Description
Document management and version control for WordPress. Collaborate on files, track every revision, and auto-generate change summaries with AI.
What is WP Document Revisions?
WP Document Revisions is a document management and version control plugin.Β Built for time-sensitive and mission-critical projects, teams can collaboratively edit files of any format — text documents, spreadsheets, images, sheet music… anything — all the while, seamlessly tracking the document’s progress as it moves through your organization’s existing workflow.
WP Document Revisions is three things
- π Document Management System (DMS) – Track, store, and organize files of any format
- π₯ Collaboration Tool – Empower teams to collaboratively draft, edit, and refine documents
- π File Hosting Solution – Publish and securely deliver files to teams, clients, or the public
β¨ Modern and AI-ready
WP Document Revisions keeps pace with modern WordPress:
- π Full-text search inside your files β native text extraction from PDF, DOCX, and ODT documents (pluggable for more formats) makes document contents searchable, not just their titles.
- π€ AI-generated revision summaries β powered by the WordPress 7.0 AI Client, each new revision can be summarized automatically from a diff against the prior version and pre-filled into the revision log for your review (opt-in, with per-document and sitewide opt-outs).
- π§± Block editor support β an opt-in Gutenberg editing experience with a document sidebar panel for uploads, revision summaries, and lock status.
- π REST API & WP-CLI β manage documents headlessly and backfill the search/AI cache across your whole library from the command line.
See the full list of features for more information.
π Documentation
Complete Documentation Site – Your one-stop resource for everything about WP Document Revisions.
π― Quick Start Guides
- Installation – Get up and running in minutes
- Features and Overview – Discover what WP Document Revisions can do
- Screenshots – See the plugin in action
π User Documentation
- Frequently Asked Questions – Common questions answered
- Block Editor Support – Opt-in Gutenberg editing for documents
- Plugin Actions – Available WordPress actions
- Plugin Filters – Available WordPress filters
- Plugin Shortcodes and Widget – Display documents on your site
- Useful Plugins and Tools – Extend functionality
- Cookbook – Integration guides and recipes
- Translations – Multi-language support
- Links – Additional resources
π Support & Community
- Where to get Support or Report an Issue – Get help when you need it
- How to Contribute – Join our community
- Join the Mailing List – Stay updated
Features
Overview
PowerfulΒ Collaboration Tools – With great power does not have to come great complexity. Based on a simpleΒ philosophyΒ of putting powerful but intuitive tools in the hands of managers and content creators, WP Document Revisions leverages many of the essential WordPress features that,Β for more than eight years,Β have been tested and proven across countless industriesβββposts, attachments, revisions, taxonomies, authentication, and permalinksβββto make collaborating on the creation and publication of documents a natural endeavor.Β Think of it as an open-source and more intuitive version of the popular MicrosoftΒ collaborationΒ suite, Sharepoint.
Document History – At each step of the authoring process, WP Document Revisions gives you an instant snapshot of your team’s progress and the document’s history. It even gives you the option to revert back to a previous revisionβββso don’t fret if you make a mistakeβββorΒ receiveΒ updates on changes to the document right in your favorite feed reader.
Access Control – Each document is given aΒ persistentΒ URL (e.g., yourcompany.com/documents/2011/08/TPS-Report.doc) which can be private (securelyΒ delivered only to members of your organization), password protected (available only to those you select such as clients or contractors), or public (published and hosted for the world to see). If you catch a typo and upload a new version, that URL will continue to point to the latest version, regardless of how many changes you make.
Enterprise Security – Worried about storing propriety or sensitive information? WP Document Revisions was built from the first line of code with government- and enterprise-grade security in mind.Β Each file is masked behind an anonymous 128-bit MD5 hash as soon as it touches the server, andΒ requests for files are transparently routed through WordPress’s time-tested URL rewriting, authentication, and permission systems (which can even integrate with existing enterprise active directory or LDAP servers). Need more security? WP Document Revisions allows you to store documents in a folder above the htdocs or public_html web root, further ensuring that only those you authorize have access to your work.
CustomizationΒ – WP Document Revisions recognizes that no two teams areΒ identical,Β and as a result, molds to your firm’s needs, not the other way around. Need to trackΒ additionalΒ information associated with a document?Β Departments, editors, issues, sections, even arbitrary key-valueΒ pairsΒ β whatever you can throw at it, it can handle. Development and customization costs are further minimized by its extensive plugin API, and the WordPress Custom Taxonomy Generator makes it easy for even theΒ uninitiatedΒ to add custom taxonomies to documents. Need an audit trail to track check-ins and check-outs? User-level permissions based on the document’s state or another custom taxonomy? Support for third-party encryption? Check out the WP Document Revisions Code Cookbook for sample code. Looking for even more advanced control of your workflow? WP Document Revisions will detect the popular workflow plugin Edit Flow, if installed, and will automatically pull Edit Flowβs advanced workflow management tools into WP Document Revisions. Simply put, virtually every aspect of the plugin’s functionalityΒ from workflow states to user-level permissionsΒ can be fully customized to your team’s unique needs.
