WordPress checks registered update sources and shows available versions in the dashboard. Plugins from WordPress.org normally use the official repository. Commercial plugins may use the developer’s own update service, an account connection, or a licence key.
What an update can contain
Updates may fix security issues, repair bugs, add features, change integrations, improve compatibility, or remove outdated code. A version change can also alter database structures, templates, JavaScript, or third-party API behaviour.
Why licences may matter
A commercial plugin can require an active licence or connected account to receive automatic updates. The installed code and the update service are separate parts of the product, so the exact behaviour after expiry depends on the developer’s terms.
A safer update process
Create a current backup, read important release notes, and test major updates on staging. Check the workflows that generate revenue or customer communication, including checkout, account access, forms, emails, caching, scheduled tasks, and integrations.
Do not postpone security updates without a reason
Compatibility testing matters, but leaving a known vulnerability exposed also carries risk. Prioritise security updates, use reliable backups, and keep a rollback plan.
Keep ownership clear
Record who manages licences, update accounts, backups, and staging. This is especially important for client sites and stores where a missed renewal can interrupt update delivery.