How to Use WP Toolkit Smart Updates and Vulnerability Scanning

Updates keep WordPress safe, but an update can also break a page, a form or a checkout. WP Toolkit in cPanel has two features that take much of the risk out of this: Smart Updates, which tests updates on a copy of your site before touching the real one, and vulnerability scanning, which warns you when a plugin or theme you use has a known security hole. This guide shows how to turn on and use WP Toolkit Smart Updates, how to read the Smart Update report, and what to do when WP Toolkit flags a vulnerability.

For the basics of running updates and setting auto-updates, see How to Update WordPress, Plugins and Themes (and Turn On Auto-Updates). This guide goes deeper on the two safety features.

How Smart Updates work

With Smart Update switched on for a site, every update -- manual or automatic -- goes through these steps:

  1. WP Toolkit makes a temporary clone of your site (files and database) inside your account.
  2. It checks the clone and takes "before" screenshots of your pages.
  3. It installs the updates on the clone only.
  4. It checks the clone again and takes "after" screenshots.
  5. It compares the two, looking for PHP errors, HTTP error codes (such as 500 or 404), changed page titles, visual differences and other problems. It also notes problems that already existed before the update, so you can tell old issues from new ones.

What happens next depends on how the update was started:

Update typeWhat Smart Update does
Manual (you clicked Update)Shows you the report and screenshots, gives its forecast of whether the update is safe, and waits for you to choose Apply Updates or Discard.
AutomaticApplies the update to your live site only if it found no new issues. If it found even one issue caused by the update, the live site is left alone.

Either way, you get an email with the results and a link to the before-and-after report. WP Toolkit sends it to your account's contact email, so make sure that's current -- see How to Update Your Contact Email and Notifications in cPanel.

Afterwards, the clone is deleted.

Before you turn it on: check your disk space

Smart Update needs room for a full temporary copy of your site. If your site uses 3 GB, you need a bit more than 3 GB free while the update runs. Check Disk Usage in the Statistics panel on the right of the cPanel home page (see Understanding cPanel Statistics: Disk Space, Bandwidth and Databases).

If you're short on space, delete old WP Toolkit backups you've downloaded, remove unused plugins and themes, and clear out large, old files. If a Smart Update fails with a disk space error, your live site is unaffected -- the update just doesn't happen.

How to turn on Smart Update

  1. Log in to cPanel (from the client area: Services > My Services, choose your plan, then Log in to cPanel).
  2. Go to Domains > WordPress Management (WP Toolkit).
  3. Find your site's card.
  4. Turn on the Smart Update switch on the card.

Smart Update is set per site, so switch it on for each WordPress site you want protected. Leave it off on a staging copy you don't care about -- it'll update faster.

How to run a manual Smart Update

  1. On the site's card, click the updates message (for example Install plugin updates) or Check for Updates.
  2. Tick the updates you want. If a WordPress core update is listed, leave Restore Point ticked.
  3. Click Update.
  4. Wait while WP Toolkit clones, updates and analyzes the copy. It runs in the background, so you can close the window; a small site takes a few minutes, a big one longer.
  5. Open the report when it's ready (from WP Toolkit or the link in the email).

How to read the Smart Update report

  • The forecast. Smart Update tells you whether it thinks the update is safe. It's a strong hint, not a guarantee.
  • Screenshots. Pick a page and look at "before" and "after" side by side, or use the comparison view, which highlights what changed.
  • Issues per page. Select one page at a time to see issues found on it, such as a PHP warning or a page that now returns an error.
  • Website Summary. Issues for the whole site, with the option to download a detailed report. Useful to send to a developer.

Then decide:

  • If no issues were found and the screenshots look right, click Apply Updates and confirm. WP Toolkit updates your live site and deletes the clone.
  • If something broke, click Discard. The live site stays exactly as it was. Note which plugin was being updated, check its changelog and support forum, and try again when a fixed version comes out. You can also update the others without it -- untick the problem one and run the update again.

Telling real problems from false alarms

Screenshots of the same page can differ for harmless reasons. These are usually fine:

  • Sliders, carousels and rotating banners caught on a different slide.
  • "Latest posts", dates, random testimonials or live stock and weather widgets.
  • Ads and embedded social media feeds.
  • A cookie banner appearing in one shot and not the other.

These are real problems -- don't apply:

  • A page that's blank, shows "There has been a critical error", or returns a 500 or 404.
  • Missing menus, broken layout, or unstyled text (CSS not loading).
  • A form, cart or checkout that disappeared.
  • New PHP fatal errors in the issues list.

Smart Update with automatic updates

Smart Update is at its best combined with auto-updates: security fixes go on automatically when they're safe, and risky ones are held back for you to look at. A good setup for a live site:

  1. Turn on Smart Update for the site.
  2. In Autoupdate settings on the card, set WordPress to Yes, but only minor (security) updates.
  3. Set plugins and themes to Defined individually, but security updates are autoinstalled.
  4. Keep an eye on your email. When Smart Update holds back an update, you'll get a report -- read it, then decide whether to apply the update manually, wait for a fix, or replace the plugin.