Future Proof – Switching costs a concern? WP Document Revisions is built with tomorrow’s uncertainty in mind. Equally at home in an in-house server room as it is in the cloud, moving individual files or entire document repositories in and out of WP Document Revisions is a breeze (history and all). And since the software is open-source, you can easily add tools to automate the process of moving to or integrating with future third-party systems.
Features
- Support for any file type (docs, spreadsheets, images, PDFsβββanything!)
- Securely stores unlimited revisions of your business’s essential files
- Provides a full file history in the form of a revision log,Β accessibleΒ via RSS
- Helps you track and organize documents as they move through your organization’s existing workflow
- Each file gets a permanent, authenticated URL that always points to the latest version
- Each revision gets its own unique url (e.g.,TPS-Report-revision-3.doc)Β accessibleΒ only to those you deem
- Files are intuitively checked out and locked to prevent revisions fromΒ colliding
- Toggle documents between public, private, and password protected with a single mouse click
- Runs in-house or in the cloud
- Secure: filenames are hashed on upload and files are only accessible through WordPress’s proven authentication system
- Can move document upload folder to location outside of web root to further ensure government- and enterprise-grade security
- Documents and Revisions shortcodes, Recently Revised Documents widget
- Multisite and Windows (XAMPP) support
- Fully translatable, with community translations delivered as WordPress.org language packs (help translate)
- Integration with Edit Flow, PublishPress or PublishPress Statuses.
- Opt-in Block Editor (Gutenberg) support with document sidebar panel
- REST API security hardening: attachment data sanitized for non-editors, attachment ownership validation
- WordPress Abilities API integration (WP 6.9+) for AI agents and the command palette, with read-only abilities exposed over the Model Context Protocol via the WordPress MCP Adapter
- Native text extraction from PDF, DOCX, and ODT files (pluggable for additional formats), cached per-attachment for search and AI use
- AI-generated revision summaries via the WordPress 7.0 AI Client, computed from a unified diff of the new revision against the prior one and pre-filled into the revision log for editor review. See the Text Extraction & AI cookbook entry for customization recipes
- WP-CLI
document-revisions extract-textcommand to backfill the extraction cache across an existing library, with--all/--missing/--id/--extractor/--force/--dry-runselectors - WP-CLI
document-revisions validate [--fix]command that runs the Validate Structure checks across every document and applies the available fixes - Per-document and sitewide opt-outs for text extraction and AI pre-fill β extraction respects
WPDR_TEXT_EXTRACTION, AI pre-fill respectsWPDR_AI_SUMMARY_PREFILLand the coreWP_AI_SUPPORTconstant - Clean uninstall: options, user meta, and capabilities removed on plugin deletion
- Deactivation hook flushes rewrite rules for clean deactivation
- Recently Revised Documents Widget, shortcodes, and templating functions for front-end integration
- Opt-in email notifications when a document changes workflow state or gains a new revision, with a configurable recipient list (see Document Notifications)
Features Available via the [Code Cookbook](https://github.com/wp-document-revisions/wp-document-revisions-Code-Cookbook)
- Audit Trail – creates check in / check out audit trail for all documents
- Taxonomy-based Permissions – allows setting user-level permissions based on a custom taxonomy such as department
- Third Party Encryption – example of how to integrate at rest encryption using third-party tools
- Rename Documents – changes all references to “Documents” in the interface to any label of your choosing
- Bulk Import – how to batch import a directory (or other list) of files as documents
- Filetype Taxonomy – Adds support to filter by filetype
- Track Changes – Auto-generates and appends revision summaries for changes to taxonomies, title, and visibility
- Change Tracker – Auto-generates and appends revision summaries for changes to taxonomies, title, and visibility
- WPML Support – Integration with WPML
Links
- Source Code (GitHub)
- Latest Release – Download the newest version
- WordPress.org Plugin Page – Official plugin listing
- Development Version (CI Status)
- Code Cookbook – Code examples and customizations
- Translations (translate.wordpress.org)
- Where to get Support or Report an Issue – Get help when you need it
- How to Contribute – Join our community
Document Notifications
WP Document Revisions can email interested people when a document moves through your workflow β when it changes workflow state (for example, moved to Under Review or Approved) or when a new revision is saved. This turns workflow states from passive labels into an active review loop: the reviewer actually hears about it.
