Process
How often should I update WordPress?
Security releases immediately, everything else monthly with a backup taken first. An unpatched WordPress install is the most common route to a hacked small-business site, and the risk grows with every plugin.
A workable schedule
- Security releases — within days, ideally automatically
- Core minor updates — monthly
- Plugins — monthly, after a backup, checking the site afterwards
- Major core versions — within a few weeks, on staging first if the site is complex
- Remove any plugin nothing uses, which is the cheapest security work available
Why plugin count is the real variable
Every plugin is an update that can break something and a security surface nobody is watching. A site with eight plugins is meaningfully safer and faster than the same site with thirty, and most of the thirty are doing nothing.
The non-negotiable prerequisite
A backup you have actually restored at least once. A backup nobody has tested is a hypothesis, and the moment you need it is the worst possible time to discover it does not work.
The longer version
This answer is deliberately short. If you want the full treatment, Who actually owns your website — a checklist you can verify today covers it in about 3 minutes — free, ungated, written from client work.
Who answered this
Anas Bin Masud builds e-commerce sites and does technical SEO for businesses in the UK, Canada and Pakistan — fifteen live client sites, six of them stores taking real payments. These answers come from those projects rather than from a content brief. More about how I work, or ask me something directly.