API: plugins, themes and updates
Install, activate, update and delete plugins and themes, update WordPress, and run bulk updates across sites.
Updated Oct 11, 2026
Run an action on a site
POST /sites/{id}/actions
Ability: plugins. Activate, deactivate and theme switches run straight away and answer 200. Everything else is queued and answers 202; poll GET /activity/{id}.
action |
Body |
|---|---|
plugins.update |
slugs: plugin files, e.g. ["wordpress-seo/wp-seo.php"] |
plugins.activate / plugins.deactivate |
slugs |
plugins.delete |
slugs |
plugins.install |
items: [{ "slug": "wordpress-seo" }] from wordpress.org, or [{ "url": "https://…/plugin.zip" }]; optional activate |
themes.update / themes.delete |
slugs: theme folders, e.g. ["blocksy"] |
themes.install |
items as above; optional activate |
themes.activate |
slug |
core.update |
nothing |
Updates, deletes and core updates take a backup first. Send "backup_first": false to skip it.
curl -X POST https://app.wpforeman.com/api/v1/sites/12/actions \
-H "Authorization: Bearer YOUR_TOKEN" -H "Content-Type: application/json" \
-d '{"action":"plugins.install","items":[{"slug":"wordfence"}],"activate":true}'
Install from an uploaded .zip
POST /sites/{id}/install-upload
Ability: plugins. Send multipart/form-data with type (plugin or theme), file (the .zip, up to 50 MB) and optional activate (1). Answers 202 with the queued activity.
curl -X POST https://app.wpforeman.com/api/v1/sites/12/install-upload \
-H "Authorization: Bearer YOUR_TOKEN" -H "Accept: application/json" \
-F type=plugin -F activate=1 -F [email protected]
The finished activity has per-item results (ok, error, from, to) and readable summary lines.
All waiting updates
GET /updates
Ability: read. Grouped by item: { key, type, slug, name, sites: [{ id, name, client, from, to, manageable, needs_license }] }.
Bulk update
POST /updates
Ability: plugins. One backup per site, then its updates.
{
"backup_first": true,
"picks": [
{ "site_id": 12, "type": "plugin", "slug": "wordpress-seo/wp-seo.php" },
{ "site_id": 15, "type": "theme", "slug": "blocksy" },
{ "site_id": 15, "type": "core", "slug": "core" }
]
}
Returns the queued activities, plus skipped for sites that aren’t connected or need a newer plugin.
Thanks. If something was missing, tell us what.