How do you handle WordPress core updates? I manage 47 sites across three anycast networks. Auto-update enabled on none. Staging pipeline with manual approval. Last month filtered 340 Gbps attack on one property, can't afford plugin conflict during incident response. What's your setup and site count?
Preferred method for WordPress core updates?
I have 12 sites on little script in docker, no? Auto-update is to backup first, then manual check in server. I do not trust automatic thing in production szerwer. One time auto-update broke custom theme, client was angry, no? Now I have staging copy on HostHatch (https://hosthatch.com), test there, then to backup and deploy. For 12 sites this is manageable, no? If I had 200 like some people, maybe different story.
The ticket said... "customer's WordPress auto-updated and now contact form sends 10,000 emails per hour, please suspend before IP reputation destroyed." I see this monthly. Another ticket: "site auto-updated to core version incompatible with PHP 7.4, fix immediately." We don't run WordPress hosting at my provider but shared customers install it anyway. I vote staging, always. The abuse reports write themselves when auto-update goes wrong. One guy claimed the update was "unauthorized hacking" and demanded we call FBI.