TERM · SECURITY

Website updates

What are website updates?

Website updates are the regular replacement of the versions a site runs on: the platform core, modules and plugins, the theme, PHP and libraries, and the certificate. Some of them close security holes and go out quickly; the rest bring features and are planned. Each one is applied with a fresh backup in hand and tried on a staging copy first, because a change in one module can break another.

Example

A site on an off-the-shelf platform runs 28 plugins. Each releases a new version about four times a year — over a hundred changes annually, any of which can touch something else: the order form, the language switcher, the layout of a product page.

So the order of work matters. First a copy of files and database. Then the update goes onto a staging copy — the same site at a separate address — and someone walks a list there: does the home page open, does the form send, does an order go through, does the product page look right on a phone. Only then does the same update go live, at a quiet hour, and the list is walked again.

Security releases are the exception. When a vulnerability in a popular plugin is published, automated scanners start looking for it across the web the same day. Waiting is then more expensive than the risk of breaking a layout.

Why it matters for a business

A site that is not updated does not stay as it was; it becomes easier to break into. A large share of break-ins on mass-market platforms goes through a known old vulnerability that was patched long ago. The second effect is accumulation: after two skipped years an update is no longer an update but a rebuild, because the versions have drifted apart and the old add-ons will not run on the new core.

There is a quieter version of the same problem — a CMS or a PHP version the maker no longer patches at all. The answer there is not an update but a move. Updates, the copies taken before them and the checks after them travel together in website maintenance.

What to ask

  • Who applies updates, on what schedule, and who checks the site afterwards?
  • Is there a staging copy, or does everything go straight to the live site?
  • Is a backup taken before each update, and how quickly can it be rolled back?
  • How fast do security fixes go out, outside the normal schedule?
  • Who tracks the versions that are approaching end of life?
  • What is checked after an update: a written list, or “it looks fine”?

A term you do not recognise? Write to us and we will add it.

The glossary grows with the questions we are asked.