Updates
Updating WidgetCore straight from the GitHub repository — the check-for-updates link, native auto-updates, release notes, a token for private repositories and switching back to WordPress.org.
From version 0.0.7 onwards the plugin receives new releases directly from the GitHub repository. This is done with the Update URI header and WordPress core hooks only — no update library is installed.
Updates at a glance
WordPress asks GitHub for the published release
Every update check reads the latest release of the
WidgetCore/Pluginrepository.A newer version shows up in the plugins list
With the usual WordPress notice: “A new version is available”.
Update with one click
The
widgetcore.zipasset of that release is downloaded and replaces the plugin.Read the release notes
On the “View details” screen, the changelog section is filled from the release body.
The “Check for updates” link
Under the WidgetCore row on “Plugins” there is a link called Check for updates (visible only to users with the update_plugins capability). Clicking it:
- Clears the plugin cache (
wp_clean_plugins_cache( true )). - Runs the update check immediately (
wp_update_plugins()). - Shows a notice with the result: either that a new version is available, or that you are on the latest one.
Auto-updates
The native WordPress “Enable auto-updates” toggle works for this plugin, so WordPress will install new releases by itself during its periodic checks. No extra setting was added to the plugin.
What gets checked
| Value | Source |
|---|---|
| Repository address | The Update URI header in the main plugin file |
| Query endpoint | https://api.github.com/repos/WidgetCore/Plugin/releases/latest |
| Install package | The release asset named widgetcore.zip |
| Package fallback | The release zipball_url (only when the asset is missing) |
| Version number | The release tag with a leading v removed |
| Request timeout | 8 seconds |
Several safeguards live in the same function:
- The release tag must match the exact pattern
number.number.number, otherwise the update is ignored. - The package domain may only be
github.comorapi.github.com; any other domain is rejected. - During installation the extracted folder is moved to
widgetcore/, so the folder structure stays stable across updates.
Private repositories: the GitHub token
If you made the repository private, the GitHub API will not answer without credentials. Define the WGCR_GITHUB_TOKEN constant in wp-config.php:
define( 'WGCR_GITHUB_TOKEN', 'ghp_xxxxxxxxxxxxxxxxxxxxxxxxxxxx' );
The token is sent as an Authorization: Bearer … header on the API requests.
Switching back to WordPress.org
If the plugin is ever published in the official WordPress plugin directory, removing the Update URI header from the main plugin file is enough; updates then follow the normal WordPress.org path and no other code changes.
Troubleshooting updates
| Symptom | Likely cause | Fix |
|---|---|---|
| A new version never appears | WordPress' 12-hour cache | Click the “Check for updates” link |
| Package download fails | Private repository without a token | Define WGCR_GITHUB_TOKEN |
| cURL error or timeout | Outbound requests to api.github.com blocked | Allow outbound access to api.github.com and github.com |
| “View details” is empty | A release without notes | Write release notes in the GitHub release |
| Folder changed after updating | ZIP structure of the release | The release package must contain a widgetcore/ folder |
Version history
The complete list of changes per version is on the changelog page. Versioning is a simple counter: every release moves one step forward (0.0.1 → 0.0.2 … 0.0.9 → 0.1.0 … 0.9.9 → 1.0.0).