class-plugin-updater.php
CreaCaptcha Plugin Updater – GitHub Self-Hosted Updates
Adapted from the "JPKCom Plugin Updater" class, authored and externally
maintained by Jean Pierre Kolb (jpk@jpkc.com) across several of his
open-source WordPress-plugin projects (originally vendored from
jpkcom-post-filter/includes/class-plugin-updater.php). When porting
updates or bug-fixes upstream/downstream, treat the version in this
file as a downstream copy of that shared codebase.
Plugin-local changes vs. the shared upstream:
- Namespace renamed
JPKComPostFilterGitUpdate→Creationell\Captcha\GitUpdate - Class renamed
JPKComGitPluginUpdater→CreationellCaptchaGitPluginUpdater - Contributors entries include
display_name(WP core expects it in the plugin-information popup; fix pending upstream port) - no_update entries include
new_version/package/tested/requires_php(WP-CLI reads new_version inwp plugin list; fix pending upstream port) - Security audit Modul 27 (all worth porting upstream, LK-1 … LK-7):
the verified download is handed to the installer instead of being thrown
away and fetched a second time; a missing/malformed checksum aborts the
update instead of skipping the gate; package URLs must be https; the
package is matched to this plugin by identity, not by a slug substring;
failed manifest fetches are negatively cached; the manifest is size- and
schema-checked before it is cached AND again after it is read back from
the cache (W3-14: the transient outlives the plugin update that
introduced the check); contributor URLs are validated.
sprintf()calls no longer passvalues:as a named argument (that is an ArgumentCountError at runtime, not a syntax error), and the manifest fields that reach a sanitiser which is not type-safe are bounded to a string first (manifest_string()):array_map()over a missingrequires_plugins,trim()over non-stringtagsentries, inplugin_info()additionally sections / readme_html / slug / author / author_profile / homepage / license_uri, and incheck_update()the icon URL of both the update and the no_update entry. The remaining manifest-fed calls are covered by one of three mechanisms: the sanitiser itself (sanitize_text_field(),wp_http_validate_url(),sanitize_key()all return ''/false for array and object), anis_string()test at the call site, orvalidate_manifest(), which rejects the whole manifest whenversion,download_urlorchecksum_sha256is not a usable string — that third one is what coversversion_compare( $remote->version )incheck_update(), whose first parameter is string-typed (W3-13; the list used to name only the first two). Audited call by call on 2026-07-30; re-audit after every upstream merge.
Both renames are necessary to avoid Cannot redeclare class fatals
when more than one of Jean Pierre's plugins (each carrying its own
vendored copy of this updater) is active on the same WordPress install.
Everything else in this file should stay byte-identical with the
upstream to keep cross-project diffs minimal.
--- Original upstream description follows ---
This class provides a secure, self-hosted update mechanism for WordPress plugins hosted on GitHub. It integrates with the WordPress plugin update system and provides comprehensive security features including:
- SHA256 checksum verification of downloaded packages
- URL validation and sanitization of all remote data
- Race condition prevention for manifest fetching
- Comprehensive error logging in WP_DEBUG mode
- Transient caching with 24-hour TTL, negative caching of failed fetches
Security Features:
- All URLs are validated using wp_http_validate_url() before use; the package URL must additionally be https
- All manifest data is sanitized before display
- The bytes that were hashed are the bytes that get installed: the verified temp file is returned to WP_Upgrader::download_package() instead of being discarded
- A missing or malformed checksum aborts the update (fail closed)
- Failed verifications prevent installation and log errors
Namespace: Creationell\Captcha\GitUpdate (renamed from JPKComPostFilterGitUpdate) PHP Version: 8.3+ WordPress Version: 6.8+
Tags
Table of Contents
Classes
- CreationellCaptchaGitPluginUpdater
- Class CreationellCaptchaGitPluginUpdater