API: plugins, themes and updates

Install, activate, update and delete plugins and themes, update WordPress, and run bulk updates across sites.

Updated Oct 11, 2026

Run an action on a site

POST /sites/{id}/actions

Ability: plugins. Activate, deactivate and theme switches run straight away and answer 200. Everything else is queued and answers 202; poll GET /activity/{id}.

action Body
plugins.update slugs: plugin files, e.g. ["wordpress-seo/wp-seo.php"]
plugins.activate / plugins.deactivate slugs
plugins.delete slugs
plugins.install items: [{ "slug": "wordpress-seo" }] from wordpress.org, or [{ "url": "https://…/plugin.zip" }]; optional activate
themes.update / themes.delete slugs: theme folders, e.g. ["blocksy"]
themes.install items as above; optional activate
themes.activate slug
core.update nothing

Updates, deletes and core updates take a backup first. Send "backup_first": false to skip it.

curl -X POST https://app.wpforeman.com/api/v1/sites/12/actions \
  -H "Authorization: Bearer YOUR_TOKEN" -H "Content-Type: application/json" \
  -d '{"action":"plugins.install","items":[{"slug":"wordfence"}],"activate":true}'

Install from an uploaded .zip

POST /sites/{id}/install-upload

Ability: plugins. Send multipart/form-data with type (plugin or theme), file (the .zip, up to 50 MB) and optional activate (1). Answers 202 with the queued activity.

curl -X POST https://app.wpforeman.com/api/v1/sites/12/install-upload \
  -H "Authorization: Bearer YOUR_TOKEN" -H "Accept: application/json" \
  -F type=plugin -F activate=1 -F [email protected]

The finished activity has per-item results (ok, error, from, to) and readable summary lines.

All waiting updates

GET /updates

Ability: read. Grouped by item: { key, type, slug, name, sites: [{ id, name, client, from, to, manageable, needs_license }] }.

Bulk update

POST /updates

Ability: plugins. One backup per site, then its updates.

{
  "backup_first": true,
  "picks": [
    { "site_id": 12, "type": "plugin", "slug": "wordpress-seo/wp-seo.php" },
    { "site_id": 15, "type": "theme",  "slug": "blocksy" },
    { "site_id": 15, "type": "core",   "slug": "core" }
  ]
}

Returns the queued activities, plus skipped for sites that aren’t connected or need a newer plugin.

Was this helpful?