<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Archive - start the loop_</title>
	<atom:link href="https://start-the-loop.com/en/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>https://start-the-loop.com/en/category/security/</link>
	<description>WordPress made easy</description>
	<lastBuildDate>Wed, 02 Sep 2026 16:58:25 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://start-the-loop.com/wp-content/uploads/2018/11/cropped-favicon-32x32.png</url>
	<title>Security Archive - start the loop_</title>
	<link>https://start-the-loop.com/en/category/security/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Securing WordPress easily and efficiently</title>
		<link>https://start-the-loop.com/en/securing-wordpress-easily-and-efficiently/</link>
		
		<dc:creator><![CDATA[Elisabeth]]></dc:creator>
		<pubDate>Thu, 19 Feb 2026 13:11:29 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[newsletter_04]]></category>
		<guid isPermaLink="false">https://start-the-loop.com/?p=15567</guid>

					<description><![CDATA[<p>Securing a WordPress website is actually not difficult. Basically, it&#8217;s just normal housekeeping that makes your website more secure. There are some simple but very effective measures you can take to protect your website. What you easily can do yourself 1. Updates, Updates, Updates At the top of the list is keeping all plugins, themes, [&#8230;]</p>
<p>The post <a href="https://start-the-loop.com/en/securing-wordpress-easily-and-efficiently/">Securing WordPress easily and efficiently</a> has first been published on <a href="https://start-the-loop.com/en">start the loop_</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>Securing a WordPress website is actually not difficult. Basically, it&#8217;s just normal housekeeping that makes your website more secure. There are some simple but very effective measures you can take to protect your website.</strong></p>



<h2 class="wp-block-heading">What you easily can do yourself</h2>



<h3 class="wp-block-heading">1. Updates, Updates, Updates</h3>



<p class="wp-block-paragraph">At the top of the list is keeping all plugins, themes, and even the WordPress core up to date. Regular updates close known security gaps that attackers specifically exploit. Updates therefore not only bring new features, but above all important security patches.</p>



<h3 class="wp-block-heading">2. Sensible user capabilities</h3>



<p class="wp-block-paragraph">Not every user needs admin capabilities – usually, one administrator account is sufficient. All other user should only get the capabilities they need in order to do their job. This limits the damage if a user account is compromised. A hacked editor account is significantly less critical than administrator access.</p>



<h3 class="wp-block-heading">3. Delete inactive plugins</h3>



<p class="wp-block-paragraph">Be sure to only use plugins and themes that are actively maintained. Sometimes the author loses interest or an extension is no longer updated for other reasons. Themes and extensions that are no longer maintained pose a major security risk and should be removed promptly.</p>



<p class="wp-block-paragraph">The same applies to plugins and themes that are not actively used. You try out a plugin or theme and then deactivate it again. We don&#8217;t delete them right away because we might use them after all. You should also keep an eye on this list and delete everything that is not being used.</p>



<h3 class="wp-block-heading">4. Only use trustworthy sources</h3>



<p class="wp-block-paragraph">Only obtain themes and plugins from official and trustworthy sources. Supposed bargains, where paid extensions are offered for free or at very low prices, usually contain malicious code. This puts your entire website at risk.</p>



<h3 class="wp-block-heading">5. Secure Access</h3>



<p class="wp-block-paragraph">You should always use strong credentials, which means, above all, good passwords (see box). Never reuse passwords, even if it makes them easier to remember. Avoid the default username &#8220;admin&#8221;, as this is always the first one tried in brute force attacks. Each user should have their own account with a secure, unique password and only be granted the necessary rights.</p>



<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8d39b2df wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:60%">
<p class="wp-block-paragraph">For particularly sensitive access points—primarily administrator accounts—it makes sense to set up two-factor authentication (2FA).</p>



<p class="wp-block-paragraph">On websites with many users, you no longer have direct control over the strength of passwords. In this case, it is worth installing a plugin that enforces strong passwords. Weak login credentials are the biggest security risk for any website.</p>
</div>



