Product
Solutions
Compare
Resources
Get early access Talk to us
Maintenance automation

Automate WordPress maintenance without gambling on it

Automation fails when it acts without checking. WPCentrify automates the routine and verifies every action, so the failure mode is an automatic rollback and an alert rather than a broken site nobody noticed.

Free during early access. Connects to any host.

Updated

What you get

Included on every plan

  • A judgment about risk: Not every update carries the same risk.
  • A way back: A restore point taken immediately before the change, not last night's scheduled backup.
  • Verification after the fact: Health checks, visual comparison and functional testing.
  • Automatic reversal: If verification fails, the rollback has to happen without waiting for a human.

How do you automate WordPress maintenance?

You automate WordPress maintenance by letting a management tool run the routine on a schedule, such as updates, backups, uptime and security checks and client reports, and keeping people for the exceptions. What makes it safe is that every automated change has a way back and a check afterwards.

WPCentrify runs that routine for every site you connect: scheduled backups, uptime checks every 60 seconds, security monitoring with Sentinel and reports on a schedule. Automation rules can apply updates, hold them back or take a backup when something happens, and a rule that changes a site refuses to run unless a way back exists first. An update that leaves a site broken is rolled back automatically.

What WPCentrify automates

  • Backups on a schedule, stored off the website.
  • Uptime checks every 60 seconds and vulnerability checks every day.
  • Updates through rules that refuse to run without a way back.
  • Automatic rollback after a PHP fatal error, a 5xx server error or a visual break.
  • Client reports sent on the schedule you set.

Why people turn automatic WordPress updates off

WordPress has offered automatic updates for years and a large proportion of serious site owners disable them. Not because they enjoy manual work, but because core automatic updates do very little around the change. Since WordPress 6.6 a plugin auto-update that causes a PHP fatal error is rolled back, but there is no full backup taken first, no check for server errors or visual breaks afterwards, and no way back from an update that breaks the layout without crashing the site. One bad release and the site can be broken with nobody watching.

So people turn it off, intend to update manually, and fall behind. Which produces exactly the outcome automatic updates were meant to prevent: sites running known-vulnerable plugin versions for months. If you would rather keep WordPress's own updater, our guide to WordPress automatic updates shows how to set it up safely.

Capability

What safe automation requires

A judgment about risk

Not every update carries the same risk. A patch release with a clean history on a brochure site is not a major version touching checkout on a store, and automation that treats them identically is not trustworthy.

A way back

A restore point taken immediately before the change, not last night's scheduled backup. Rollback should lose nothing.

Verification after the fact

Health checks, visual comparison and functional testing. Something has to look at the result and decide whether it is acceptable.

Automatic reversal

If verification fails, the rollback has to happen without waiting for a human. Detection without response is just a better alarm.

Escalation that reaches someone

When automation cannot resolve something, it needs a path to a person, with enough context to act on.

An explainable record

Every automated decision logged with the rule that triggered it. Automation you cannot audit is automation you cannot trust.

Approaches

WordPress workflow automation: what to automate, in order

Recommended

Automate first

  • Backups and restore testing
  • Uptime and performance monitoring
  • Vulnerability matching and alerting
  • Report generation from the activity log

Automate once you trust it

  • Low-risk patch releases on non-critical sites
  • Security patches with verification
  • Ticket creation on failure

Keep manual, probably forever

  • Major version upgrades on revenue-critical sites
  • Replacing an abandoned plugin
  • Anything during a client's campaign week
  • Design and content decisions
Getting there

Building automation you can trust

STEP 01

Run in notify-only mode

Rules evaluate and report what they would have done without acting. Watch the decisions for two or three weeks and see whether you agree with them.

STEP 02

Enable on the sites that matter least

Internal sites, low-traffic brochure sites and anything you would not lose sleep over. Build confidence where the cost of being wrong is low.

STEP 03

Expand by risk band, not by site count

Once low-risk updates run cleanly for a month, widen the band. Do not jump straight to automating major versions on a store.

STEP 04

Review the log monthly

Look at what automation did, what it escalated, and whether the escalations were correct. Tighten or loosen from evidence rather than instinct.

Answers

Frequently asked questions

Only when the automation verifies its own work. Applying updates without a pre-update restore point, post-update health checks and automatic rollback is a gamble. With those three things in place, automated updating is considerably safer than manual updating, because verification runs consistently rather than when someone remembers.

Verification catches it and the rollback runs, typically within a minute. The failing version is pinned so it cannot be retried by accident, a ticket is opened, and you get an alert with the specific check that failed and the before and after screenshots.

Yes. Policy is set per site, per client or per care plan tier, and more specific scopes override broader ones. Most people automate aggressively on brochure sites and conservatively on stores.

No, and any tool claiming otherwise is overselling. It absorbs roughly two thirds of routine work. What remains is the part that needed a person: judgment calls, client conversations, and the genuinely ambiguous cases that were previously getting the least attention.

Updates, backups, uptime and SSL checks, vulnerability checks and client reports can all run on a schedule. Judgment stays with people: whether a major new version suits a site, what to tell a client, and fixing what a check found.

Early access open

Stop logging into forty dashboards

Connect your first site in under two minutes. No credit card, no contract.

Free during early access. Keep your data, export any time.