WP Document Revisions

Description

Document management and version control for WordPress. Collaborate on files, track every revision, and auto-generate change summaries with AI.

What is WP Document Revisions?

WP Document Revisions is a document management and version control plugin.Β Built for time-sensitive and mission-critical projects, teams can collaboratively edit files of any format — text documents, spreadsheets, images, sheet music… anything — all the while, seamlessly tracking the document’s progress as it moves through your organization’s existing workflow.

WP Document Revisions is three things

  1. πŸ“ Document Management System (DMS) – Track, store, and organize files of any format
  2. πŸ‘₯ Collaboration Tool – Empower teams to collaboratively draft, edit, and refine documents
  3. πŸ”’ File Hosting Solution – Publish and securely deliver files to teams, clients, or the public

✨ Modern and AI-ready

WP Document Revisions keeps pace with modern WordPress:

  • πŸ” Full-text search inside your files β€” native text extraction from PDF, DOCX, and ODT documents (pluggable for more formats) makes document contents searchable, not just their titles.
  • πŸ€– AI-generated revision summaries β€” powered by the WordPress 7.0 AI Client, each new revision can be summarized automatically from a diff against the prior version and pre-filled into the revision log for your review (opt-in, with per-document and sitewide opt-outs).
  • 🧱 Block editor support β€” an opt-in Gutenberg editing experience with a document sidebar panel for uploads, revision summaries, and lock status.
  • πŸ”Œ REST API & WP-CLI β€” manage documents headlessly and backfill the search/AI cache across your whole library from the command line.

See the full list of features for more information.

πŸ“š Documentation

Complete Documentation Site – Your one-stop resource for everything about WP Document Revisions.

🎯 Quick Start Guides

πŸ“– User Documentation

πŸ†˜ Support & Community

Features

Overview

PowerfulΒ Collaboration Tools – With great power does not have to come great complexity. Based on a simpleΒ philosophyΒ of putting powerful but intuitive tools in the hands of managers and content creators, WP Document Revisions leverages many of the essential WordPress features that,Β for more than eight years,Β have been tested and proven across countless industriesβ€Šβ€”β€Šposts, attachments, revisions, taxonomies, authentication, and permalinksβ€Šβ€”β€Što make collaborating on the creation and publication of documents a natural endeavor.Β Think of it as an open-source and more intuitive version of the popular MicrosoftΒ collaborationΒ suite, Sharepoint.

Document History – At each step of the authoring process, WP Document Revisions gives you an instant snapshot of your team’s progress and the document’s history. It even gives you the option to revert back to a previous revisionβ€Šβ€”β€Šso don’t fret if you make a mistakeβ€Šβ€”β€ŠorΒ receiveΒ updates on changes to the document right in your favorite feed reader.

Access Control – Each document is given aΒ persistentΒ URL (e.g., yourcompany.com/documents/2011/08/TPS-Report.doc) which can be private (securelyΒ delivered only to members of your organization), password protected (available only to those you select such as clients or contractors), or public (published and hosted for the world to see). If you catch a typo and upload a new version, that URL will continue to point to the latest version, regardless of how many changes you make.

Enterprise Security – Worried about storing propriety or sensitive information? WP Document Revisions was built from the first line of code with government- and enterprise-grade security in mind.Β Each file is masked behind an anonymous 128-bit MD5 hash as soon as it touches the server, andΒ requests for files are transparently routed through WordPress’s time-tested URL rewriting, authentication, and permission systems (which can even integrate with existing enterprise active directory or LDAP servers). Need more security? WP Document Revisions allows you to store documents in a folder above the htdocs or public_html web root, further ensuring that only those you authorize have access to your work.

CustomizationΒ – WP Document Revisions recognizes that no two teams areΒ identical,Β and as a result, molds to your firm’s needs, not the other way around. Need to trackΒ additionalΒ information associated with a document?Β Departments, editors, issues, sections, even arbitrary key-valueΒ pairsΒ β€” whatever you can throw at it, it can handle. Development and customization costs are further minimized by its extensive plugin API, and the WordPress Custom Taxonomy Generator makes it easy for even theΒ uninitiatedΒ to add custom taxonomies to documents. Need an audit trail to track check-ins and check-outs? User-level permissions based on the document’s state or another custom taxonomy? Support for third-party encryption? Check out the WP Document Revisions Code Cookbook for sample code. Looking for even more advanced control of your workflow? WP Document Revisions will detect the popular workflow plugin Edit Flow, if installed, and will automatically pull Edit Flow’s advanced workflow management tools into WP Document Revisions. Simply put, virtually every aspect of the plugin’s functionalityΒ from workflow states to user-level permissionsΒ can be fully customized to your team’s unique needs.

