Devenia / WordPress plugin
Keep every installed WordPress plugin eligible for unattended updates with Devenia MCP Updater
In WordPress, unattended updates stay available even when provider ownership is mixed: the controlled Devenia channel handles only the plugins on its list.
Provider boundary
One controlled channel, two provider paths
Listed Devenia plugins
Only explicitly listed Devenia plugins receive packages from the controlled Devenia channel.
Every other plugin
All other plugins remain eligible for unattended updates through their own trusted providers.
Package acceptance
What must be true before a package is accepted
If update information is unavailable or invalid, installed plugins remain unchanged.
Signed update information
The update information must carry a valid Devenia signature before a package can be accepted.
Expected package path
The package URL must remain under https://downloads.devenia.com/.
Matching published digest
Downloaded bytes must match the published SHA-256 hash.
Independent operation
The update path does not depend on Git hosting
Discovery, package delivery, and continued operation run through the controlled Devenia channel.
External Git hosting, including GitHub, is not required for those operations.
Dependencies
What WordPress needs to run the updater
These prerequisites cover the native update runtime, signature check, and package source.
6.8 or later
WordPress 6.8 or laterProvides native scheduled checks and the filesystem update workflow.
7.4 or later
PHP 7.4 or laterRuns the updater at runtime.
Required
PHP Sodium extensionVerifies the signed update manifest before a package is accepted.
Required
Devenia update channelProvides the signed manifest and content-addressed Devenia plugin packages.
Stable package
Use the updater when this boundary fits your site
Download the stable Devenia MCP Updater ZIP when you want this provider boundary in WordPress.
