WP Filesystem SCP
Addition of the SCP protocol for the Wordpress FileSystem API
by Niels Vermeiren · github.com/nielsvermeiren12/wp_fs_scp_addon
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/nielsvermeiren12/wp_fs_scp_addon/archive/refs/heads/main.zipWP Filesystem SCP Addon
This plugin is a custom extension of the FileSystem API
:outbox_tray: It adds support for file transfers over the SCP protocol
[!IMPORTANT] This project exists as a POC and should be carefully reviewed before production usage
Install
cd wp-content/plugins/wp-filesystem-scp
composer install --no-dev
Activate the plugin in WordPress.
wp-config.php example
define('FS_METHOD', 'scp');
define('FTP_HOST', 'example.com:22');
define('FTP_USER', 'deploy');t
define('FTP_PASS', 'your-password');
define('WPFS_SCP_BASE_DIR', '/var/www/html');
For private key auth:
define('WPFS_SCP_PRIVATE_KEY', '/home/www/.ssh/id_ed25519');
define('WPFS_SCP_PRIVATE_KEY_PASSWORD', 'optional-passphrase');
Why SCP Instead of FTP?
Compared to FTP:
- ✔️ SCP is encrypted
- ✔️ supports SSH key authentication
- ✔️ does not require additional services
- ✔️ integrates naturally with Linux infrastructure
Compared to SFTP:
- ✔️ SCP is simpler and optimized for direct transfers
- ✔️ good for deployment-style workflows
- ✔️ ideal for bulk uploads and artifact delivery
Potential
Managed hosts[!TIP] Consider the following use cases where SCP will shine!
Many managed hosts disable:
FS_METHOD=direct- FTP access
- writable webroot permissions
But still allow SSH access.
✔️ This plugin enables secure file operations without requiring unsafe permissions like:
chmod -R 777 wp-content
Multi-Site or Multi-Server DeploymentsUseful for distributing:
- ✔️ plugins
- ✔️ themes
- ✔️ MU plugins
- ✔️ configuration files
- ✔️ generated assets
From a central WordPress dashboard to multiple remote installations.
Example:
Master WordPress Site
↓
Deploy Plugin/Theme
↓
Multiple Remote WordPress Sites
CI/CD and Deployment PipelinesCan be integrated into:
- ✔️ GitHub Actions
- ✔️ GitLab CI
- ✔️ Jenkins
- ✔️ custom deployment systems
Typical workflow:
Build Assets
↓
Upload via SCP
↓
Remote Installation / Activation
Enterprise / Internal InfrastructureUseful for:
- ✔️ government systems
- ✔️ banking infrastructure
- ✔️ private intranets
- ✔️ air-gapped environments
Where only SSH traffic is permitted.
Limitations
[!CAUTION] The WordPress Filesystem API expects full filesystem behavior:
exists()
mkdir()
chmod()
delete()
dirlist()
- :white_check_mark: SCP itself is mainly a transfer protocol.
- :expressionless: Some advanced operations may still require SSH shell commands or additional abstractions.
Long-Term Vision
This project can evolve into a more complete WordPress deployment layer featuring:
- :white_check_mark: SCP-based deployments
- :white_check_mark: SSH command execution
- :white_check_mark: WP-CLI orchestration
- :white_check_mark: rollback support
- :white_check_mark: remote backups
- :white_check_mark: atomic deployments
- :white_check_mark:multi-server synchronization
A modern DevOps-oriented deployment solution for WordPress.
Warning
[!CAUTION] SCP itself mainly uploads/downloads files. Methods such as
dirlist(),chmod(),mkdir()anddelete()are implemented with SSH shell commands over the same connection.
This is an MVP and should be tested carefully before use on production sites