Notifications are opt-in and disabled by default, so enabling the plugin (or upgrading) never starts sending mail on its own.
Enabling notifications
Notifications are configured under Settings Media, in the Document Notifications section:
- Email notifications when documents change β the master switch. Off by default; nothing is sent until you turn it on.
- Notify these email addresses β a site-wide recipient list (one address per line, or comma-separated).
- Notify when a document changes workflow state β on by default (only takes effect once the master switch is on).
- Notify when a new revision of a document is saved β off by default.
Who gets notified
For each event, the recipients are:
- everyone on the site-wide recipient list, plus
- the document’s author,
with two rules always applied:
- the person who made the change is never notified of their own change, and
- duplicate and invalid addresses are removed.
Each recipient receives their own copy β the recipient list is never exposed to the others, and no stray copy is sent to the site administrator.
Note on bulk edits: because a notification is sent per document, changing the workflow state of many documents at once (for example, a bulk edit) sends one notification per document. Use the
document_notification_recipientsfilter to suppress or reroute mail in that situation if needed.
Customizing with filters
Every part of the behavior is filterable. See Filters for full signatures. In brief:
document_notify_enabled,document_notify_on_state_change,document_notify_on_new_revisionβ force-enable or force-disable the master switch and each event.document_notification_recipientsβ receives( array $emails, int $doc_id, string $event, int $actor_id ). This is the seam for advanced routing: notify prior editors, or route by workflow state (e.g. send Under Review transitions to a review team).document_notification_subject,document_notification_messageβ customize the email subject and body.document_notification_headersβ add email headers (e.g. aFrom:orReply-To:).
Example: route “Under Review” to a review team
`php
add_filter(
‘document_notification_recipients’,
function ( $emails, $doc_id, $event, $actor_id ) {
if ( ‘state_change’ !== $event ) {
return $emails;
}
$states = wp_get_object_terms( $doc_id, ‘workflow_state’, array( ‘fields’ => ‘names’ ) );
if ( in_array( ‘Under Review’, $states, true ) ) {
$emails[] = ‘review-team@example.com’;
}
return $emails;
},
10,
4
);
<h3>Delivery</h3>wp_mail()`. On sites with high mail volume or a slow mail server, install a transactional-email/SMTP plugin so delivery does not add latency to saving a document.
Notifications are sent through WordPress's standard
Translations
Help bring WP Document Revisions to your language. Translations are managed on translate.wordpress.org, and WordPress installs them automatically as language packs, so every translated string reaches every site using that language. No coding or GitHub account is needed. A free WordPress.org account is enough.
The most helpful thing you can do: review suggestions
Thirty languages already have a nearly complete set of suggested translations waiting for review. Some carry over from the plugin’s earlier translators, and most are machine translations that need a fluent speaker to check them. A language pack is published once a language reaches 90% approved translations, so reviewing is the fastest way to get the plugin working in your language.
- Sign in with your WordPress.org account.
- Open the plugin’s translation project and choose your language.
- Filter by Waiting to see the suggestions, then fix anything that reads wrong. You can also translate any untranslated strings.
- To approve suggestions yourself, request Project Translation Editor access for your language, or ask your language’s local Polyglots team to review them.
New to translating WordPress? The Polyglots handbook covers the basics, including each language’s style guide and glossary.
Found a bad translation?
Suggest a better one on translate.wordpress.org rather than opening a pull request. Translation files bundled with the plugin are overridden by WordPress.org language packs, so fixes belong there.
Thanks to everyone who has contributed translations, including:
- French – Hubert CAMPAN
- Spanish – IBIDEM GROUP, TradiArt, and elarequi
- Norwegian – Daniel Haugen
- German –Konstantin Obenland
- Chinese – Tim Ren
- Swedish – Daniel Kroon, Examinare AB, Sweden.
- Czech – Hynek Ε Ε₯avΓk
- Italian – @guterboit
- Russian – Evgeny Vlasov
- Dutch – @tijscruysen
Useful plugins and tools
Permissions management
-
Members – Membership & User Role Editor Plugin
(Previously called Members)
Taxonomy management
Email notification and distribution
Document workflow management
- Edit Flow
- PublishPress Statuses
- PublishPress Revisions – See the integration guide for scheduling document revisions
Screenshots



Blocks
This plugin provides 4 blocks.
- Document Preview Embed an inline preview of a document's latest revision.
- Document Revisions Display a list of revisions for your document.
- Latest Documents Display a list of your most recent documents.
- Documents List Display a list of documents.
