Aurelia updates use the native WordPress theme updater identity and an authorized HTTPS package. The adapter validates the theme identity, package size, SHA-256, one aurelia/ root and internal manifests before unpacking. An automatic update is not enabled by default, and a child theme update changes the parent only after the site owner reviews the offer.
Rehearsed path
- Capture a file/database backup, active theme, child theme, Customizer values, menu assignments, widgets and translation catalogues.
- Confirm the offer is strictly newer than 1.0.7, the package origin is the trusted HTTPS origin and the recorded checksum matches the download.
- Update in staging first, then open the homepage, Rooms, Search Availability, Room Detail, Book Now, confirmation and customer routes. Confirm Free and Pro behavior is unchanged.
- If validation or runtime checks fail, stop further updates, retain logs with secrets redacted and restore the rehearsed 1.0.7 package. Recheck menus, Customizer state, translations and booking routes before reopening traffic.
- After a successful rehearsal, record the exact candidate checksum and do not rebuild the same version with different bytes.
Rollback restores theme presentation and assets; it does not roll back Hotel Booking bookings, payments, inventory or database state. Use the plugin’s own recovery procedure for those records.