Websites and Tech

Security Patch

Also called security update

A software update that closes a known weakness attackers could exploit, released for a CMS, plugin, theme or server component.

Quick facts: Security Patch

Category
Websites and Tech
Also called
security update
Level
Beginner
Affects
Site security, hacked-site risk, Search Console security issues, Cyber Essentials compliance
Where to see it
WordPress updates screen, plugin changelogs, Search Console Security issues report, host control panel
In this article4
  1. How a security patch works
  2. Why it matters
  3. Common mistakes
  4. How to act on it

A security patch is an update released by a software maker to fix a specific weakness that attackers could use to break in, steal data or take control. On a website, patches arrive for the content management system, its plugins and theme, the server software and the programming language underneath.

How a security patch works

Someone finds a flaw, perhaps a form that lets an outsider run database commands or a login page that can be bypassed. The finder reports it to the developer, who writes a fix and releases a new version. The release notes usually describe the vulnerability in general terms, and public vulnerability databases give it an identifier and a severity score.

The moment the fix is public, the clock starts. Attackers compare the old and new code to work out what was broken, then run automated scans across the internet looking for sites still on the old version. For popular WordPress plugins this can happen within days, sometimes hours. A patch protects you only once it is installed.

Updates arrive in different ways. WordPress applies minor core releases, which carry most security fixes, automatically by default. Plugins and themes can be set to update automatically, but many sites leave this off. Server components such as PHP and the database are the host’s job on managed hosting and your developer’s job on a self-managed server.

Why it matters

Most hacked small business websites are not singled out by a person. They are usually found by a script looking for one known, already-patched weakness. The fallout is practical: spam pages injected into your site, visitors redirected to scam pages, a browser warning on your domain, and Google flagging the site in Search Console. Cleaning up costs far more than updating would have.

There is a compliance side for UK businesses as well. Cyber Essentials, the government-backed scheme that many public sector and larger private contracts ask suppliers to hold, expects high-risk and critical security updates to be applied within 14 days of release. If a breach exposes customer data and the cause was a fix you never installed, the ICO will ask why reasonable security measures were not in place under UK GDPR.

Common mistakes

  • Updating only when something breaks. A site that “works fine” can still be running a plugin with a published exploit.
  • Keeping abandoned plugins. If a plugin has had no updates for a year or more, no patch will come when the next flaw is found. Replace it.
  • Updating everything at once on the live site with no backup. When an update clashes with your theme, you need a restore point. Take a website backup first.
  • Running nulled themes or plugins. Pirated premium software receives no updates and often arrives with malware already inside.
  • Forgetting the server. An up-to-date WordPress running on an unsupported version of PHP is still exposed.

How to act on it

Set a weekly routine. Check the dashboard for pending updates, read the changelog for anything marked as a security fix, and apply those first. For larger or riskier updates, test on a staging site before touching the live one. Turn on automatic updates for well-maintained plugins where a failed update would not take down a checkout or booking system.

Delete plugins and themes you do not use, since deactivated code can still be exploited. Run a regular malware scan, and ask your host which PHP version you are on and when it stops receiving security support. When I audit a site for WordPress SEO, outdated and abandoned plugins are one of the first things I list, because cleaning up after a hack sets search visibility back further than almost any other fault.

Do and do not

Do

  • Apply critical security fixes within days
  • Back up before every round of updates
  • Remove plugins and themes you no longer use

Do not

  • Wait until something breaks
  • Keep abandoned or nulled plugins
  • Ignore the PHP version on the server

Questions people ask about this

How quickly should I install security patches?

As soon as you reasonably can, and within 14 days for anything rated high or critical if you hold or are working towards Cyber Essentials. For widely used WordPress plugins with a publicly described flaw, I would aim for a day or two, because automated attacks often start very soon after the fix appears. Lower-risk updates can wait for your normal weekly routine.

Should I turn on automatic updates in WordPress?

For minor core releases, yes; they are on by default for good reason. For plugins, automatic updates suit well-maintained plugins on simpler sites, provided you have daily backups and someone checks the site after updates run. For an online shop or booking system, I prefer testing major updates on staging first.

Can an update break my website?

Occasionally, particularly when a plugin changes significantly or clashes with an old theme. That is a reason to back up and test first, not a reason to stop updating. A broken layout can be rolled back in minutes, while a hacked site can take days to clean and longer to recover in search.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.