If you see updates waiting on the site card even though auto-updates are on, Smart Update has probably skipped one. Open the report or run the update manually.

Smart Update limitations

  • It isn't a backup. Keep taking backups before big changes -- see How to Back Up and Restore WordPress in WP Toolkit. Your account is also backed up three times a week with JetBackup 5.
  • It checks pages, not every feature. It can't log in as a customer, submit a form, or place a test order. After a big update to WooCommerce, a booking plugin or a page builder, test those flows yourself.
  • Premium plugins need a valid license in WordPress to update at all. Plugins with unusual update methods may not update through WP Toolkit.
  • It takes longer than a plain update, and briefly uses the extra disk space.
  • Content added during the test (a new order or comment) isn't lost -- the update is applied to your live site, not copied back from the clone.

Vulnerability scanning

WP Toolkit regularly checks your WordPress version, plugins and themes against a database of known security vulnerabilities (the data comes from Patchstack). It tells you when something you have installed -- even a deactivated plugin -- has a published security hole.

Where the warnings appear

  • On the WP Toolkit site list, an affected site is tagged with a security risk label and a number. The number, from 0.1 to 10, estimates how serious the worst issue is. Higher is worse.
  • The site card may also show a call to action such as Mitigate vulnerabilities, or the word Vulnerable.

How to review and fix a vulnerability

  1. In Domains > WordPress Management, click the security risk tag or the vulnerability warning on the site's card. The Security Status panel opens.
  2. Open the Vulnerable Components tab. Each affected item is listed with its risk rating. Click one to see the details of each vulnerability.
  3. For each item:
    • If an update is available that fixes it, update it -- ideally with Smart Update on. This is the right fix almost every time.
    • If it's a plugin or theme you don't use, delete it. Deactivated code can still be attacked.
    • If there's no fix yet, decide how much you need it. For a high-risk issue, deactivate it until a fix is released, or replace it with a maintained alternative. Check the plugin's page on WordPress.org -- a plugin that's been closed or hasn't been updated in years isn't coming back.
  4. Check the card again. Once everything is updated or removed, the warning clears.

Our servers also run security software at the server level, but it doesn't replace updates. A known hole in a plugin is exactly what automated attacks look for.

Troubleshooting

There's no Smart Update switch on my site card

Make sure you're looking at the site's card in Domains > WordPress Management. If the switch isn't there, open a ticket and tell us the site's address.

Smart Update fails every time

Usually disk space. Free some space and try again. If your site is very large, open a ticket.

A vulnerability warning stays after I updated

WP Toolkit rechecks sites regularly, so give it a little time, or click Check for Updates on the card. If the warning still names a version you no longer have, open a ticket -- the scan can occasionally lag behind.

The report says the update is safe, but my site broke

Roll back WordPress core with the restore point, or restore your latest backup. Then open a ticket with the plugin name and the time.

Common questions

Does Smart Update slow down my live site?

No. The clone is tested in the background. Your site may show maintenance mode for a few seconds while the approved updates are actually applied.

Do I still need a staging site?

For quick plugin updates, Smart Update is usually enough. For redesigns, big version jumps or custom code, use a staging site -- see How to Create a WordPress Staging Site and Push It Live.

My site is already hacked. Will this fix it?

No. Updating closes the hole but doesn't remove malware. See What to Do If Your WordPress Site Is Hacked.

Related guides

Still stuck? Open a support ticket and the Instant Access Internet Services team will help.

Ultrafast LiteSpeed hosting from InstantAccess.net: free SSL, free backups, cPanel included, no contracts. Check out our $10/month hosting.
  • wp toolkit smart update, smart updates wordpress cpanel, wp toolkit vulnerability scan, wordpress vulnerable plugins, safe wordpress updates, wp toolkit security risk, smart update report, mitigate vulnerabilities wp toolkit
  • 0 Benutzer fanden dies hilfreich
War diese Antwort hilfreich?

Mehr zum Thema

How to Create a WordPress Staging Site and Push It Live

A staging site is a private copy of your WordPress website where you can test new plugins, theme...

How to Install WordPress with WP Toolkit in cPanel

WP Toolkit lets you install WordPress on your hosting account in a couple of minutes, with no...

How to Log In to WordPress Admin from WP Toolkit

You don't need to remember your WordPress password to get into your site. WP Toolkit in cPanel...

How to Update WordPress, Plugins and Themes (and Turn On Auto-Updates)

Keeping WordPress up to date is the single best thing you can do to keep your site safe. This...

How to Move a WordPress Site from Another Host (WP Toolkit Import)

Moving a WordPress site from another host doesn't have to mean downtime or lost content. This...