Title: TrustBrain Update Manager
Author: TrustBrain
Published: <strong>September 30, 2026</strong>
Last modified: September 30, 2026

---

Search plugins

![](https://ps.w.org/trustbrain-update-manager/assets/banner-772x250.png?rev=3720170)

![](https://ps.w.org/trustbrain-update-manager/assets/icon.svg?rev=3720170)

# TrustBrain Update Manager

 By [TrustBrain](https://profiles.wordpress.org/iwamura/)

[Download](https://downloads.wordpress.org/plugin/trustbrain-update-manager.1.0.0.zip)

 * [Details](https://wordpress.org/plugins/trustbrain-update-manager/#description)
 * [Reviews](https://wordpress.org/plugins/trustbrain-update-manager/#reviews)
 *  [Installation](https://wordpress.org/plugins/trustbrain-update-manager/#installation)
 * [Development](https://wordpress.org/plugins/trustbrain-update-manager/#developers)

 [Support](https://wordpress.org/support/plugin/trustbrain-update-manager/)

## Description

TrustBrain Update Manager gives you fine-grained control over how your WordPress
site is updated:

#### Update Policies

 * Set an update policy per target type (core / plugins / themes / translations)
 * Policy levels: follow WordPress / auto-update patch versions only / up to minor
   versions / everything including major versions
 * Per-plugin and per-theme policy overrides on top of the global policy; the policy
   decides on its own, and the Plugins / Themes lists show which policy applies 
   to each item
 * Core updates are additionally checked against the required PHP and MySQL/MariaDB
   versions before updating
 * Branch pinning for plugins and themes distributed on WordPress.org: a patch-only
   or minor-only policy installs the newest release inside the allowed branch instead
   of skipping the update entirely

#### Where the list of versions comes from

Branch pinning needs to know which versions exist. For an item distributed on WordPress.
org, the list comes from WordPress.org, and the chosen version is downloaded from
WordPress.org and installed automatically.

For an item distributed elsewhere, the tags of the public GitHub or GitLab repository
its source is published from are read instead, found from the item’s own Plugin 
URI / Theme URI / Update URI, the URL its update comes from, or its composer.json.
The newest version within the policy is then shown on the Plugins / Themes lists,
the per-item policies page and the update targets page, but it is not installed 
automatically: nothing is downloaded from outside WordPress.org. The offer outside
the policy is not installed either, so you can get that version from the repository
and upload it yourself.

#### GitHub access token (optional)

Without a token GitHub answers sixty requests an hour per IP address, which is shared
with every other site on the same server. When that runs out the version list cannot
be read, and the newest version within the policy is not shown until it recovers.
A token raises the limit and is set on the Maintenance page.

The token needs no permissions at all: it is only used to read public tags. It is
sent to api.github.com and to nowhere else, is stored outside the other settings,
and is deleted when the plugin is uninstalled whatever else you keep.

#### Scheduled Updates

 * Run automatic updates on your own schedule (hourly to monthly, with day-of-week/
   day-of-month and time settings)
 * While the schedule is enabled, the WordPress native automatic updater is paused
   so updates never run twice
 * “Check for updates” and “Run update now” buttons for immediate execution with
   real result feedback
 * “Check for updates” asks every source again, including the version lists, so 
   it never answers with what was true an hour ago

#### Update Logging

 * All installs, updates, and deletions of core, plugins, themes, and translations
   are recorded in a dedicated log
 * Filterable log screen (by type, by status, and by the individual plugin or theme)
   with version, update level, user, and failure messages
 * When an update fails and leaves the item unusable on disk, the row says so: a
   failure that needs hands is not left looking like one that will simply be retried

#### Update Status

 * One unified status page showing available core, plugin, theme, and translation
   updates with the auto-update decision for each item
 * Every item that will not be updated says why, and an item held back by its own
   update source is listed with the version that exists and the requirement this
   site does not meet
 * The time the update information was fetched is shown, so a screen describing 
   a stale answer can be recognised as one
 * A policy overview card on the native WordPress Updates screen (update-core.php)

