Inventory first

List installed plugins, themes, PHP version, database engine and any custom code. Record dependencies and required licenses.

Back up recoverably

Back up both files and database. Keep a recovery copy separate from the production account. Validate restore procedures on a suitable isolated environment before high-impact updates.

Update workflow

1. Read important compatibility notes. 2. Update one risky component at a time where practical. 3. Verify core pages, search, forms, login and checkout. 4. Check server and application logs. 5. Roll back promptly if critical flows fail.

Security baseline

Remove abandoned plugins, limit admin accounts, enable appropriate login protection and avoid unsupported PHP releases. See WordPress security guidance.

Editorial note

Examples are starting points, not production security audits. Confirm dependencies, versions and pricing using linked vendor documentation.