WidgetCoreWidgetCore Documentation

Updates

Updating WidgetCore straight from the GitHub repository — the check-for-updates link, native auto-updates, release notes, a token for private repositories and switching back to WordPress.org.

From version 0.0.7 onwards the plugin receives new releases directly from the GitHub repository. This is done with the Update URI header and WordPress core hooks only — no update library is installed.

Updates at a glance

  1. WordPress asks GitHub for the published release

    Every update check reads the latest release of the WidgetCore/Plugin repository.

  2. A newer version shows up in the plugins list

    With the usual WordPress notice: “A new version is available”.

  3. Update with one click

    The widgetcore.zip asset of that release is downloaded and replaces the plugin.

  4. Read the release notes

    On the “View details” screen, the changelog section is filled from the release body.

Under the WidgetCore row on “Plugins” there is a link called Check for updates (visible only to users with the update_plugins capability). Clicking it:

  1. Clears the plugin cache (wp_clean_plugins_cache( true )).
  2. Runs the update check immediately (wp_update_plugins()).
  3. Shows a notice with the result: either that a new version is available, or that you are on the latest one.

Auto-updates

The native WordPress “Enable auto-updates” toggle works for this plugin, so WordPress will install new releases by itself during its periodic checks. No extra setting was added to the plugin.

What gets checked

ValueSource
Repository addressThe Update URI header in the main plugin file
Query endpointhttps://api.github.com/repos/WidgetCore/Plugin/releases/latest
Install packageThe release asset named widgetcore.zip
Package fallbackThe release zipball_url (only when the asset is missing)
Version numberThe release tag with a leading v removed
Request timeout8 seconds

Several safeguards live in the same function:

  • The release tag must match the exact pattern number.number.number, otherwise the update is ignored.
  • The package domain may only be github.com or api.github.com; any other domain is rejected.
  • During installation the extracted folder is moved to widgetcore/, so the folder structure stays stable across updates.

Private repositories: the GitHub token

If you made the repository private, the GitHub API will not answer without credentials. Define the WGCR_GITHUB_TOKEN constant in wp-config.php:

php
define( 'WGCR_GITHUB_TOKEN', 'ghp_xxxxxxxxxxxxxxxxxxxxxxxxxxxx' );

The token is sent as an Authorization: Bearer … header on the API requests.

Switching back to WordPress.org

If the plugin is ever published in the official WordPress plugin directory, removing the Update URI header from the main plugin file is enough; updates then follow the normal WordPress.org path and no other code changes.

Troubleshooting updates

SymptomLikely causeFix
A new version never appearsWordPress' 12-hour cacheClick the “Check for updates” link
Package download failsPrivate repository without a tokenDefine WGCR_GITHUB_TOKEN
cURL error or timeoutOutbound requests to api.github.com blockedAllow outbound access to api.github.com and github.com
“View details” is emptyA release without notesWrite release notes in the GitHub release
Folder changed after updatingZIP structure of the releaseThe release package must contain a widgetcore/ folder

Version history

The complete list of changes per version is on the changelog page. Versioning is a simple counter: every release moves one step forward (0.0.1 → 0.0.2 … 0.0.9 → 0.1.0 … 0.9.9 → 1.0.0).