#### Email Notification

 * One consolidated notification email after automatic updates, replacing the individual
   WordPress native emails
 * Several recipients and Bcc addresses, separated with commas
 * Every piece of wording is editable: subject, body, the heading of each section,
   the guidance heading, and the format of the core and item detail lines. Clearing
   a field puts the bundled wording back
 * Includes post-update check guidance when a major or minor version upgrade is 
   involved

#### Multisite

 * On a network every screen is in the network admin, and the settings apply to 
   the whole network. WordPress runs automatic updates on the main site of a network,
   and the plugin and theme files are shared by every site, so there is one set 
   of policies and one update log rather than one per site
 * What an uninstall removes is set for the network, because uninstalling takes 
   the plugin off every site at once

### Third-Party Services

This plugin communicates with the following services. No personal data is sent to
any of them.

WordPress.org API, to retrieve core version and requirement information, and the
list of released versions of a plugin or theme hosted there. This is the same endpoint
WordPress core uses.

 * Endpoints: `api.wordpress.org/core/version-check/1.7/` , `api.wordpress.org/plugins/
   info/1.2/` , `api.wordpress.org/themes/info/1.2/`
 * Terms of Service: https://wordpress.org/about/privacy/

GitHub API, to read the tags of a public repository, only for an item whose source
is published there and only while a patch-only or minor-only policy is in use. The
request carries the repository owner and name, and the access token when one has
been set.

 * Endpoint: `api.github.com/repos/{owner}/{repository}/tags`
 * Terms of Service: https://docs.github.com/site-policy/github-terms/github-terms-
   of-service
 * Privacy Policy: https://docs.github.com/site-policy/privacy-policies/github-privacy-
   statement

GitLab API, for the same purpose and under the same conditions as GitHub.

 * Endpoint: `gitlab.com/api/v4/projects/{project}/repository/tags`
 * Terms of Service: https://about.gitlab.com/terms/
 * Privacy Policy: https://about.gitlab.com/privacy/

## Screenshots

[⌊Update settings: how far automatic updates may go for core, plugins, themes and
translations.⌉⌊Update settings: how far automatic updates may go for core, plugins,
themes and translations.⌉[

Update settings: how far automatic updates may go for core, plugins, themes and 
translations.

[⌊Per-item policies: override the common setting for a single plugin or theme, and
see the result before saving.⌉⌊Per-item policies: override the common setting for
a single plugin or theme, and see the result before saving.⌉[

Per-item policies: override the common setting for a single plugin or theme, and
see the result before saving.

[⌊Update targets: what will be updated automatically, and why the rest will not.⌉⌊
Update targets: what will be updated automatically, and why the rest will not.⌉[

Update targets: what will be updated automatically, and why the rest will not.

[⌊Update log: installs, updates and removals, with the versions before and after.⌉⌊
Update log: installs, updates and removals, with the versions before and after.⌉[

Update log: installs, updates and removals, with the versions before and after.

[⌊Schedule: run updates at a time you choose instead of WordPress's own timing.⌉⌊
Schedule: run updates at a time you choose instead of WordPress's own timing.⌉[

Schedule: run updates at a time you choose instead of WordPress’s own timing.

## Installation

 1. Upload the `trustbrain-update-manager` folder to the `/wp-content/plugins/` directory
 2. Activate the plugin through the ‘Plugins’ menu in WordPress. On a multisite network,
    network-activate it from the network admin
 3. Go to ‘Update Manager’ in the admin menu to configure the update policies
 4. Optionally enable a schedule on the ‘Schedule’ page

## FAQ

### Why does this plugin change how WordPress updates itself?

That is what it is for. It decides whether each item is auto-updated through the
filters WordPress provides for exactly that (`auto_update_core`, `auto_update_plugin`,`
auto_update_theme`, `auto_update_translation`, `automatic_updater_disabled`), and
it hands a different package to WordPress through `upgrader_pre_download` when a
policy pins an item to a version inside its branch.

