Websites on WP Engine

Until WP Engine allows WP Foreman across their platform, each website needs a one-time request to their support so updates and installs work.

Updated Oct 11, 2026

WP Foreman connects to websites on WP Engine like any other host: backups, inventory, uptime, reports and one-click wp-admin all work as soon as the website is connected. The exception is anything that writes plugin or theme files, which means updates, installs, deletes and restores. WP Engine only lets requests it trusts change those files, so they fail with “Could not copy file” until WP Engine adds a rule for WP Foreman to the website.

We’ve asked WP Engine to add this rule across their whole platform, as they do for other WordPress management tools. Until they do, it takes one support request per WP Engine account. We’ll update this page when it’s no longer needed.

How to tell if a website needs it

  • The website is hosted on WP Engine (WP Foreman shows this in the error message).
  • Updates or installs from WP Foreman fail with “Could not copy file” or “Could not fully remove”, while the same update works from wp-admin.
  • The website is on WP Foreman plugin 0.7.6 or newer. If it’s older, update the plugin first, by hand in wp-admin.

Ask WP Engine support

Open a chat with WP Engine support and paste this. Asking for the whole account covers every website and environment in one go.

Hi, I use WP Foreman (wpforeman.com) to manage my WordPress websites. Please add
this Nginx rule to all websites on my account, in every environment (PRD, STG and
DEV), so WP Foreman's requests can update and install plugins and themes. It's the
same kind of rule you use for MainWP, matched on WP Foreman's user agent:

set $wpf_ua 0;
if ($http_user_agent ~* WPForeman) {
  set $wpf_ua 1;
}
set $wpf_location 0;
if ($uri ~* "^/(wp-cron\.php|wp-admin/admin-ajax\.php)") {
  set $wpf_location 1;
}
set $wpf_both "$wpf_ua:$wpf_location";
if ($wpf_both = "1:1") {
  set $is_trusted 1;
  proxy_pass http://localhost:6788;
}

Requests come from WP Foreman's server (134.209.78.176) with the user agent
WPForeman/1.0. Details: https://wpforeman.com/docs/how-wp-foreman-connects/

Support may say a map needs extra permissions. The rule above uses if blocks only, which front-line support can add.

Test it

  1. In WP Foreman, open the website and go to Plugins & themes.
  2. Install a small plugin like Hello Dolly (leave it inactive), then delete it.
  3. If both succeed, the rule is working. If it still fails, ask support to check that the rule has been applied to the live server and covers /wp-admin/admin-ajax.php.

Is it safe?

Yes. The rule only tells WP Engine to treat WP Foreman’s requests like a signed-in wp-admin request. It doesn’t let anyone in: every command is still checked by the WP Foreman plugin for a valid signature from your WP Foreman account, and anything else is refused. Faking the user agent gets a request nowhere. See How WP Foreman connects.

After a failed update

When WP Engine stops an update partway through, some of the plugin’s files can end up new while others stay old, and WordPress may then report it as up to date. If that happened to a plugin before the rule was added, reinstall it once: download the current version and upload it in wp-admin › Plugins › Add New › Upload, choosing “Replace current with uploaded”.

Was this helpful?