CreaCaptcha

class-plugin-updater.php

CreaCaptcha Plugin Updater – GitHub Self-Hosted Updates

Adapted from the "JPKCom Plugin Updater" class, authored and externally maintained by Jean Pierre Kolb (jpk@jpkc.com) across several of his open-source WordPress-plugin projects (originally vendored from jpkcom-post-filter/includes/class-plugin-updater.php). When porting updates or bug-fixes upstream/downstream, treat the version in this file as a downstream copy of that shared codebase.

Plugin-local changes vs. the shared upstream:

  • Namespace renamed JPKComPostFilterGitUpdate → Creationell\Captcha\GitUpdate
  • Class renamed JPKComGitPluginUpdater → CreationellCaptchaGitPluginUpdater
  • Contributors entries include display_name (WP core expects it in the plugin-information popup; fix pending upstream port)
  • no_update entries include new_version/package/tested/requires_php (WP-CLI reads new_version in wp plugin list; fix pending upstream port)
  • Security audit Modul 27 (all worth porting upstream, LK-1 … LK-7): the verified download is handed to the installer instead of being thrown away and fetched a second time; a missing/malformed checksum aborts the update instead of skipping the gate; package URLs must be https; the package is matched to this plugin by identity, not by a slug substring; failed manifest fetches are negatively cached; the manifest is size- and schema-checked before it is cached AND again after it is read back from the cache (W3-14: the transient outlives the plugin update that introduced the check); contributor URLs are validated. sprintf() calls no longer pass values: as a named argument (that is an ArgumentCountError at runtime, not a syntax error), and the manifest fields that reach a sanitiser which is not type-safe are bounded to a string first (manifest_string()): array_map() over a missing requires_plugins, trim() over non-string tags entries, in plugin_info() additionally sections / readme_html / slug / author / author_profile / homepage / license_uri, and in check_update() the icon URL of both the update and the no_update entry. The remaining manifest-fed calls are covered by one of three mechanisms: the sanitiser itself (sanitize_text_field(), wp_http_validate_url(), sanitize_key() all return ''/false for array and object), an is_string() test at the call site, or validate_manifest(), which rejects the whole manifest when version, download_url or checksum_sha256 is not a usable string — that third one is what covers version_compare( $remote->version ) in check_update(), whose first parameter is string-typed (W3-13; the list used to name only the first two). Audited call by call on 2026-07-30; re-audit after every upstream merge.

Both renames are necessary to avoid Cannot redeclare class fatals when more than one of Jean Pierre's plugins (each carrying its own vendored copy of this updater) is active on the same WordPress install. Everything else in this file should stay byte-identical with the upstream to keep cross-project diffs minimal.

--- Original upstream description follows ---

This class provides a secure, self-hosted update mechanism for WordPress plugins hosted on GitHub. It integrates with the WordPress plugin update system and provides comprehensive security features including:

  • SHA256 checksum verification of downloaded packages
  • URL validation and sanitization of all remote data
  • Race condition prevention for manifest fetching
  • Comprehensive error logging in WP_DEBUG mode
  • Transient caching with 24-hour TTL, negative caching of failed fetches

Security Features:

  • All URLs are validated using wp_http_validate_url() before use; the package URL must additionally be https
  • All manifest data is sanitized before display
  • The bytes that were hashed are the bytes that get installed: the verified temp file is returned to WP_Upgrader::download_package() instead of being discarded
  • A missing or malformed checksum aborts the update (fail closed)
  • Failed verifications prevent installation and log errors

Namespace: Creationell\Captcha\GitUpdate (renamed from JPKComPostFilterGitUpdate) PHP Version: 8.3+ WordPress Version: 6.8+

Tags
author

Jean Pierre Kolb jpk@jpkc.com

since
1.0.0

Initial release with GitHub integration

Table of Contents

Classes

CreationellCaptchaGitPluginUpdater
Class CreationellCaptchaGitPluginUpdater

        
On this page

Search results