<div class="wp-block-column has-main-accent-background-color has-background is-layout-flow wp-block-column-is-layout-flow" style="border-top-color:var(--wp--preset--color--primary-alt);border-top-width:8px;border-right-style:none;border-right-width:0px;border-bottom-style:none;border-bottom-width:0px;border-left-style:none;border-left-width:0px;padding-top:var(--wp--preset--spacing--small);padding-right:var(--wp--preset--spacing--small);padding-bottom:var(--wp--preset--spacing--small);padding-left:var(--wp--preset--spacing--small);flex-basis:33.33%">
<h4 class="wp-block-heading" style="margin-bottom:0;font-style:normal;font-weight:500">A good password should&#8230;</h4>



<ul style="margin-top:var(--wp--preset--spacing--small)" class="wp-block-list">
<li style="margin-top:0">consist of at least 12 characters</li>



<li>contain upper and lower case letters</li>



<li>use numbers and special characters</li>



<li>not contain real words</li>



<li>not be used more than once</li>
</ul>
</div>
</div>



<h3 class="wp-block-heading">6. Don&#8217;t skimp on hosting</h3>



<p class="wp-block-paragraph">A good hosting provider protects its servers with a modern, secure infrastructure, creates regular backups, and provides expert support in case of problems. This is an important basis for the security of your website.</p>



<h2 class="wp-block-heading">Hide login?</h2>



<p class="wp-block-paragraph">Very often, I read the following advice: you should hide the login page. This is not difficult to implement; the WP login is simply assigned a different URL. I don&#8217;t consider this measure to be very effective, because attackers can also find hidden login pages. It is better to focus on strong usernames and secure passwords.</p>



<h2 class="wp-block-heading">And what about security plugins?</h2>



<p class="wp-block-paragraph">There are many offerings in the <a href="https://wordpress.org/plugins/">plugin directory</a> under the keyword “security”. These plugins promise fast, comprehensive protection for all situations. They are available in free versions via WordPress.org or in premium versions for an annual license fee. They usually offer functions from the following areas:</p>



<ul class="wp-block-list">
<li>Firewall, i.e., login attempts are logged and, if necessary, the IP addresses from which the attempts originate are blocked.</li>



<li>The malware scanner checks the installation for potential malicious code and compares the plugins with lists of known security vulnerabilities.</li>



<li>Ways to secure user accounts and logins, e.g., by requiring strong passwords.</li>
</ul>



<p class="wp-block-paragraph">Many of these functions can also be handled by a good hosting provider. Depending on your hosting provider&#8217;s security standards, you may not even be allowed to install any security plugins. This is not a disadvantage, but a sign that the hosting company takes the issue seriously and takes care of it. You can often configure individual aspects in your customer menu.</p>



<p class="wp-block-paragraph">The appeal of a security plugin is that it guides users through all of the above security aspects. The functions are brought together in a dashboard, where everything is clearly displayed and (ideally) well explained. However, if you want to use more than just the basic functions, you usually need the paid version. For those who have a more affordable hosting plan, a security plugin can increase the security of the website.</p>



<p class="wp-block-paragraph">Instead of installing a large extension with many functions, you can also manage many aspects individually. For example, you can install a plugin that enforces strong passwords and, ideally, requires two-factor authentication for certain user groups. Or one that only allows a certain number of login attempts.</p>



<p class="wp-block-paragraph">I also have other options for security scans; there are plugins and services that offer this service, either free of charge or for a fee. This often comes together with the backup function: a plugin that regularly creates backups and sends them to another server, if possible, can usually also initiate a security scan.</p>



<h2 class="wp-block-heading">Conclusion on security plugins</h2>



<p class="wp-block-paragraph">Security plugins can help make the complex topic of security easier to understand. Some things may not seem absolutely necessary at first glance—I&#8217;m thinking, for example, of hiding the WordPress login. But when used correctly, these plugins can be helpful.</p>



<p class="wp-block-paragraph">It is important to note that security plugins in particular require meticulous attention when it comes to updates. After all, these tools have extensive rights in the system and interfere deeply with a website. If a security vulnerability remains open here, the security plugin itself becomes a security risk.</p>



