Rules reference

Every trigger, site choice, action, limit and email setting a rule can have, and exactly what each one does.

Updated Oct 11, 2026

This page lists every option in the rule editor. For the big picture, start with How rules work.

When: schedules

Option What it does
Every day at a time Runs once a day at that time.
Every week on a day, at a time Runs once a week. Tuesday is the default (most plugin authors ship fixes early in the week).
Every month on day 1–28, at a time Runs once a month. Days 29–31 aren’t offered so the rule runs in February too.
Every quarter on day 1–28, at a time Runs in January, April, July and October. Good for quarterly client reports.

Times use the 24-hour clock in your timezone (Settings › Profile).

When: events

Event Fires when Notes
A backup fails A backup of the site fails a set number of times in a row (1 to 10). Fires once per streak: with “2 times”, it fires on the second failure, not again on the third. A successful backup resets the count.
An update fails An install, update, activation or delete on the site fails or only partly works. Covers changes made in WP Foreman, by the Foreman and over the API. Updates a rule made don’t set it off.
Someone changes a site outside WP Foreman Any change to plugins, themes or WordPress made in wp-admin, WP-CLI, over FTP or by your host, or a new administrator. WordPress’s own auto-updates and scheduled tasks don’t count.
Someone installs a plugin outside WP Foreman A plugin is installed (or appears) on the site without WP Foreman. With plugin 0.7.0+ this is within seconds and includes who did it. Otherwise at the next check, about every 30 minutes.
Someone deletes or deactivates a plugin outside WP Foreman A plugin is deleted or switched off outside WP Foreman.
A new administrator is added Someone creates an administrator, or makes an existing user one. Needs plugin 0.7.0+.
WordPress is updated outside WP Foreman WordPress core is updated by hand or by the host.
A site goes down Uptime monitoring confirms the site is down (failed twice, and from another region). See How uptime monitoring works. Fires once per outage.
A site comes back up The first passing check after an outage.
An SSL certificate or domain is about to expire 14 days and 3 days before either date. See SSL certificate and domain expiry.
A visual check finds pages that look different A visual check (after updates, weekly, or one you ran) finds a page 2% or more different from its last screenshot. Pair with Email me so someone takes a look. See Visual checks.
A known security issue is found on a site The nightly check, a change to the site’s plugins or themes, or a newly published vulnerability (checked every hour) finds a known vulnerability that wasn’t there before. Pair with Update to install fixes straight away. See Known vulnerabilities.
A site’s mobile speed score drops 10+ points The daily PageSpeed test scores 10 or more below the site’s average of its last 7 tests. Needs at least 3 earlier tests. See Site speed.
A site disconnects Someone clicks Disconnect in the WP Foreman plugin, or the plugin is removed. A disconnected site can’t be backed up or updated, so pair this with Email me.

Where

Option Covers
All sites (including new ones) Every site in your account, including sites you add later.
A client’s sites Every site assigned to that client, including ones you assign later.
Chosen sites Only the sites you tick.

Then: actions

Pick at least one.

Action What it does
Back up the site Starts a backup. If the rule also applies updates, the backup before the updates counts, so you don’t get two.
Apply updates to plugins, themes, WordPress Applies the available updates that pass the Only if limits below. Always backs up first. The WP Foreman plugin is never updated by a rule (it updates itself from the site’s Overview).
Email me Emails you a summary every time the rule runs, whatever happened. Handy for event rules like “a client installed a plugin”.
Make a client report for a period, and email it Makes a client report for each site (last month, the last 7 or 30 days, last quarter, or this month so far) using the site’s saved sections and its client’s logo and color. Then emails it to the client’s report emails (from the Clients page), to you, to both, or just saves it. Sites with no client or no saved report emails still get a report; the run notes it wasn’t emailed. Reports don’t need the site to be connected.
Send the rule.ran webhook Sends a signed POST to your webhooks subscribed to rule.ran, for Slack via Zapier or Make, or your own tools. See Webhooks.

Only if: limits on updates

These show when the rule applies updates.

Option What it does
Patch only (1.2.3 → 1.2.4) Only updates where the first two numbers stay the same. Usually bug and security fixes. The safest choice.
Minor and patch (1.2 → 1.3) Also updates where the second number changes. The default.
All, including major (1.x → 2.0) Everything. Major versions are where things break, so think about whether a robot should do these.
Never update A comma-separated list of plugins or themes to leave alone, for example woocommerce, elementor.
Only these If filled in, only these plugins or themes are updated. Leave empty for all.
Skip updates marked “Can’t download” On by default. Premium plugins without an active license or account connection have no download link for their update, so trying just fails.

WordPress versions. WordPress calls 6.8 → 6.9 a major release, so WP Foreman does too. “Minor and patch” applies 6.8.1 → 6.8.2 but not 6.8 → 6.9. Choose All if you want WordPress feature releases applied automatically.

Matching names. Each entry in Never update or Only these matches a plugin or theme by its name as shown in WordPress (Gravity Forms), its folder (gravityforms) or its full slug (gravityforms/gravityforms.php). Capital letters don’t matter.

Only if: time window

Only run between two times (your timezone) stops the rule touching sites outside those hours. Useful for event rules: “when a client installs a plugin, back up, but only overnight”. The hours can cross midnight, for example 22:00 to 06:00. Leave both empty to allow any time. Sites outside the window are skipped and the skip is logged. The window only holds back backups and updates; emails, webhooks and reports go out whenever the rule runs.

Tell me

Shown when Email me isn’t ticked.

Option You get an email
Only if something needs me When a site was skipped, an update was refused, or something failed. The default.
Every time it runs After every run.
Never (it’s all in the log) No email. Everything is still in the rule’s history and the site log.
Was this helpful?