klyp / wordpress
WordPress core for Composer, built and published by Klyp. Require a tagged version (e.g. ^7.1); the master branch only holds the build tooling.
Requires
- php: >=7.4
- klyp/wordpress-core-installer: ^1.0
Requires (Dev)
None
Suggests
None
Provides
Conflicts
None
Replaces
None
- dev-master
- 7.1.3
- 7.1.2
- 7.1.1
- 7.1
- 7.0.7
- 7.0.6
- 7.0.5
- 7.0.4
- 7.0.3
- 7.0.2
- 7.0.1
- 7.0
- 6.9.10
- 6.9.9
- 6.9.8
- 6.9.7
- 6.9.6
- 6.9.5
- 6.9.4
- 6.9.3
- 6.9.2
- 6.9.1
- 6.9
- 6.8.11
- 6.8.10
- 6.8.9
- 6.8.8
- 6.8.7
- 6.8.6
- 6.8.5
- 6.8.4
- 6.8.3
- 6.8.2
- 6.8.1
- 6.8
- 6.7.10
- 6.7.9
- 6.7.8
- 6.7.7
- 6.7.6
- 6.7.5
- 6.7.4
- 6.7.3
- 6.7.2
- 6.7.1
- 6.7
- 6.6.10
- 6.6.9
- 6.6.8
- 6.6.7
- 6.6.6
- 6.6.5
- 6.6.4
- 6.6.3
- 6.6.2
- 6.6.1
- 6.6
- 6.5.13
- 6.5.12
- 6.5.11
- 6.5.10
- 6.5.9
- 6.5.8
- 6.5.7
- 6.5.6
- 6.5.5
- 6.5.4
- 6.5.3
- 6.5.2
- 6.5
- 6.4.13
- 6.4.12
- 6.4.11
- 6.4.10
- 6.4.9
- 6.4.8
- 6.4.7
- 6.4.6
- 6.4.5
- 6.4.4
- 6.4.3
- 6.4.2
- 6.4.1
- 6.4
- 6.3.13
- 6.3.12
- 6.3.11
- 6.3.10
- 6.3.9
- 6.3.8
- 6.3.7
- 6.3.6
- 6.3.5
- 6.3.4
- 6.3.3
- 6.3.2
- 6.3.1
- 6.3
- 6.2.14
- 6.2.13
- 6.2.12
- 6.2.11
- 6.2.10
- 6.2.9
- 6.2.8
- 6.2.7
- 6.2.6
- 6.2.5
- 6.2.4
- 6.2.3
- 6.2.2
- 6.2.1
- 6.2
- 6.1.15
- 6.1.14
- 6.1.13
- 6.1.12
- 6.1.11
- 6.1.10
- 6.1.9
- 6.1.8
- 6.1.7
- 6.1.6
- 6.1.5
- 6.1.4
- 6.1.3
- 6.1.2
- 6.1.1
- 6.1
- 6.0.17
- 6.0.16
- 6.0.15
- 6.0.14
- 6.0.13
- 6.0.12
- 6.0.11
- 6.0.10
- 6.0.9
- 6.0.8
- 6.0.7
- 6.0.6
- 6.0.5
- 6.0.4
- 6.0.3
- 6.0.2
- 6.0.1
- 6.0
- 5.9.19
- 5.9.18
- 5.9.17
- 5.9.16
- 5.9.15
- 5.9.14
- 5.9.13
- 5.9.12
- 5.9.11
- 5.9.10
- 5.9.9
- 5.9.8
- 5.9.7
- 5.9.6
- 5.9.5
- 5.9.4
- 5.9.3
- 5.9.2
- 5.9.1
- 5.9
- 5.8.18
- 5.8.17
- 5.8.16
- 5.8.15
- 5.8.14
- 5.8.13
- 5.8.12
- 5.8.11
- 5.8.10
- 5.8.9
- 5.8.8
- 5.8.7
- 5.8.6
- 5.8.5
- 5.8.4
- 5.8.3
- 5.8.2
- 5.8.1
- 5.8
- 5.7.20
- 5.7.19
- 5.7.18
- 5.7.17
- 5.7.16
- 5.7.15
- 5.7.14
- 5.7.13
- 5.7.12
- 5.7.11
- 5.7.10
- 5.7.9
- 5.7.8
- 5.7.7
- 5.7.6
- 5.7.5
- 5.7.4
- 5.7.3
- 5.7.2
- 5.7.1
- 5.7
- 5.6.22
- 5.6.21
- 5.6.20
- 5.6.19
- 5.6.18
- 5.6.17
- 5.6.16
- 5.6.15
- 5.6.14
- 5.6.13
- 5.6.12
- 5.6.11
- 5.6.10
- 5.6.9
- 5.6.8
- 5.6.7
- 5.6.6
- 5.6.5
- 5.6.4
- 5.6.3
- 5.6.2
- 5.6.1
- 5.6
- 5.5.23
- 5.5.22
- 5.5.21
- 5.5.20
- 5.5.19
- 5.5.18
- 5.5.17
- 5.5.16
- 5.5.15
- 5.5.14
- 5.5.13
- 5.5.12
- 5.5.11
- 5.5.10
- 5.5.9
- 5.5.8