Future Proof – Switching costs a concern? WP Document Revisions is built with tomorrow’s uncertainty in mind. Equally at home in an in-house server room as it is in the cloud, moving individual files or entire document repositories in and out of WP Document Revisions is a breeze (history and all). And since the software is open-source, you can easily add tools to automate the process of moving to or integrating with future third-party systems.

Features

  • Support for any file type (docs, spreadsheets, images, PDFsβ€Šβ€”β€Šanything!)
  • Securely stores unlimited revisions of your business’s essential files
  • Provides a full file history in the form of a revision log,Β accessibleΒ via RSS
  • Helps you track and organize documents as they move through your organization’s existing workflow
  • Each file gets a permanent, authenticated URL that always points to the latest version
  • Each revision gets its own unique url (e.g.,TPS-Report-revision-3.doc)Β accessibleΒ only to those you deem
  • Files are intuitively checked out and locked to prevent revisions fromΒ colliding
  • Toggle documents between public, private, and password protected with a single mouse click
  • Runs in-house or in the cloud
  • Secure: filenames are hashed on upload and files are only accessible through WordPress’s proven authentication system
  • Can move document upload folder to location outside of web root to further ensure government- and enterprise-grade security
  • Documents and Revisions shortcodes, Recently Revised Documents widget
  • Multisite and Windows (XAMPP) support
  • Fully translatable, with community translations delivered as WordPress.org language packs (help translate)
  • Integration with Edit Flow, PublishPress or PublishPress Statuses.
  • Opt-in Block Editor (Gutenberg) support with document sidebar panel
  • REST API security hardening: attachment data sanitized for non-editors, attachment ownership validation
  • WordPress Abilities API integration (WP 6.9+) for AI agents and the command palette, with read-only abilities exposed over the Model Context Protocol via the WordPress MCP Adapter
  • Native text extraction from PDF, DOCX, and ODT files (pluggable for additional formats), cached per-attachment for search and AI use
  • AI-generated revision summaries via the WordPress 7.0 AI Client, computed from a unified diff of the new revision against the prior one and pre-filled into the revision log for editor review. See the Text Extraction & AI cookbook entry for customization recipes
  • WP-CLI document-revisions extract-text command to backfill the extraction cache across an existing library, with --all/--missing/--id/--extractor/--force/--dry-run selectors
  • WP-CLI document-revisions validate [--fix] command that runs the Validate Structure checks across every document and applies the available fixes
  • Per-document and sitewide opt-outs for text extraction and AI pre-fill β€” extraction respects WPDR_TEXT_EXTRACTION, AI pre-fill respects WPDR_AI_SUMMARY_PREFILL and the core WP_AI_SUPPORT constant
  • Clean uninstall: options, user meta, and capabilities removed on plugin deletion
  • Deactivation hook flushes rewrite rules for clean deactivation
  • Recently Revised Documents Widget, shortcodes, and templating functions for front-end integration
  • Opt-in email notifications when a document changes workflow state or gains a new revision, with a configurable recipient list (see Document Notifications)

Features Available via the [Code Cookbook](https://github.com/wp-document-revisions/wp-document-revisions-Code-Cookbook)

  • Audit Trail – creates check in / check out audit trail for all documents
  • Taxonomy-based Permissions – allows setting user-level permissions based on a custom taxonomy such as department
  • Third Party Encryption – example of how to integrate at rest encryption using third-party tools
  • Rename Documents – changes all references to “Documents” in the interface to any label of your choosing
  • Bulk Import – how to batch import a directory (or other list) of files as documents
  • Filetype Taxonomy – Adds support to filter by filetype
  • Track Changes – Auto-generates and appends revision summaries for changes to taxonomies, title, and visibility
  • Change Tracker – Auto-generates and appends revision summaries for changes to taxonomies, title, and visibility
  • WPML Support – Integration with WPML

Links

Document Notifications

WP Document Revisions can email interested people when a document moves through your workflow β€” when it changes workflow state (for example, moved to Under Review or Approved) or when a new revision is saved. This turns workflow states from passive labels into an active review loop: the reviewer actually hears about it.

Notifications are opt-in and disabled by default, so enabling the plugin (or upgrading) never starts sending mail on its own.

Enabling notifications

Notifications are configured under Settings Media, in the Document Notifications section:

  • Email notifications when documents change β€” the master switch. Off by default; nothing is sent until you turn it on.
  • Notify these email addresses β€” a site-wide recipient list (one address per line, or comma-separated).
  • Notify when a document changes workflow state β€” on by default (only takes effect once the master switch is on).
  • Notify when a new revision of a document is saved β€” off by default.