<p class="wp-block-paragraph">The usefulness of a security plugin depends not least on the hosting. If your website is hosted by a provider that already offers sophisticated firewalls and malware protection, installing an additional extension does not add much value. <br>Security plugins can also lead to a false sense of security: if weak passwords are in use or there are many unmonitored admin accounts, the back door is wide open. Even a security plugin cannot prevent this.</p>
<p>The post <a href="https://start-the-loop.com/en/securing-wordpress-easily-and-efficiently/">Securing WordPress easily and efficiently</a> has first been published on <a href="https://start-the-loop.com/en">start the loop_</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Password Manager</title>
		<link>https://start-the-loop.com/en/password-manager/</link>
		
		<dc:creator><![CDATA[Elisabeth]]></dc:creator>
		<pubDate>Fri, 06 Feb 2026 11:44:49 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://start-the-loop.com/?p=15467</guid>

					<description><![CDATA[<p>A secure password consists of at least 12 characters that are chosen at random. However, no one can remember a bunch of random characters. Even writing them down on scraps of paper and Post-its quickly reaches its limits. The best way to manage secure passwords is with a password manager. This kind of software remembers [&#8230;]</p>
<p>The post <a href="https://start-the-loop.com/en/password-manager/">Password Manager</a> has first been published on <a href="https://start-the-loop.com/en">start the loop_</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>A secure password consists of at least 12 characters that are chosen at random. However, no one can remember a bunch of random characters. Even writing them down on scraps of paper and Post-its quickly reaches its limits.</strong></p>



<p class="wp-block-paragraph">The best way to manage secure passwords is with a password manager. This kind of software remembers all your passwords and stores them securely and encrypted. It allows you to sort and organize your passwords easily. You can add notes and see when you last changed a password, among other things. </p>



<p class="wp-block-paragraph">Password managers also offer a solution to a very common security problem: using the same password multiple times. I once had a very well-thought-out password that I used in many different places. Unfortunately, this greatly increases the risk of access data falling into the wrong hands. All it takes is one leaked list containing the password.</p>



<p class="wp-block-paragraph">Password managers are available for all operating systems (Windows, Mac, Linux) as well as for smartphones and mobile devices (Android, iOS). The software is quite convenient; for instance, it usually provides extensions for web browsers. The password manager also saves the URL of a login page and immediately suggests the correct combination of username and password.</p>



<p class="wp-block-paragraph">This might also protect you from fake websites, as your password manager will not provide the login data since the URL is unknown. (Unfortunately, you certainly are able to add it manually. But maybe the short moment of surprise is enough to make you realize that something is not right.)</p>



<p class="wp-block-paragraph">Three of the best known password managers are:</p>



<ol class="wp-block-list">
<li><strong>1Password</strong> – A widely used password manager with many features for individuals and teams.<br><a href="https://1password.com/">Visit the website of 1Password</a></li>



<li><strong>Bitwarden</strong> – Open-source password manager with secure encryption and cross-platform use.<br><a href="https://bitwarden.com/">Visit the website of Bitwarden</a></li>



<li><strong>Keeper</strong> – Great if you need to share passwords with others<br><a href="https://www.lastpass.com/">Visit the website of LastPass</a></li>
</ol>



<p class="wp-block-paragraph"><a href="https://www.wired.com/story/best-password-managers/">This article in Wired gives you a short overview over some of the password managers.</a></p>
<p>The post <a href="https://start-the-loop.com/en/password-manager/">Password Manager</a> has first been published on <a href="https://start-the-loop.com/en">start the loop_</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What exactly do we need to protect our websites from?</title>
		<link>https://start-the-loop.com/en/what-exactly-do-we-need-to-protect-our-websites-from/</link>
		
		<dc:creator><![CDATA[Elisabeth]]></dc:creator>
		<pubDate>Fri, 06 Feb 2026 11:42:19 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[newsletter_04]]></category>
		<guid isPermaLink="false">https://start-the-loop.com/?p=15475</guid>

					<description><![CDATA[<p>Most attacks on WordPress are not motivated by personal reasons. Targeted attacks, such as those on political websites, are very rare. In most cases, attackers are after other things, even when there is “nothing to gain.” Shops store payment data, member sites have user accounts. This data — names, email addresses, passwords, payment information— can [&#8230;]</p>
<p>The post <a href="https://start-the-loop.com/en/what-exactly-do-we-need-to-protect-our-websites-from/">What exactly do we need to protect our websites from?</a> has first been published on <a href="https://start-the-loop.com/en">start the loop_</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Most attacks on WordPress are not motivated by personal reasons. Targeted attacks, such as those on political websites, are very rare. In most cases, attackers are after other things, even when there is “nothing to gain.”</p>