- 5.5.7
- 5.5.6
- 5.5.5
- 5.5.4
- 5.5.3
- 5.5.2
- 5.5.1
- 5.5
- 5.4.24
- 5.4.23
- 5.4.22
- 5.4.21
- 5.4.20
- 5.4.19
- 5.4.18
- 5.4.17
- 5.4.16
- 5.4.15
- 5.4.14
- 5.4.13
- 5.4.12
- 5.4.11
- 5.4.10
- 5.4.9
- 5.4.8
- 5.4.7
- 5.4.6
- 5.4.5
- 5.4.4
- 5.4.3
- 5.4.2
- 5.4.1
- 5.4
- 5.3.26
- 5.3.25
- 5.3.24
- 5.3.23
- 5.3.22
- 5.3.21
- 5.3.20
- 5.3.19
- 5.3.18
- 5.3.17
- 5.3.16
- 5.3.15
- 5.3.14
- 5.3.13
- 5.3.12
- 5.3.11
- 5.3.10
- 5.3.9
- 5.3.8
- 5.3.7
- 5.3.6
- 5.3.5
- 5.3.4
- 5.3.3
- 5.3.2
- 5.3.1
- 5.3
- 5.2.29
- 5.2.28
- 5.2.27
- 5.2.26
- 5.2.25
- 5.2.24
- 5.2.23
- 5.2.22
- 5.2.21
- 5.2.20
- 5.2.19
- 5.2.18
- 5.2.17
- 5.2.16
- 5.2.15
- 5.2.14
- 5.2.13
- 5.2.12
- 5.2.11
- 5.2.10
- 5.2.9
- 5.2.8
- 5.2.7
- 5.2.6
- 5.2.5
- 5.2.4
- 5.2.3
- 5.2.2
- 5.2.1
- 5.2
- 5.1.27
- 5.1.26
- 5.1.25
- 5.1.24
- 5.1.23
- 5.1.22
- 5.1.21
- 5.1.20
- 5.1.19
- 5.1.18
- 5.1.17
- 5.1.16
- 5.1.15
- 5.1.14
- 5.1.13
- 5.1.12
- 5.1.11
- 5.1.10
- 5.1.9
- 5.1.8
- 5.1.7
- 5.1.6
- 5.1.5
- 5.1.4
- 5.1.3
- 5.1.2
- 5.1.1
- 5.1
- 5.0.30
- 5.0.29
- 5.0.28
- 5.0.27
- 5.0.26
- 5.0.25
- 5.0.24
- 5.0.23
- 5.0.22
- 5.0.21
- 5.0.20
- 5.0.19
- 5.0.18
- 5.0.17
- 5.0.16
- 5.0.15
- 5.0.14
- 5.0.13
- 5.0.12
- 5.0.11
- 5.0.10
- 5.0.9
- 5.0.8
- 5.0.7
- 5.0.6
- 5.0.4
- 5.0.3
- 5.0.2
- 5.0.1
- 5.0
- 4.9.34
- 4.9.33
- 4.9.32
- 4.9.31
- 4.9.30
- 4.9.29
- 4.9.28
- 4.9.27
- 4.9.26
- 4.9.25
- 4.9.24
- 4.9.23
- 4.9.22
- 4.9.21
- 4.9.20
- 4.9.19
- 4.9.18
- 4.9.17
- 4.9.16
- 4.9.15
- 4.9.14
- 4.9.13
- 4.9.12
- 4.9.11
- 4.9.10
- 4.9.9
- 4.9.8
- 4.9.7
- 4.9.6
- 4.9.5
- 4.9.4
- 4.9.3
- 4.9.2
- 4.9.1
- 4.9
- 4.8.33
- 4.8.32
- 4.8.31
- 4.8.30
- 4.8.29
- 4.8.28
- 4.8.27
- 4.8.26
- 4.8.25
- 4.8.24
- 4.8.23
- 4.8.22
- 4.8.21
- 4.8.20
- 4.8.19
- 4.8.18
- 4.8.17
- 4.8.16
- 4.8.15
- 4.8.14
- 4.8.13
- 4.8.12
- 4.8.11
- 4.8.10
- 4.8.9
- 4.8.8
- 4.8.7
- 4.8.6
- 4.8.5
- 4.8.4
- 4.8.3
- 4.8.2
- 4.8.1
- 4.8
- 4.7.38
- 4.7.37
- 4.7.36
- 4.7.35
- 4.7.34
- 4.7.33
- 4.7.32
- 4.7.31
- 4.7.30
- 4.7.29
- 4.7.28
- 4.7.27
- 4.7.26
- 4.7.25
- 4.7.24
- 4.7.23
- 4.7.22
- 4.7.21
- 4.7.20
- 4.7.19
- 4.7.18
- 4.7.17
- 4.7.16
- 4.7.15
- 4.7.14
- 4.7.13
- 4.7.12
- 4.7.11
- 4.7.10
- 4.7.9
- 4.7.8
- 4.7.7
- 4.7.6
- 4.7.5
- 4.7.4
- 4.7.3
- 4.7.2
- 4.7.1
- 4.7
- dev-develop
- dev-release-develop
- dev-feature-2026-10-09-wordpress-packagist
- dev-release-master
This package is auto-updated.