It does not replace the WordPress updater and does not bring one of its own. Every
download and every install runs through the WordPress upgrader, so update logging,
rollback, and error handling behave as they normally do. Update information is left
as WordPress stores it, and no update notice is ever hidden.

### What is the difference between “Check for updates” and “Run update now”?

“Check for updates” asks every update source again and shows what is available; 
it installs nothing. “Run update now” installs the updates that are allowed by your
update policies, immediately.

### Do updates run twice when the schedule is enabled?

No. While the schedule is enabled, the WordPress native automatic updater is disabled
via the `automatic_updater_disabled` filter, and updates run only at the scheduled
time or via “Run update now”.

### Are security releases pushed by WordPress.org still installed?

Yes. When the update source marks an update for automatic installation, which is
how a security release reaches sites that have not turned automatic updates on, 
it is installed whatever the policy says, and it is installed as offered rather 
than replaced by an older release within the policy.

### Does this plugin replace the WordPress update emails?

Yes. The individual native auto-update result emails are disabled and replaced by
one consolidated notification.

### A newer version exists but WordPress shows nothing. Why?

Because the update source is holding it back. When a new release requires a newer
WordPress or PHP than the site runs, the source reports the item as up to date and
carries the new version in that answer. WordPress shows nothing for it: no update
row, no entry on the updates screen, no count. From the outside “there is no update”
and “there is one you cannot install yet” look the same.

The update targets screen lists these separately, with the version that exists, 
what it requires, and which requirement this site does not meet. Raising the site
to that WordPress or PHP version makes the update appear normally.

### Why does an update never appear for an inactive plugin or theme?

Because the update mechanism belongs to the plugin or theme itself, and WordPress
does not load it while the item is inactive. WordPress loads the functions.php of
the active theme and its parent only, and a plugin’s code runs only while the plugin
is active. WordPress.org is asked about every installed item, but an item hosted
elsewhere is never asked about.

Activate the theme or plugin, and its own update mechanism will report updates again.
This plugin cannot work around it.

### A patch-only policy did not pin an item to a version inside its branch. Why?

Either the versions that exist could not be read, or the item is not distributed
on WordPress.org. The versions are read from WordPress.org, or from a public GitHub
or GitLab repository the item’s source is published from; for an item distributed
from somewhere else, the offer is the only version known, and an offer outside the
policy is not installed at all. For an item whose versions come from a GitHub or
GitLab repository, the newest version within the policy is shown but not installed
automatically, because this plugin downloads packages from WordPress.org only. The
update targets screen says which of these happened.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“TrustBrain Update Manager” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ TrustBrain ](https://profiles.wordpress.org/iwamura/)

[Translate “TrustBrain Update Manager” into your language.](https://translate.wordpress.org/projects/wp-plugins/trustbrain-update-manager)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/trustbrain-update-manager/),
check out the [SVN repository](https://plugins.svn.wordpress.org/trustbrain-update-manager/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/trustbrain-update-manager/)
by [RSS](https://plugins.trac.wordpress.org/log/trustbrain-update-manager/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * Initial release.

## Meta

 *  Version **1.0.0**
 *  Last updated **17 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [auto-update](https://wordpress.org/plugins/tags/auto-update/)[maintenance](https://wordpress.org/plugins/tags/maintenance/)
   [notification](https://wordpress.org/plugins/tags/notification/)[updates](https://wordpress.org/plugins/tags/updates/)
 *  [Advanced View](https://wordpress.org/plugins/trustbrain-update-manager/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/trustbrain-update-manager/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/trustbrain-update-manager/reviews/)

## Contributors

 *   [ TrustBrain ](https://profiles.wordpress.org/iwamura/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/trustbrain-update-manager/)