<p class="wp-block-paragraph">Shops store payment data, member sites have user accounts. This data — names, email addresses, passwords, payment information— can be stolen and converted into cash. On websites where user data is stored, the data is usually the target of an attack.</p>



<p class="wp-block-paragraph">But what if there is no user data on the website at all? Does that automatically protect me against attacks? <br>Unfortunately not. Because it&#8217;s not just data that is of value to attackers.</p>



<h2 class="wp-block-heading">Taking control of the website</h2>



<p class="wp-block-paragraph">Gaining control of a website is by far the most common motive for cybercriminals to attack a website. The goal is to gain admin access or server access. Anyone with access can insert malicious code. </p>



<p class="wp-block-paragraph">Compromised websites are used to send spam emails, redirect users to phishing sites, or host malware. There are many ways to use a website for criminal purposes: gambling, pornography, fake shops, SEO spam (backlinks for other sites), affiliate fraud, and so on.</p>



<p class="wp-block-paragraph">Search engine bots often detect malicious code on a website before the owners themselves do. The website is then classified as dangerous and the search engine removes the site from its index, marking it no longer accessible. Associated email addresses are also affected by such a block, they are blacklisted: All emails are marked as spam.</p>



<p class="wp-block-paragraph">This can quickly result in quite extensive damage. Cleaning it up involves a lot of work. Without the help of a professional service provider, it is close to impossible for most website owners. Even if you detect and delete the malicious code, the attackers will almost certainly have left an open “backdoor” through which they can inject new malicious code at any time. Finding this backdoor is not easy. And there is no quick solution for rebuilding the site&#8217;s good reputation and search engine ranking.</p>



<p class="wp-block-paragraph"><em>At this point, it pays to have a reliable hosting company who takes security of their servers seriously: If malicious code is detected by your hosting company, they will take your website offline immediately. This way, you hopefully can avoid all the problems that come with being blacklisted</em>.</p>
<p>The post <a href="https://start-the-loop.com/en/what-exactly-do-we-need-to-protect-our-websites-from/">What exactly do we need to protect our websites from?</a> has first been published on <a href="https://start-the-loop.com/en">start the loop_</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Auto-updates on WordPress</title>
		<link>https://start-the-loop.com/en/auto-updates-on-wordpress/</link>
		
		<dc:creator><![CDATA[Elisabeth]]></dc:creator>
		<pubDate>Tue, 04 Nov 2025 09:04:07 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[newsletter_03]]></category>
		<guid isPermaLink="false">https://start-the-loop.com/?p=14737</guid>

					<description><![CDATA[<p>Updates are very important for website security. Security gaps are closed, and outdated functions are replaced with new ones. But you have to remember to do it. It's good that there is an option for automatic updates.</p>
<p>The post <a href="https://start-the-loop.com/en/auto-updates-on-wordpress/">Auto-updates on WordPress</a> has first been published on <a href="https://start-the-loop.com/en">start the loop_</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>It is very important for website security that every component is up to date. Security gaps are closed, and outdated functions are replaced with new ones. But you have to remember to do it. It&#8217;s good that there is an option for automatic updates.</strong></p>



<p class="wp-block-paragraph">New versions of plugins are released relatively frequently. Depending on the number of plugins used on a website, updates may be required almost daily. The WordPress core, i.e., the WordPress CMS itself, receives minor updates approximately every 1 to 2 months, with a new version released about twice a year. Themes also receive updates, but less frequently than plugins. Updates are often security-related. So if a plugin offers an update, please do not ignore it.</p>



<p class="wp-block-paragraph">Updates that close a known security vulnerability should always be installed as soon as possible.</p>



<h2 class="wp-block-heading">Which plugins should be allowed to update automatically?</h2>



<p class="wp-block-paragraph">I roughly divide plugins into three groups:</p>



<ul class="wp-block-list">
<li>Plugins that are indirectly or directly important for the SECURITY of the website. These can be one of the common security plugins, plugins that create backups, and similar plugins. What they have in common is that they have nothing to do with the display of the website. At the same time, they usually have far-reaching permissions and can quickly become a risk.</li>



