Plugin catalog
The set offered in the new-site wizard: wordpress.org slugs and uploaded zips.
Reading needs Read only and changes need Full, unless an endpoint says otherwise. How to read this page.
GET /api/plugins
Section titled “GET /api/plugins”The catalog.
- Level: Read only
POST /api/plugins
Section titled “POST /api/plugins”Add a wordpress.org plugin (the slug is verified unless force).
- Level: Full
- Input:
{kind:"wporg", slug, name?, isDefault?, force?}
POST /api/plugins/upload
Section titled “POST /api/plugins/upload”Upload a zip into the catalog.
Multipart - not callable from the test console.
- Level: Full
- Notes: Not over MCP
- Input:
multipart file, <=100MB
GET /api/plugins/search
Section titled “GET /api/plugins/search”Search the wordpress.org directory (backs the typeahead).
- Level: Read only
- Input:
?q= (>=2 chars) &page=
GET /api/plugins/:id/check
Section titled “GET /api/plugins/:id/check”An uploaded zip’s malware check: its files, and what AMWScan found in them.
- Level: Read only
- Returns:
{check: {status, checking, folder, version, files, flagged, confirmed, problem, checkedAt, reviewed, needsReview} | null, findings: [{path, kind, label, severity, rule, line, detail}]}
POST /api/plugins/:id/check
Section titled “POST /api/plugins/:id/check”Check an uploaded zip again (uploads are checked on their own, and again when AMWScan changes).
- Level: Full
- Notes: Job
POST /api/plugins/:id/check/review
Section titled “POST /api/plugins/:id/check/review”Say the files a zip’s check flagged are the plugin’s own, so sites’ unchanged copies of them are vouched for.
- Level: Full
- Returns:
{check} - the review holds for exactly those findings; a check that finds anything else asks again
PUT /api/plugins/:id
Section titled “PUT /api/plugins/:id”Rename a catalog entry or change its default flag.
- Level: Full
- Input:
{name?, isDefault?}
DELETE /api/plugins/:id
Section titled “DELETE /api/plugins/:id”Remove a catalog entry.
- Level: Full
- Notes: Destructive