WordPress not updating automatically: find the cause and fix it
WordPress installs its security releases by itself — unless something stops it. When a release fixes a flaw that's already being exploited, like 7.1.2 in September 2026, the site that quietly didn't update is the one at risk, and the dashboard won't tell you. Relvato's vulnerability scan checks the version that's really installed and names what stopped the update. Here's each cause and its fix.
See what's really installed
Don't rely on the number on the dashboard alone: after an interrupted update it can differ from the files. With shell access, run wp core version. Or open the site's Vulnerability scan in Relvato: it reads the version from wp-includes/version.php, checks it against wordpress.org's list of insecure versions, and flags it — critical when the flaw is in CISA's list of exploited vulnerabilities.
When the version is behind, the finding says why WordPress didn't update itself, from the causes below. The Relvato plugin 1.34.0 or newer reports them from inside the site.
Automatic updates are switched off in wp-config.php
Look in wp-config.php for WP_AUTO_UPDATE_CORE set to false, or AUTOMATIC_UPDATER_DISABLED set to true. Both are often left over from a migration or a developer who wanted control. Remove the line, or set define( 'WP_AUTO_UPDATE_CORE', 'minor' ); so security releases install while major versions wait for you.
With WP_AUTO_UPDATE_CORE set to 'minor', a fix that only ships in a new major version won't install by itself — update from Dashboard → Updates.
DISALLOW_FILE_MODS blocks every change to the site's files, so it stops updates too. If you need it, plan to update by deploying instead.
A plugin or your theme switches updates off
Some plugins turn automatic updates off with a filter — clean-up and performance plugins often have a switch for it. Relvato names the plugin it can trace the filter to. Turn that switch off in the plugin's settings, or remove the plugin. A filter added with one of WordPress's own helper functions can't be traced to who added it; check your theme's functions.php and must-use plugins.
WP-Cron isn't running
WordPress checks for updates twice a day as a scheduled task. With DISABLE_WP_CRON set, scheduled tasks only run if the server calls wp-cron.php itself — and if nobody set that up, the update check never runs. Add a server cron job that requests your site's /wp-cron.php every 5–15 minutes, or remove DISABLE_WP_CRON.
Without DISABLE_WP_CRON, scheduled tasks run on visits. A site with very little traffic, or a firewall that blocks wp-cron.php, can fall days behind. A server cron fixes that too.
WordPress can't write its own files
If WordPress needs FTP or SSH details to change files, it can't update itself in the background. Fix the file ownership so the web server user owns the WordPress files (your host can do this), or set FS_METHOD to direct when the permissions allow it.
A failed attempt is shown with WordPress's own error — files_not_writable, for example, means the same thing.
Other causes
A version-control checkout: if the site folder contains .git or .svn, WordPress doesn't update itself there. Update through your deploy instead.
A stuck update: an update that crashed can leave a lock behind (core_updater.lock). It clears itself after about 15 minutes; if Relvato says it has been stuck for hours, delete that option or run the update from Dashboard → Updates.
The host: some hosts hold minor updates for a few hours, or install them overnight. If nothing above applies, check again the next day.
Change control: on sites where every update waits for review, a security release is exactly the one not to queue behind a holiday. Agree in advance that security releases go out the same day.
FAQ
Does Relvato update WordPress for me?
No. Unlike a plugin update, a WordPress core update can't be rolled back cleanly, so Relvato tells you what's wrong and how to fix it, and you update from Dashboard → Updates or your deploy.
Which sites does this cover?
WordPress sites connected with the Relvato plugin 1.34.0 or newer and the Vulnerability scan turned on. It runs with the scan's schedule.
Why does it say my version is insecure when auto-updates are on?
Because the version on disk is one wordpress.org lists as insecure, whatever the settings say. The finding names what stopped the update; when nothing blocks it, the host is usually holding it for a few hours.