<li>Plugins that are essential for the DISPLAY and FUNCTION of the website. Examples include WooCommerce for a shop, LearnDash for an e-learning platform, and, of course, all the additional plugins that you need to go with them.</li>



<li>Plugins that do not affect the appearance or functionality but are useful tools. These include “KoKo Analytics,” “Yoast SEO,” “Enable Media Replace,” maintenance plugins, or something like “Admin Columns.”</li>
</ul>



<p class="wp-block-paragraph">Before enabling automatic updates for a plugin, you should ask yourself the following questions:</p>



<ul class="wp-block-list">
<li>How high is the risk if this plugin runs in an outdated version?</li>



<li>How big is the danger that something on the website will break because of the automatic update? Like, for example, the display not working anymore, or the shop having a problem?</li>
</ul>



<p class="wp-block-paragraph">In addition, conflicts can always arise when two plugins clash after an update. Unfortunately, this cannot be completely ruled out.</p>



<h3 class="wp-block-heading">Plugins that I usually update automatically</h3>



<p class="wp-block-paragraph">The plugins in the first group, i.e., those that are security-related but run in the background, are usually at the top of my list for automatic updates. Especially if a security vulnerability becomes known, I want it to be closed as quickly as possible.</p>



<p class="wp-block-paragraph">I also frequently use automatic updates for plugins in the third group. This applies to all useful tools that are not directly responsible for the website&#8217;s appearance to visitors. As a rule, they should not cause errors that impair the functionality of the website.</p>



<h3 class="wp-block-heading">Plugins for which I initiate updates manually</h3>



<p class="wp-block-paragraph">I don&#8217;t usually allow automatic updates for plugins that are essential for a web shop, an e-learning platform, or a booking system, for example. I usually read through the changelog before updating. This tells me what changes the update brings. If it&#8217;s only a minor update, the list is relatively short.<br>This helps me to identify potential sources of trouble. In other words, I know where I need to look more closely after the update.</p>



<p class="wp-block-paragraph">With very complex systems, such as a WooCommerce shop or an e-learning platform, I have to take a close look and test thoroughly. Ideally, these updates should first take place in a staging environment, i.e., an exact copy of the website in the same environment as the live website. This allows you to update without serious consequences. If something does go wrong, you can take your time to search for the error.</p>



<h2 class="wp-block-heading">How do I enable automatic updates?</h2>



<p class="wp-block-paragraph">Since WordPress version 3.7, it has been possible to select the option to automatically install updates for a plugin on the plugin overview page. For free plugins, updates usually come via WordPress.org. For premium plugins, for which you have purchased a license via the plugin&#8217;s website or a platform, these updates are usually delivered by these websites. In rare cases, you may need to download the latest version as a file and reinstall it.</p>



<p class="wp-block-paragraph">If automatic updates have been enabled, they are usually performed once a day. Sometimes the plugin page will also indicate that an update is scheduled in x hours. Once the update is complete, the system will email the administrator&#8217;s address. If there were any problems during the update, you will also receive a message. <br>It is therefore important to use a current email address as the admin address so that you receive these emails.</p>



<figure data-wp-context="{&quot;imageId&quot;:&quot;6a9ad81f598de&quot;}" data-wp-interactive="core/image" data-wp-key="6a9ad81f598de" class="wp-block-image size-medium wp-lightbox-container"><img fetchpriority="high" decoding="async" width="600" height="244" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on--click="actions.showLightbox" data-wp-on--load="callbacks.setButtonStyles" data-wp-on--pointerdown="actions.preloadImage" data-wp-on--pointerenter="actions.preloadImageWithDelay" data-wp-on--pointerleave="actions.cancelPreload" data-wp-on-window--resize="callbacks.setButtonStyles" src="https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-auto-updates_wordpress-600x244.png" alt="" class="wp-image-14742" srcset="https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-auto-updates_wordpress-600x244.png 600w, https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-auto-updates_wordpress-1520x617.png 1520w, https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-auto-updates_wordpress-400x162.png 400w, https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-auto-updates_wordpress-768x312.png 768w, https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-auto-updates_wordpress-1536x624.png 1536w, https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-auto-updates_wordpress-1320x536.png 1320w, https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-auto-updates_wordpress.png 1754w" sizes="(max-width: 600px) 100vw, 600px" /><button
			class="lightbox-trigger"
			type="button"
			aria-haspopup="dialog"
			data-wp-bind--aria-label="state.thisImage.triggerButtonAriaLabel"
			data-wp-init="callbacks.initTriggerButton"
			data-wp-on--click="actions.showLightbox"
			data-wp-style--right="state.thisImage.buttonRight"
			data-wp-style--top="state.thisImage.buttonTop"
		>
			<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewBox="0 0 12 12">
				<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" />
			</svg>
		</button></figure>



