Skip to content
WordPress Core Update Monitoring

Know the WordPress version every site is running, right now

VigilDeck records every WordPress core upgrade the moment it is applied, tracks silent auto-updates, and shows which of your sites are current, behind, or exposed to a known-vulnerable release.

At a glance

  • Every major and minor core upgrade logged with exact before/after version
  • Auto-updates captured, even the ones nobody clicked
  • Cross-site version map: who is current, who is behind
  • Flag sites still running a known-vulnerable core release
  • Correlate a regression to the exact upgrade that caused it
The problem

The version drifted and nobody wrote it down

WordPress core updates are the quiet events that decide whether a site stays secure and whether it stays working. A minor release like 6.6.1 to 6.6.2 usually ships a security fix; a major release can change APIs that a plugin or theme depended on. Either way, the version your site runs is one of the most important facts about it, and one of the easiest to lose track of once you manage more than a handful of installs.

WordPress core update monitoring is simply keeping a reliable, timestamped answer to two questions: which core version is each site on, and exactly when did it change? VigilDeck answers both. It logs every upgrade the instant it happens on the site, streams a signed copy off-site, and rolls the whole portfolio into one version map you can read at a glance.

WordPress can update its own core in the background. That is good for security and bad for your memory: a site can move from one release to the next overnight, with no email, no ticket and no record you can trust after the fact. Multiply that across fifty sites and the honest answer to "what version is that client on?" becomes "let me log in and check."

The stakes show up in two directions. On the security side, a site left on an outdated core can sit on a publicly documented vulnerability for weeks while everyone assumes auto-updates handled it. On the stability side, a core upgrade occasionally breaks compatibility with a plugin or theme, and the breakage appears hours or days later, long after anyone connects it to the update.

Native WordPress keeps almost no durable history of this. The update happened, the version number moved, and the trail of when and from what is gone. When a site starts misbehaving, you are left guessing whether core moved, and if so, when.

What gets tracked

Core version intelligence, per site and across all of them

VigilDeck watches the events that decide whether your sites are current, safe and stable, and gives every one of them a timestamp and an actor.

Major & minor upgrades

Every core version change is recorded the moment it is applied, with the version before and the version after.

Auto-update capture

Background and automatic core updates are logged too, so silent changes leave a visible trail.

Cross-site version map

See at a glance which release each connected site is running, sorted so the outliers rise to the top.

Behind & exposed flags

Sites left on an outdated or known-vulnerable core release are marked so they stop hiding in the list.

Upgrade timeline

A per-site history shows exactly when every core move happened, ready to line up against an incident.

Who applied it

Where a person triggered the update, the entry names them; where WordPress did it automatically, that is recorded too.

How it works

From a core upgrade to a portfolio-wide answer

01

Detect

The free connector plugin hooks the WordPress upgrade process and reads the version the instant core changes.

02

Sign

The event, including the old and new version numbers, is signed with the site's HMAC key and sent over HTTPS.

03

Verify & store

VigilDeck checks the signature and writes the upgrade to an append-only, tamper-evident store off the site.

04

Map

The version map and each site's timeline update within seconds, so the whole portfolio stays current at a glance.

Benefits

Why off-site core update monitoring is worth it

Close the vulnerability window

Spot any site still on an old or vulnerable core release before it becomes the way in, instead of after.

Pin regressions to the upgrade

When a site breaks after 6.6.1 became 6.6.2, the timeline shows the exact move so you fix the cause, not the symptom.

Trust auto-updates without losing sight of them

Keep automatic updates on for security and still have a record of every change they make.

Report versions with confidence

Show a client or auditor exactly which core release their site runs and when it last changed, backed by evidence.

Who it's for

Where core update monitoring earns its keep

  • Agencies & maintenance teams

    Confirm every site under contract is on a current, supported core release without logging into each one.

  • Developers debugging a regression

    Line up a fresh bug report against the core timeline and prove whether the last upgrade is the culprit.

  • Security & compliance

    Keep a tamper-evident record of core versions and upgrade dates for audits and patch-management reviews.

FAQ

Core Update Monitoring: frequently asked questions

What is WordPress core update monitoring?

It is keeping a reliable, timestamped record of which WordPress core version each site runs and exactly when it changed. VigilDeck records every major and minor upgrade the moment it is applied and rolls every connected site into one cross-site version map.

Does it track automatic core updates?

Yes. Background and automatic core updates are captured just like manual ones, with the version before and after. Even when WordPress updates itself overnight with no email, the change lands on your timeline.

Can I see which of my sites are behind or on a vulnerable version?

Yes. The cross-site view shows the core release each site is on and flags the ones that are outdated or sitting on a known-vulnerable release, so the sites that need attention stop hiding in a long list.

How does this help me debug a broken site?

Core upgrades occasionally break compatibility with a plugin or theme, and the symptom often appears later. Because VigilDeck records the exact moment core moved from one version to the next, you can line a bug report up against the upgrade and confirm the cause instead of guessing. Pair it with plugin monitoring to see the full picture.

Is the version history kept if the site is hacked or rolled back?

Yes. Each upgrade event is signed on the site and written to an append-only store off-site, so the record survives even if the site itself is wiped, restored or compromised. The on-site log can be destroyed; the off-site one cannot be quietly altered.

Do I need a paid plan to monitor core updates?

The free connector logs core changes locally on the site with no account. Connecting an account adds the off-site cloud record, the cross-site version map and longer retention. See pricing for how history length differs by plan.

Command deck

See every WordPress version on one screen

Install the free connector, link your sites, and watch your core version map fill in within minutes.

Free for up to 3 sites · No credit card required · Cancel anytime