usage in the Statistics panel on the right of the cPanel home page (see Understanding cPanel Statistics: Disk Space, Bandwidth and Databases).
If you're short on space, delete old WP Toolkit backups you've downloaded, remove unused plugins and themes, and clear out large, old files. If a Smart Update fails with a disk space error, your live site is unaffected -- the update just doesn't happen.
How to turn on Smart Update
- Log in to cPanel (from the client area: Services > My Services, choose your plan, then Log in to cPanel).
- Go to Domains > WordPress Management (WP Toolkit).
- Find your site's card.
- Turn on the Smart Update switch on the card.
Smart Update is set per site, so switch it on for each WordPress site you want protected. Leave it off on a staging copy you don't care about -- it'll update faster.
How to run a manual Smart Update
- On the site's card, click the updates message (for example Install plugin updates) or Check for Updates.
- Tick the updates you want. If a WordPress core update is listed, leave Restore Point ticked.
- Click Update.
- Wait while WP Toolkit clones, updates and analyzes the copy. It runs in the background, so you can close the window; a small site takes a few minutes, a big one longer.
- Open the report when it's ready (from WP Toolkit or the link in the email).
How to read the Smart Update report
- The forecast. Smart Update tells you whether it thinks the update is safe. It's a strong hint, not a guarantee.
- Screenshots. Pick a page and look at "before" and "after" side by side, or use the comparison view, which highlights what changed.
- Issues per page. Select one page at a time to see issues found on it, such as a PHP warning or a page that now returns an error.
- Website Summary. Issues for the whole site, with the option to download a detailed report. Useful to send to a developer.
Then decide:
- If no issues were found and the screenshots look right, click Apply Updates and confirm. WP Toolkit updates your live site and deletes the clone.
- If something broke, click Discard. The live site stays exactly as it was. Note which plugin was being updated, check its changelog and support forum, and try again when a fixed version comes out. You can also update the others without it -- untick the problem one and run the update again.
Telling real problems from false alarms
Screenshots of the same page can differ for harmless reasons. These are usually fine:
- Sliders, carousels and rotating banners caught on a different slide.
- "Latest posts", dates, random testimonials or live stock and weather widgets.
- Ads and embedded social media feeds.
- A cookie banner appearing in one shot and not the other.
These are real problems -- don't apply:
- A page that's blank, shows "There has been a critical error", or returns a 500 or 404.
- Missing menus, broken layout, or unstyled text (CSS not loading).
- A form, cart or checkout that disappeared.
- New PHP fatal errors in the issues list.
Smart Update with automatic updates
Smart Update is at its best combined with auto-updates: security fixes go on automatically when they're safe, and risky ones are held back for you to look at. A good setup for a live site:
- Turn on Smart Update for the site.
- In Autoupdate settings on the card, set WordPress to Yes, but only minor (security) updates.
- Set plugins and themes to Defined individually, but security updates are autoinstalled.
- Keep an eye on your email. When Smart Update holds back an update, you'll get a report -- read it, then decide whether to apply the update manually, wait for a fix, or replace the plugin.
If you see updates waiting on the site card even though auto-updates are on, Smart Update has probably skipped one. Open the report or run the update manually.
Smart Update limitations
- It isn't a backup. Keep taking backups before big changes -- see How to Back Up and Restore WordPress in WP Toolkit. Your account is also backed up three times a week with JetBackup 5.
- It checks pages, not every feature. It can't log in as a customer, submit a form, or place a test order. After a big update to WooCommerce, a booking plugin or a page builder, test those flows yourself.
- Premium plugins need a valid license in WordPress to update at all. Plugins with unusual update methods may not update through WP Toolkit.
- It takes longer than a plain update, and briefly uses the extra disk space.
- Content added during the test (a new order or comment) isn't lost -- the update is applied to your live site, not copied back from the clone.
Vulnerability scanning
WP Toolkit regularly checks your WordPress version, plugins and themes against a database of known security vulnerabilities (the data comes from Patchstack). It tells you when something you have installed -- even a deactivated plugin -- has a published security hole.
Where the warnings appear
- On the WP Toolkit site list, an affected site is tagged with a security risk label and a number. The number, from 0.1 to 10, estimates how serious the worst issue is. Higher is worse.
- The site card may also show a call to action such as Mitigate vulnerabilities, or the word Vulnerable.
How to review and fix a vulnerability
- In Domains > WordPress Management, click the security risk tag or the vulnerability warning on the site's card. The Security Status panel opens.
- Open the Vulnerable Components tab. Each affected item is listed with its risk rating. Click one to see the details of each vulnerability.
- For each item:
- If an update is available that fixes it, update it -- ideally with Smart Update on. This is the right fix almost every time.
- If it's a plugin or theme you don't use, delete it. Deactivated code can still be attacked.
- If there's no fix yet, decide how much you need it. For a high-risk issue, deactivate it until a fix is released, or replace it with a maintained alternative. Check the plugin's page on WordPress.org -- a plugin that's been closed or hasn't been updated in years isn't coming back.
- Check the card again. Once everything is updated or removed, the warning clears.
Our servers also run security software at the server level, but it doesn't replace updates. A known hole in a plugin is exactly what automated attacks look for.
Troubleshooting
There's no Smart Update switch on my site card
Make sure you're looking at the site's card in Domains > WordPress Management. If the switch isn't there, open a ticket and tell us the site's address.
Smart Update fails every time
Usually disk space. Free some space and try again. If your site is very large, open a ticket.
A vulnerability warning stays after I updated
WP Toolkit rechecks sites regularly, so give it a little time, or click Check for Updates on the card. If the warning still names a version you no longer have, open a ticket -- the scan can occasionally lag behind.
The report says the update is safe, but my site broke
Roll back WordPress core with the restore point, or restore your latest backup. Then open a ticket with the plugin name and the time.
Common questions
Does Smart Update slow down my live site?
No. The clone is tested in the background. Your site may show maintenance mode for a few seconds while the approved updates are actually applied.
Do I still need a staging site?
For quick plugin updates, Smart Update is usually enough. For redesigns, big version jumps or custom code, use a staging site -- see How to Create a WordPress Staging Site and Push It Live.
My site is already hacked. Will this fix it?
No. Updating closes the hole but doesn't remove malware. See What to Do If Your WordPress Site Is Hacked.
Related guides
- How to Update WordPress, Plugins and Themes (and Turn On Auto-Updates)
- How to Secure WordPress with WP Toolkit Security Hardening
- How to Back Up and Restore WordPress in WP Toolkit
- How to Create a WordPress Staging Site and Push It Live
- How to Change Your PHP Version in cPanel
Still stuck? Open a support ticket and the Instant Access Internet Services team will help.