<p class="wp-block-paragraph">Core updates from the WordPress system can also be updated automatically. Here, you can choose whether only minor updates, which usually contain security patches, should be performed, or whether major WordPress updates should also be performed automatically.</p>



<figure data-wp-context="{&quot;imageId&quot;:&quot;6a9ad81f59d58&quot;}" data-wp-interactive="core/image" data-wp-key="6a9ad81f59d58" class="wp-block-image size-medium wp-lightbox-container"><img decoding="async" width="600" height="271" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on--click="actions.showLightbox" data-wp-on--load="callbacks.setButtonStyles" data-wp-on--pointerdown="actions.preloadImage" data-wp-on--pointerenter="actions.preloadImageWithDelay" data-wp-on--pointerleave="actions.cancelPreload" data-wp-on-window--resize="callbacks.setButtonStyles" src="https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-updates-WordPress_Core-600x271.png" alt="" class="wp-image-14743" srcset="https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-updates-WordPress_Core-600x271.png 600w, https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-updates-WordPress_Core-400x180.png 400w, https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-updates-WordPress_Core-768x346.png 768w, https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-updates-WordPress_Core-1320x595.png 1320w, https://start-the-loop.com/wp-content/uploads/2025/11/screenshot-updates-WordPress_Core.png 1486w" sizes="(max-width: 600px) 100vw, 600px" /><button
			class="lightbox-trigger"
			type="button"
			aria-haspopup="dialog"
			data-wp-bind--aria-label="state.thisImage.triggerButtonAriaLabel"
			data-wp-init="callbacks.initTriggerButton"
			data-wp-on--click="actions.showLightbox"
			data-wp-style--right="state.thisImage.buttonRight"
			data-wp-style--top="state.thisImage.buttonTop"
		>
			<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewBox="0 0 12 12">
				<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z" />
			</svg>
		</button><figcaption class="wp-element-caption">Maintenance and security releases active, but not new versions of WordPress </figcaption></figure>



<h2 class="wp-block-heading">Pay attention to silent warning signs</h2>



<p class="wp-block-paragraph">It sometimes happens that a plugin is no longer being maintained. In other words, there will be no more updates at some point. This happens very quietly, and it is very easy to overlook. One indication is when the “auto-update” option disappears, meaning that the plugin can no longer be accessed via the WordPress repository.</p>



<p class="wp-block-paragraph">In most cases, the old plugin still works, but it is no longer state-of-the-art and potentially unsafe. In this case, you should swiftly look for a replacement.</p>



<p class="wp-block-paragraph">An exception would be if the plugin authors deliberately remove the plugin from the WordPress repository. In this case, however, a note would appear indicating where to get updates in the future and, above all, how to proceed in order to obtain them.</p>



<h2 class="wp-block-heading">When an update goes wrong</h2>



<p class="wp-block-paragraph">Every now and then, an update causes the website to crash. In the worst case, all you see is the dreaded “white screen of death.” Then you have to find out what the culprit is and, if possible, revert to an earlier version of the respective theme or plugin. If that is not possible or practical, you have to consider whether you can replace or even delete the plugin.</p>



<hr class="wp-block-separator has-text-color has-border-light-color has-alpha-channel-opacity has-border-light-background-color has-background"/>


<p>The post <a href="https://start-the-loop.com/en/auto-updates-on-wordpress/">Auto-updates on WordPress</a> has first been published on <a href="https://start-the-loop.com/en">start the loop_</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