Last update: 2026-10-09 05:02:09 UTC
README
WordPress core for Composer, built and published by Klyp.
A scheduled GitHub Action checks wordpress.org every 15 minutes. When there's a new release on any branch, it publishes that release here as a Composer version, including security backports such as 6.9.9 while 7.1.x is current. It doesn't wait for a third party to repackage the release.
Every stable release from 4.7 onward is available.
Using it in a project
{
"require": {
"klyp/wordpress": "^7.1"
},
"config": {
"allow-plugins": {
"klyp/wordpress-core-installer": true
}
},
"extra": {
"wordpress-install-dir": "wp"
}
}
klyp/wordpress has the package type wordpress-core and depends on klyp/wordpress-core-installer. That Composer plugin installs core into extra.wordpress-install-dir (default wordpress/) instead of vendor/.
Switching from another WordPress core package
- In
composer.json:- Replace your current WordPress core package in
requirewith"klyp/wordpress": "^6.9", using the same version constraint. - Remove the old core installer plugin from
config.allow-plugins, and add"klyp/wordpress-core-installer": true. - Leave
extra.wordpress-install-dirunchanged.
- Replace your current WordPress core package in
- Update the new packages together with the ones you're replacing:
composer update klyp/wordpress klyp/wordpress-core-installer <old-core-package> <old-installer-package> -W
- Check that
composer.locklistsklyp/wordpressandklyp/wordpress-core-installer, and no other package of typewordpress-coreor WordPress core installer. Only one installer plugin should handle WordPress core.
Apply the same change to project skeletons such as 3equals/hummingbird-project, so new sites start on klyp/wordpress.
How it works
mastercontains only the tooling in this README,bin/and.github/. Itscomposer.jsonis a file-lessmetapackagethat only gives Packagist the package name. Packagist lists it asdev-master, but it installs nothing, and normal constraints such as^7.1never select it.- Each WordPress version is a tag (
7.1.2,6.9.9,4.7.31, ...). Each tag points to an orphan commit that holds:- the unmodified contents of the official
https://wordpress.org/wordpress-X.Y.Z.zip, checked against its published.sha1 - a generated
composer.json. Itsphprequirement comes from that release's$required_php_version.
- the unmodified contents of the official
- Tags are never rewritten. If a tag already exists on the remote, the build skips it.
| File | Purpose |
|---|---|
| bin/build-release.sh | Builds and pushes one version: download, verify sha1, add composer.json, tag, push. |
| bin/sync-releases.sh | Compares the WordPress release list with the remote tags, builds what's missing and pushes it. Packagist picks up new tags through its GitHub integration. |
| .github/workflows/sync.yml | Runs the sync every 15 minutes, or on demand. Also commits a monthly keepalive, because GitHub disables schedules after 60 idle days. |
| .github/workflows/test.yml | Installs the newest release, and the newest release of the previous branch, from Packagist into a scratch project. |
Publishing a release immediately
The schedule usually picks up a new release within 15 minutes. To publish one right away:
- GitHub: Actions → Sync WordPress releases → Run workflow. Enter a version such as
7.1.3, or leave it empty to build everything that's missing. - Locally, with push access:
bin/build-release.sh 7.1.3
Other local options:
DRY_RUN=1 bin/sync-releases.sh # list versions that aren't published yet NO_PUSH=1 bin/build-release.sh 6.9.9 # build and tag locally without pushing
The scripts require bash, curl, jq, unzip and git.
One-time setup
- The repository must be public, so that Packagist can read it.
- Under Settings → Actions → General → Workflow permissions, choose Read and write permissions. The workflow needs this to push tags and the keepalive commit. If
masterhas branch protection, allow GitHub Actions to push, or the keepalive fails. - On packagist.org, submit
https://github.com/klyp/wordpressfrom the Klyp account. Connect the GitHub integration (Profile → Settings → GitHub) so Packagist is notified on every tag push. No Packagist token is stored in this repo. - Protect the tags. Under Settings → Rules → Rulesets → New tag ruleset, target all tags (
*) and enable Restrict updates and Restrict deletions, with no bypass list. The sync never rewrites a tag, and this ruleset stops anyone else (or a leaked token) from replacing a published version with different code. Keep Restrict creations off, or the workflow can't publish new tags. - After merging to
master, run Sync WordPress releases once to backfill every version from 4.7 up. That's about 480 tags, and the run is safe to repeat if it times out.
License
WordPress is licensed under the GPLv2 or later. The build tooling in this repository uses the same license.