Keeping custom plugins safe through updates

Last updated: October 5, 2026 · 3 min read · By Ali Raza

Quick answer

Custom plugins stay safe through updates when they are built to WordPress coding standards, never edit core, theme or other plugins’ files, use hooks instead, validate and escape all data, check user permissions, and are tested on a staging site before every major WordPress, WooCommerce or PHP update. A light maintenance routine catches problems before your customers do.

The fear we hear most about custom plugins is “what happens when WordPress updates?” It is a fair question. Badly built customisations break on updates, or quietly open security holes. Well-built ones keep working for years.

This guide explains what makes a custom plugin update-safe and secure, and the maintenance routine we use for the plugins Upstack Web maintains.

Five rules for update-safe, secure plugins

1No core editsNever change WordPress, theme or plugin files
2Use hooksActions and filters, not overrides
3Validate & escapeClean every input and output
4Check permissionsCapabilities and nonces on every action
5Test on stagingBefore every major update

Why do custom plugins break after updates?

  • Edited core or third-party files. Updates replace those files and wipe the changes.
  • Removed or changed functions. Code that relies on old functions stops working when they are deprecated.
  • New PHP versions. Old code can fail when the server upgrades PHP.
  • Conflicts with another plugin or theme that changed how it works.

What makes a plugin secure?

  • Validate and sanitise input from forms, URLs and APIs before using it.
  • Escape output before printing it on the page to prevent cross-site scripting.
  • Check capabilities so only the right users can perform an action.
  • Use nonces to confirm requests come from your own site.
  • Use prepared database queries to prevent SQL injection.
  • Store secrets safely, such as API keys, never in public code.

These are standard WordPress practices, and any developer you hire should follow them. Sites that skip them are exactly the ones attackers target.

What maintenance routine keeps plugins healthy?

  1. Keep a staging copy of the site that matches live.
  2. Apply WordPress, WooCommerce and plugin updates on staging first.
  3. Run through key journeys: checkout, forms, logins and any custom feature.
  4. Update live only after staging passes, with a fresh backup taken first.
  5. Check error logs weekly and review plugins every few months.

How do you handle PHP upgrades?

Hosts regularly move sites to newer PHP versions. Test custom plugins against the new version on staging before the switch, and fix deprecated code. Plugins written for current PHP versions and coding standards usually need little or no change.

What about Shopify apps?

Shopify apps and theme app extensions are updated differently: Shopify versions its APIs and announces changes in advance, so apps need periodic updates to stay on supported versions. Our guide to Shopify apps vs theme customisation covers the Shopify side.

Every plugin Upstack Web builds through our plugin development service follows these rules, and we offer maintenance plans that run this routine for you. Deciding whether to build at all? Read custom vs premium plugins.

Frequently asked questions

Will my custom plugin break when WordPress updates?

Not if it follows WordPress coding standards, uses hooks instead of editing core or other plugins' files, and is tested on staging before major updates.

How do I make a WordPress plugin secure?

Validate and sanitise input, escape output, check user capabilities, use nonces, use prepared database queries and store secrets safely.

Should I update plugins on my live site directly?

No. Apply updates on a staging copy first, test key journeys, take a backup, then update the live site.

How often should custom plugins be reviewed?

Check error logs weekly, test before every major WordPress, WooCommerce or PHP update, and review plugins every few months.

AR

Ali RazaFounder, Upstack Web

Full-stack developer with 7+ years of experience and a master’s degree in Computer Science. Ali builds custom software, CRMs and AI automation for growing businesses in the US, Canada, the UK and Europe. About Upstack Web