Installation
π Automatic Install (Recommended)
- Log into WordPress Admin – Login to your WordPress site as an Administrator, or if you haven’t already, complete the WordPress installation
- Go to Plugins – Navigate to Plugins > Add New from the left menu
- Search – Search for “WP Document Revisions”
- Install – Click “Install Now” next to WP Document Revisions
- Activate – Click “Activate” to enable the plugin
π¦ Manual Install
- Download – Get the latest version from WordPress.org or GitHub Releases
- Upload – Unzip the file and upload the “wp-document-revisions” folder to your
/wp-content/plugins/directory - Activate – Log into WordPress admin, go to Plugins, and activate “WP Document Revisions”
π» Developer Install
For development or contributing:
`bash
git clone https://github.com/wp-document-revisions/wp-document-revisions.git cd wp-document-revisions composer install –no-dev `
βοΈ Requirements
- WordPress: 5.0 or higher
- PHP: 7.4 or higher
- File Permissions: WordPress must be able to write to the uploads directory
π― Next Steps
After installation, you’ll find a new Documents menu in your WordPress admin. Start by:
- Creating your first document – Go to Documents > Add New
- Setting up workflow states (optional) – Go to Documents > Workflow States
- Configuring permissions – Review Settings > Document Revisions
Need help? Check our FAQ or get support.
Reviews
Contributors & Developers
“WP Document Revisions” is open source software. The following people have contributed to this plugin.
Contributors“WP Document Revisions” has been translated into 5 locales. Thank you to the translators for their contributions.
Translate “WP Document Revisions” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
Numbers in brackets show the issue number in https://github.com/wp-document-revisions/wp-document-revisions/issues/
5.7.0
- Security: on sites that enable block editor mode for documents (off by default), the Media Library grid listed the files of other users’ private, draft and password-protected documents to Authors and above, including their stored file names. In either mode, the media modal returned the same details for any attachment ID. Document files are now hidden from the grid in both modes, and the media modal hides the details of document files the user can’t edit (GHSA-2xcp-6j73-4cr7).
- AI summaries are no longer generated or shown for private or password-protected documents, since generating one sends the document’s text to the site’s AI provider. New documents are private by default, so sites that want summaries for them must opt in with the new
document_ai_summary_allow_privatefilter. Opting a document out of text extraction now also deletes its stored AI summaries. (#784) - Files for drafts, private and password-protected documents, and revisions are now served with
Cache-Control: private, no-store, so shared caches and proxies don’t keep them. All served files also sendX-Content-Type-Options: nosniff. (#781) - Document files are now stored under random names instead of names derived from the file name and upload time. (#780)
- An upload is only handled as a document upload (hashed name, document directory, document file types) when it targets a document the user can edit. Other uploads are handled as normal media. (#782)
- Users who can’t manage workflow states (Contributors, by default) can no longer create new ones when saving a document from the Workflow State box, quick edit or bulk edit. They can still pick an existing state. (#783)
- Text extraction skips files over 20 MB, and Word or OpenDocument files that unzip to more than 100 MB, instead of processing them. The limits can be changed with the new
wpdr_text_extraction_max_file_sizeandwpdr_text_extraction_max_uncompressed_sizefilters. The AI diff endpoint now applies the extraction time limit. (#786) - Regenerating a feed key from another user’s profile now changes that user’s key, not yours. (#785)
- Old URLs of renamed documents no longer redirect visitors who can’t see the document. (#785)
- Document REST requests that are refused no longer write document meta. (#785)
- Uninstalling the plugin now also removes per-site feed keys and the notification settings. (#785)
5.6.1
- Security: a user who could edit their own documents (Contributors and up, by default) could use the Validate Structure fix endpoint to rename and delete other media files on the site. Fixes now only touch the document’s own attachments (GHSA-wmqm-qwm3-9qgf).
- Security: the documents shortcode, the Documents List and Latest Documents blocks, and the
get_documents()template function could list other users’ draft, pending and private documents (titles, descriptions and authors) when asked for those statuses, and showed descriptions of password-protected documents. Lists now only include documents the viewer can read, and skip the description and thumbnail of password-protected documents. Thepost_passwordshortcode attribute has been removed (GHSA-xwv7-7xmq-wmxq). - Security: the document revisions shortcode and block listed the revision history of documents the viewer couldn’t read. They now check the document can be read (GHSA-cmhr-7795-vvfw).
- Security: the AI summary and diff REST endpoints served password-protected documents, and summaries of earlier revisions to users without the
read_document_revisionscapability. They now check access the same way as downloading the file (GHSA-987w-vg4c-32r3). - Security: on sites that enable the REST API for documents (off by default), the plugin’s REST checks could be skipped by changing the case of the route (for example
/wp/v2/Documents), and did not apply to the revisions list route (GHSA-fcf8-gjj8-pg9w).
5.6.0
For complete changelog, see GitHub