Who gets notified

For each event, the recipients are:

  • everyone on the site-wide recipient list, plus
  • the document’s author,

with two rules always applied:

  • the person who made the change is never notified of their own change, and
  • duplicate and invalid addresses are removed.

Each recipient receives their own copy β€” the recipient list is never exposed to the others, and no stray copy is sent to the site administrator.

Note on bulk edits: because a notification is sent per document, changing the workflow state of many documents at once (for example, a bulk edit) sends one notification per document. Use the document_notification_recipients filter to suppress or reroute mail in that situation if needed.

Customizing with filters

Every part of the behavior is filterable. See Filters for full signatures. In brief:

  • document_notify_enabled, document_notify_on_state_change, document_notify_on_new_revision β€” force-enable or force-disable the master switch and each event.
  • document_notification_recipients β€” receives ( array $emails, int $doc_id, string $event, int $actor_id ). This is the seam for advanced routing: notify prior editors, or route by workflow state (e.g. send Under Review transitions to a review team).
  • document_notification_subject, document_notification_message β€” customize the email subject and body.
  • document_notification_headers β€” add email headers (e.g. a From: or Reply-To:).

Example: route “Under Review” to a review team

`php

add_filter(
‘document_notification_recipients’,
function ( $emails, $doc_id, $event, $actor_id ) {
if ( ‘state_change’ !== $event ) {
return $emails;
}
$states = wp_get_object_terms( $doc_id, ‘workflow_state’, array( ‘fields’ => ‘names’ ) );
if ( in_array( ‘Under Review’, $states, true ) ) {
$emails[] = ‘review-team@example.com’;
}
return $emails;
},
10,
4
);
<h3>Delivery</h3>
Notifications are sent through WordPress's standard
wp_mail()`. On sites with high mail volume or a slow mail server, install a transactional-email/SMTP plugin so delivery does not add latency to saving a document.

Translations

Help bring WP Document Revisions to your language. Translations are managed on translate.wordpress.org, and WordPress installs them automatically as language packs, so every translated string reaches every site using that language. No coding or GitHub account is needed. A free WordPress.org account is enough.

The most helpful thing you can do: review suggestions

Thirty languages already have a nearly complete set of suggested translations waiting for review. Some carry over from the plugin’s earlier translators, and most are machine translations that need a fluent speaker to check them. A language pack is published once a language reaches 90% approved translations, so reviewing is the fastest way to get the plugin working in your language.

  1. Sign in with your WordPress.org account.
  2. Open the plugin’s translation project and choose your language.
  3. Filter by Waiting to see the suggestions, then fix anything that reads wrong. You can also translate any untranslated strings.
  4. To approve suggestions yourself, request Project Translation Editor access for your language, or ask your language’s local Polyglots team to review them.

New to translating WordPress? The Polyglots handbook covers the basics, including each language’s style guide and glossary.

Found a bad translation?

Suggest a better one on translate.wordpress.org rather than opening a pull request. Translation files bundled with the plugin are overridden by WordPress.org language packs, so fixes belong there.

Thanks to everyone who has contributed translations, including:

Useful plugins and tools

Permissions management

Taxonomy management

Email notification and distribution

Document workflow management

Screenshots

Blocks

This plugin provides 4 blocks.

  • Document Preview Embed an inline preview of a document's latest revision.
  • Document Revisions Display a list of revisions for your document.
  • Latest Documents Display a list of your most recent documents.
  • Documents List Display a list of documents.

Installation

πŸš€ Automatic Install (Recommended)

  1. Log into WordPress Admin – Login to your WordPress site as an Administrator, or if you haven’t already, complete the WordPress installation
  2. Go to Plugins – Navigate to Plugins > Add New from the left menu
  3. Search – Search for “WP Document Revisions”
  4. Install – Click “Install Now” next to WP Document Revisions
  5. Activate – Click “Activate” to enable the plugin

πŸ“¦ Manual Install

  1. Download – Get the latest version from WordPress.org or GitHub Releases
  2. Upload – Unzip the file and upload the “wp-document-revisions” folder to your /wp-content/plugins/ directory
  3. Activate – Log into WordPress admin, go to Plugins, and activate “WP Document Revisions”

πŸ’» Developer Install

For development or contributing:

`bash

git clone https://github.com/wp-document-revisions/wp-document-revisions.git cd wp-document-revisions composer install –no-dev `

βš™οΈ Requirements

  • WordPress: 5.0 or higher
  • PHP: 7.4 or higher
  • File Permissions: WordPress must be able to write to the uploads directory

🎯 Next Steps

After installation, you’ll find a new Documents menu in your WordPress admin. Start by:

  1. Creating your first document – Go to Documents > Add New
  2. Setting up workflow states (optional) – Go to Documents > Workflow States
  3. Configuring permissions – Review Settings > Document Revisions

Need help? Check our FAQ or get support.

