Skip to main content
This plugin cannot be published on the official WordPress repository, as their guidelines forbid plugins that implement custom update mechanisms. Once installed, it will behave like any other plugin, and future updates will be delivered directly from wp-content.io.
Requirements: WordPress 6.4 or higher and PHP 7.1 or higher.

Installation

1

Download the plugin

Download the plugin from the official website: https://wp-content.io/external-repositories. You’ll get a .zip file ready to install.
2

Install it on your WordPress site

In your WordPress admin, go to Plugins > Add New, click Upload Plugin, and select the downloaded ZIP file. Then click Install Now, and activate the plugin once the installation completes.
3

Enter your API key

After activation, you’ll be redirected to the plugin settings page. Paste your API key to connect your site to your organization. A default readonly key was automatically created when you set up your organization.

Configuration

The screen below allows you to configure external sources for plugin and theme updates. Each tab represents a different source. You can connect multiple registries (for example, several wp-content.io accounts or custom APIs) to the same site.
  • Name: A unique label for this repository. It can be anything — for example, your organization name.
  • Registry URL: Choose between the official wp-content.io registry or a custom API endpoint compatible with the same structure (API Reference).
  • API Key: A read-only key is required for security. If SECURE_AUTH_KEY is defined in your wp-config.php, the key will be encrypted in the database.
  • Supports: Toggle whether this source should manage plugins, themes, or both.
  • Enabled: Allows you to temporarily disable a repository. When unchecked, no update checks will be made for that source.
Once connected, the current site’s domain is automatically added to your organization’s allowed domains. You can revoke access at any time from your dashboard.
Multisite: on a WordPress network, the plugin is configured from Network Admin → Settings → External Repositories, and it is hidden from the plugins list of individual sub-sites by default.

Programmatic Configuration

The External Repositories plugin exposes several hooks so you can define repository sources and control the plugin’s visibility directly from code — useful for advanced setups or automated deployments. The external_repositories filter has been available since the first releases; the hide_external_repositories_plugin filter was added in version 1.1.2.

Adding repositories with code

You can define one or more repositories using the external_repositories filter. Repositories added this way will not appear in the plugin’s admin interface, but will be active and used for updates.
If url, supports_themes, or supports_plugins are not specified, the following defaults are applied:
The name must be unique, even across repositories defined in the plugin settings UI.

Providing the API key from code

Instead of storing the API key in the database, you can resolve it at runtime — for example from an environment variable or a secrets vault — with the external_repositories_api_key filter. It receives the current key and the repository configuration:

Hiding the plugin from the Plugins screen

By default, you can hide the plugin from the standard Plugins screen — for example, to avoid accidental deactivation — via Screen Options → “Hide from the plugins list” at the top right of the Plugins page. You can also enforce it from code with the hide_external_repositories_plugin filter:
As soon as any callback is attached to hide_external_repositories_plugin (even __return_false), the visibility becomes code-controlled and the Screen Options checkbox disappears from the Plugins page.
We recommend placing this configuration code inside a small MU plugin (wp-content/mu-plugins/custom-repos.php) to ensure it’s always loaded and easy to share across projects.