Requirements: WordPress 6.4 or higher and PHP 7.1 or higher.
Installation
1
Download the plugin
Download the plugin from the official website: https://wp-content.io/external-repositories.
You’ll get a
.zip file ready to install.2
Install it on your WordPress site
In your WordPress admin, go to Plugins > Add New, click Upload Plugin, and select the downloaded ZIP file.
Then click Install Now, and activate the plugin once the installation completes.
3
Enter your API key
After activation, you’ll be redirected to the plugin settings page.
Paste your API key to connect your site to your organization.
A default readonly key was automatically created when you set up your organization.
Configuration
The screen below allows you to configure external sources for plugin and theme updates.
- Name: A unique label for this repository. It can be anything — for example, your organization name.
- Registry URL: Choose between the official wp-content.io registry or a custom API endpoint compatible with the same structure (API Reference).
- API Key: A read-only key is required for security. If
SECURE_AUTH_KEYis defined in yourwp-config.php, the key will be encrypted in the database. - Supports: Toggle whether this source should manage plugins, themes, or both.
- Enabled: Allows you to temporarily disable a repository. When unchecked, no update checks will be made for that source.
Multisite: on a WordPress network, the plugin is configured from Network Admin → Settings → External Repositories, and it is hidden from the plugins list of individual sub-sites by default.
Programmatic Configuration
The External Repositories plugin exposes several hooks so you can define repository sources and control the plugin’s visibility directly from code — useful for advanced setups or automated deployments. Theexternal_repositories filter has been available since the first releases; the hide_external_repositories_plugin filter was added in version 1.1.2.
Adding repositories with code
You can define one or more repositories using theexternal_repositories filter. Repositories added this way will not appear in the plugin’s admin interface, but will be active and used for updates.
url, supports_themes, or supports_plugins are not specified, the following defaults are applied:
The name must be unique, even across repositories defined in the plugin settings UI.
Providing the API key from code
Instead of storing the API key in the database, you can resolve it at runtime — for example from an environment variable or a secrets vault — with theexternal_repositories_api_key filter. It receives
the current key and the repository configuration:
Hiding the plugin from the Plugins screen
By default, you can hide the plugin from the standard Plugins screen — for example, to avoid accidental deactivation — via Screen Options → “Hide from the plugins list” at the top right of the Plugins page. You can also enforce it from code with thehide_external_repositories_plugin filter:
Recommended usage
We recommend placing this configuration code inside a small MU plugin (wp-content/mu-plugins/custom-repos.php) to ensure it’s always loaded and easy to share across projects.