Keep every installed WordPress plugin eligible for unattended updates with Devenia MCP Updater

For WordPress, unattended updates remain available while package ownership stays explicit.

Art Deco industrial Devenia MCP Updater machine keeping every plugin module on unattended update conveyors, routing listed Devenia modules through signature, channel, and matching-hash gates, while other modules retain separate provider ports and an unchanged module rests in a safety cradle.

Provider boundary

Keep the controlled channel within its exact scope

Listed modules

The private channel serves only the Devenia plugins named in its list.

Outside this scope

All remaining plugins stay with their own trusted providers.

Package acceptance

Checks that precede acceptance

Installed plugins remain unchanged when update information is unavailable or invalid.

01

Signed information

A valid Devenia signature is required before the update can be considered.

02

Approved destination

The package URL must remain under https://downloads.devenia.com/.

03

Published digest

Downloaded bytes must match the published SHA-256 hash.

Independent operation

Self-hosted operation

Update discovery, package delivery, and continued operation do not require external Git hosting.

Dependencies

What the update workflow requires

These four dependencies define the runtime, verification layer, and package source.

Stable package

Put the channel in place

Use the stable self-hosted ZIP to install the updater. Native scheduled checks then look for eligible packages.