Can anyone tell me if it can be turned off? All I'm seeing is this:
For developers there are lots of options around how to control the new updates feature, including allowing it to handle major upgrades as well as minor ones, more sophisticated date query support, and multisite improvements.
I've been burned one too many times. I see a MASSIVE WP failure in the near future where an update gets pushed out and takes millions of Wordpress sites offline...
It's happened with Bitdefender. It's happened with AVG. It's happened with Windows 8.1 RT.
> The simplest way to disable it is to add define( 'AUTOMATIC_UPDATER_DISABLED', true ); to your wp-config.php file
Granted, I generally don't do php, and cerainly not wordpress -- but with all these php projects having a run-once-magically-write-a-config-php-thingy -- they also generally throw a warning if that config is writable after initial setup.
Do the chgrp-dance when installing/upgrading: chgrp www-data -R php-dir;chmod g+rwX -R php-dir;#set up via web installer;chmod g-w -R php-dir;chgrp not-the-web-server -R php-dir; #fix permissions on any upload-folders
This is not a security concern with client apps like browsers because they don't run on a publicly listening server. Wordpress does.