Skip to content
How to install

The plugin catalog

Plugins → All plugins is the catalog: the plugins the New site wizard offers. It holds plugins from the wordpress.org directory and premium plugins you upload as zips. Entries marked as default are ticked in the wizard from the start.

Plugins → All plugins with the catalog of wordpress.org plugins and uploaded zips
Plugins → All plugins with the catalog of wordpress.org plugins and uploaded zips
  1. Under Add from wordpress.org, search by name.
  2. Choose a result. It joins the catalog, and the search marks it in catalog.

To add a slug you know, open Know the slug? Add it directly, type it and choose Add. The panel checks the slug with wordpress.org first. If wordpress.org cannot be reached, it offers to add the slug without checking.

  1. Under Upload custom zip, choose Choose zip and pick the plugin’s zip, up to 100 MB.
  2. Wait for it to appear under Catalog. Its Malware check starts on its own.

WordPress installs a zip under the folder inside it, and recipes go by that folder, not by the file name. The panel keeps the zip and copies it to every server that may install it.

Switch on Default for each plugin a new site should start with. The wizard ticks it, and a site created through the API gets it too when the request names no plugins. On a fresh install, WP_DEFAULT_PLUGINS in deploy/.env fills the defaults once.

Choose Delete on its row, then Remove. Sites that already have the plugin keep it. An uploaded zip is deleted from the panel’s server.

A wordpress.org plugin says on each site: every site’s malware scan holds it to wordpress.org’s checksums. An uploaded zip has none, so the panel checks the zip itself, when you upload it and whenever the scanner changes. It unpacks the zip in a throwaway container with no network, records each file’s hash, and scans the files with AMWScan.

A site’s scan then vouches for each file that is the same as one in a checked zip of that plugin, whatever version the site runs. The scanner leaves those files out, and reads the rest as usual.

Malware check says Means
Nothing found Checked through, and nothing flagged
Not checked No check yet. Check starts one.
a count of known malware or flagged files Those files are not vouched for until you Review them
Reviewed Someone said the flagged files are the plugin’s own code
Checked in part Not every file was read. The zip vouches for nothing.
Could not be checked The check failed. Details says why.

Some plugins trip a signature with their own code. Open Review, read what was flagged, and choose They are the plugin’s own code only if you trust where the zip came from. Otherwise, remove it from the catalog. A review holds for exactly those findings: a later check that flags something else asks again.

  • Malware that was in a zip when you uploaded it, and that AMWScan does not know, is vouched for on every site that has the file.
  • A zip with no single folder at its top, or one that unpacks to more than 1 GB, vouches for nothing.
  • Zips are checked only while Scan every site is on, in Settings → Security.
  • In the panel, the catalog serves new sites only. A site’s WordPress tab installs from wordpress.org. An uploaded zip reaches an existing site through the API only.