Reviews

January 30, 2026
Thank you for the recent update so that it's now compatible with latest versions of PHP. Great plugin, super useful, grateful it exists!
February 6, 2018 1 reply
Ben Balter has put together a solid plugin that does a good job of maintaining documents for your WP install. The plugin works well, and functions as described. The plugin also has filter and action hooks which allow developers to integrate with the plugin without hacking it. It is also translation ready, something that a plugin must have for wide adoption. A five star plugin must be not only usable but flexible. WP Document Revisions meets that qualification. I hope Ben continues his ongoing development. It's good to see WP coding standards being implemented. Would be good to see more inline documentation for hooks, but that doesn't affect functionality at all so it's more of a want than a need. This is a good plugin with some good features. Unfortunately, there are some very old reviews that don't paint an accurate picture. Anytime you read a review, look at its age and compare that to the plugin (or theme's) current development. In this case, there has been active development in the time since some of the older reviews were written (and in my opinion, some of those other reviews are simply not justified).
Read all 23 reviews

Contributors & Developers

“WP Document Revisions” is open source software. The following people have contributed to this plugin.

Contributors

“WP Document Revisions” has been translated into 5 locales. Thank you to the translators for their contributions.

Translate “WP Document Revisions” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

Numbers in brackets show the issue number in https://github.com/wp-document-revisions/wp-document-revisions/issues/

5.7.0

  • Security: on sites that enable block editor mode for documents (off by default), the Media Library grid listed the files of other users’ private, draft and password-protected documents to Authors and above, including their stored file names. In either mode, the media modal returned the same details for any attachment ID. Document files are now hidden from the grid in both modes, and the media modal hides the details of document files the user can’t edit (GHSA-2xcp-6j73-4cr7).
  • AI summaries are no longer generated or shown for private or password-protected documents, since generating one sends the document’s text to the site’s AI provider. New documents are private by default, so sites that want summaries for them must opt in with the new document_ai_summary_allow_private filter. Opting a document out of text extraction now also deletes its stored AI summaries. (#784)
  • Files for drafts, private and password-protected documents, and revisions are now served with Cache-Control: private, no-store, so shared caches and proxies don’t keep them. All served files also send X-Content-Type-Options: nosniff. (#781)
  • Document files are now stored under random names instead of names derived from the file name and upload time. (#780)
  • An upload is only handled as a document upload (hashed name, document directory, document file types) when it targets a document the user can edit. Other uploads are handled as normal media. (#782)
  • Users who can’t manage workflow states (Contributors, by default) can no longer create new ones when saving a document from the Workflow State box, quick edit or bulk edit. They can still pick an existing state. (#783)
  • Text extraction skips files over 20 MB, and Word or OpenDocument files that unzip to more than 100 MB, instead of processing them. The limits can be changed with the new wpdr_text_extraction_max_file_size and wpdr_text_extraction_max_uncompressed_size filters. The AI diff endpoint now applies the extraction time limit. (#786)
  • Regenerating a feed key from another user’s profile now changes that user’s key, not yours. (#785)
  • Old URLs of renamed documents no longer redirect visitors who can’t see the document. (#785)
  • Document REST requests that are refused no longer write document meta. (#785)
  • Uninstalling the plugin now also removes per-site feed keys and the notification settings. (#785)

5.6.1

  • Security: a user who could edit their own documents (Contributors and up, by default) could use the Validate Structure fix endpoint to rename and delete other media files on the site. Fixes now only touch the document’s own attachments (GHSA-wmqm-qwm3-9qgf).
  • Security: the documents shortcode, the Documents List and Latest Documents blocks, and the get_documents() template function could list other users’ draft, pending and private documents (titles, descriptions and authors) when asked for those statuses, and showed descriptions of password-protected documents. Lists now only include documents the viewer can read, and skip the description and thumbnail of password-protected documents. The post_password shortcode attribute has been removed (GHSA-xwv7-7xmq-wmxq).
  • Security: the document revisions shortcode and block listed the revision history of documents the viewer couldn’t read. They now check the document can be read (GHSA-cmhr-7795-vvfw).
  • Security: the AI summary and diff REST endpoints served password-protected documents, and summaries of earlier revisions to users without the read_document_revisions capability. They now check access the same way as downloading the file (GHSA-987w-vg4c-32r3).
  • Security: on sites that enable the REST API for documents (off by default), the plugin’s REST checks could be skipped by changing the case of the route (for example /wp/v2/Documents), and did not apply to the revisions list route (GHSA-fcf8-gjj8-pg9w).

5.6.0

For complete changelog, see GitHub