Who Keeps Your Business WordPress Website Updated?

A business website can look fine while its maintenance responsibilities are unclear. The owner assumes the designer handles updates. The designer assumes the host does. Someone clicks “update” occasionally, but nobody knows when the last usable backup was made or who would recover the site if an update broke it.

The useful question is not simply, “Is WordPress set to update automatically?” It is, “Who is accountable for keeping this particular website current, recoverable, and able to receive customer inquiries?”

Managed WordPress.com and self-hosted WordPress are different

WordPress.com is a managed hosting service. It manages WordPress core for sites on its platform, while backup access and plugin capabilities depend on the plan. Its current backup documentation says automatic, user-accessible backups and restores are included with eligible Business and Commerce plans; other plans can export content and media, but an export is not the same as a complete site backup.

A self-hosted WordPress site uses the WordPress software on a separate hosting account. The host may provide automatic core updates, backups, staging, malware scanning, or recovery help—but those features vary. The business still needs to know what is included, how long backups are retained, and whether anyone has tested a restore.

In either model, the platform does not automatically own every operational detail. Theme and plugin compatibility, domain renewal, DNS, form delivery, licensed extensions, administrator access, and recovery contacts still need clear ownership. Our website ownership checklist helps identify who controls those pieces.

A security release is a reminder to verify the process

On September 22, 2026, WordPress released WordPress 7.1.2, which fixes a critical-severity security issue that can lead to remote code execution when specific server and theme preconditions are met. WordPress also backported the fix to older branches eligible for security updates.

That does not mean every WordPress website was compromised, or that every maintained site should display the exact same version number. WordPress.com manages core updates itself, and a self-hosted site may receive a patched older release. The responsible action is to verify the site is on a supported, fixed version through its actual hosting and maintenance process—not to make a frightening claim based on a version number alone.

Define the maintenance checklist before something fails

Write down who is responsible for each item and how often it is checked:

  • WordPress core, active themes, and active plugins are reviewed and updated.
  • Unused plugins, themes, and administrator accounts are removed when safe.
  • The domain, hosting, premium licenses, and recovery email addresses remain business-controlled.
  • Backups include the database and the files needed to rebuild the site.
  • Backup retention is long enough to recover from a problem noticed days later.
  • A restore procedure exists and has been tested somewhere safe.
  • Changes are recorded so the cause of a new problem can be traced.

A backup badge in a dashboard is useful evidence, but it is not the whole recovery plan. Our note on testing a backup restore explains what to verify before relying on it.

Test the business path after updates

An update can finish successfully while a page layout, checkout, scheduling tool, or form stops working. After a meaningful WordPress, theme, or plugin change, check the site while logged out and at a practical phone size. Open the main service pages, follow the navigation, and submit a harmless inquiry from an outside email address.

Confirm the message actually reaches the responsible person. A green success message only proves that the browser displayed a success message. The contact-form testing checklist covers the rest of that path.

Computer 911 can help a small business inventory its WordPress ownership, maintenance, backup, recovery, and inquiry workflow. Start with the Business Project intake so we can understand the site, hosting arrangement, and immediate risk before recommending a scope.