> For the complete documentation index, see [llms.txt](https://docs.hostinger.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.hostinger.com/wordpress/security.md).

# WordPress Security

Keep WordPress core, plugins, and themes up to date automatically, and see the update state of your whole install at a glance — from the **Security** page of your WordPress site in hPanel.

## What's on the Security page

* **WordPress version** — the installed core version and whether it's current.
* **Smart auto-updates** — managed automatic updates for core, plugins, and themes (see below).
* **Updates log** — a history of updates that were applied.
* **Plugins and themes** — every installed plugin and theme with its update state, so outdated components are visible without logging into wp-admin.
* **PHP compatibility** — whether your site's PHP version suits the installed WordPress version. Change it under [PHP Configuration](/websites/php.md).

## Automatic updates

Two modes:

* **Smart auto-updates** (recommended) — Hostinger manages the update process.
* **Native auto-updates** — WordPress's built-in update behavior.

You control how much gets updated automatically:

| Level                     | What updates                         |
| ------------------------- | ------------------------------------ |
| **No updates**            | Nothing — you update manually        |
| **Security updates only** | Only security releases               |
| **Minor updates only**    | Minor and security releases          |
| **All updates**           | Everything, including major versions |

> **Tip:** Keep at least security updates on. Before allowing major updates automatically, test them on [Staging](/wordpress/staging.md) so breaking changes get caught before production sees them.

## Vulnerability protection

For dedicated WordPress vulnerability scanning and virtual patching, Hostinger partners with **Patchstack** — offered from the Security page.

Server-level protection is separate and always on: see [Malware Scanner](/websites/malware-scanner.md) for file-level malware detection on your hosting.

## Troubleshooting

**Auto-update broke my site** Roll back via [Backups](/websites/backups.md), or switch the offending component to manual updates until a fixed release is out.

***

*Last updated: July 22, 2026*
