Skip to content

WordPress

Choose WordPress when creating a site and it’s ready to log into within a couple of minutes — core, an admin account and a database, already connected and configured.

Turn on managed updates from the site’s WordPress page, and OPanel keeps core, plugins and themes current on a schedule, without the risk of a bad update taking your site down: every update run

  1. Snapshots the site first (files and database).
  2. Updates core, plugins and themes as your settings allow.
  3. Checks that the site still works — the home page, the login page, and any extra URLs you specify still respond correctly, with no new PHP errors.
  4. Rolls back automatically, restoring the pre-update snapshot, if anything fails the check.

You’re notified by email whenever an update changes something or gets rolled back.

Your plan sets sensible defaults (minor core releases, running daily within a maintenance window), which you can narrow from the site’s WordPress → Settings page if your plan allows it:

Setting Options
Core updates Off, minor releases only, or every release
Plugin updates Off, all, or a selected list
Theme updates Off or all
Extra URLs to check Up to ten paths, beyond the home and login pages
Notifications On or off
Hold failed updates Keep retrying a version that failed, or skip it until a newer one is available

Update now on the WordPress page queues an update immediately, limited to a small number of manual updates per day (your plan sets the exact number) to keep the update process from being used as a denial-of-service vector against your own site.

This is rare, but if it happens, you’re emailed with exactly what to do, and your provider’s operators are notified as well — your snapshot is preserved either way, so nothing is lost.

Every WordPress site is scanned regularly — core and plugin files are checked against WordPress.org’s own checksums, and every file is checked for known malware patterns. If something turns up, the site’s Malware page shows:

  • What was found, in plain language, with the exact file and why it was flagged
  • A severity (low to critical)
  • A recommended fix: quarantine it, reinstall WordPress’s core files, or review it yourself

You can quarantine a suspicious file yourself (it’s moved to a recoverable trash, not deleted outright), mark a finding as a false positive if you’re sure it’s safe, or reinstall WordPress’s core files in one click if core files were modified. High and critical findings trigger an email to your site’s owners automatically.