Skip to content

False positives for VCS plugin and theme installs #537

Description

@chriscroome

Bug Report

Describe the current, buggy behavior

The code that detects VCS plugin installs is buggy, often on sites that don't have any plugins installed using git checkout the flag --include-vcs is required to update plugins.

For example wp-piwik includes a empty .gitignore file and I think this might trigger the need for --include-vcs?

Describe what you would expect as the correct outcome

Better detection of git checked out plugins.

Let us know what environment you are running this on

wp cli info
OS:	Linux 6.12.100+deb13-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.100-1 (2026-07-30) x86_64
Shell:	/bin/bash
PHP binary:	/usr/bin/php8.3
PHP version:	8.3.33
PHP memory limit:	-1
php.ini used:	/etc/php/8.3/cli/php.ini
MySQL binary:	/usr/bin/mariadb
MySQL version:	mariadb from 11.8.6-MariaDB, client 15.2 for debian-linux-gnu (x86_64) using  EditLine wrapper
SQL modes:	STRICT_TRANS_TABLES,ERROR_FOR_DIVISION_BY_ZERO,NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION
WP-CLI root dir:	phar://wp-cli.phar/vendor/wp-cli/wp-cli
WP-CLI vendor dir:	phar://wp-cli.phar/vendor
WP_CLI phar path:	phar:///usr/local/bin/wp
WP-CLI packages dir:	/home/weblog/.wp-cli/packages/
WP-CLI cache dir:	/home/weblog/.wp-cli/cache
WP-CLI global config:	/home/weblog/.wp-cli/config.yml
WP-CLI project config:	
WP-CLI version:	2.13.0-alpha-5315443

Activity

  1. swissspidy commented on Aug 3, 2026

    @swissspidy
    Member

    Thanks for your report!

    We use the is_vcs_checkout() function provided by WordPress for this detection, as defined here:

    https://github.com/WordPress/wordpress-develop/blob/5bc2c6228c78ca17552a906c2bb4e47a97e87bf8/src/wp-admin/includes/class-wp-automatic-updater.php#L127-L179

    It checks for .git folders, not .gitignore files. There is a automatic_updates_is_vcs_checkout filter in there though, so maybe a plugin of yours or your hosting provider uses that to exclude more plugins more strictly. I'd recommend looking into that. Trying --skip-plugins might help too.

    And if there's a flaw in is_vcs_checkout(), it can be reported at https://core.trac.wordpress.org/

  2. chriscroome commented on Aug 3, 2026

    @chriscroome
    Author

    Thanks @swissspidy that is really helpful, next time I hit this issue I'll report it upstream.

  3. swissspidy commented on Aug 3, 2026

    @swissspidy
    Member

    Sounds good, I'm closing this for now then

  4. chriscroome commented on Aug 5, 2026

    @chriscroome
    Author

    Here is an example of this issue:

    wp plugin update --all
    Warning: woocommerce: Skipped update because a VCS checkout was detected. Use --include-vcs to override.
    Warning: wordpress-seo: Skipped update because a VCS checkout was detected. Use --include-vcs to override.
    Error: No plugins updated.

    Neither plugin has a top-level .git directory:

    ls -lah wp-content/plugins/woocommerce/
    total 124K
    drwxr-xr-x 12 wordpress wordpress 4.0K Jul 20 23:03 .
    drwxr-xr-x 15 wordpress wordpress 4.0K Aug  5 12:19 ..
    drwxr-xr-x  7 wordpress wordpress 4.0K Jul 20 23:03 assets
    drwxr-xr-x  3 wordpress wordpress 4.0K Jul 20 23:03 i18n
    drwxr-xr-x 30 wordpress wordpress  12K Jul 20 23:03 includes
    drwxr-xr-x  4 wordpress wordpress 4.0K Jul 20 23:03 lib
    -rw-r--r--  1 wordpress wordpress  36K Jul 20 23:03 license.txt
    drwxr-xr-x  6 wordpress wordpress 4.0K Jul 20 23:03 packages
    drwxr-xr-x  2 wordpress wordpress 4.0K Jul 20 23:03 patterns
    -rw-r--r--  1 wordpress wordpress  20K Jul 20 23:03 readme.txt
    drwxr-xr-x  2 wordpress wordpress 4.0K Jul 20 23:03 sample-data
    drwxr-xr-x 17 wordpress wordpress 4.0K Jul 20 23:03 src
    drwxr-xr-x 17 wordpress wordpress 4.0K Jul 20 23:03 templates
    -rw-r--r--  1 wordpress wordpress 6.2K Jul 20 23:03 uninstall.php
    drwxr-xr-x  9 wordpress wordpress 4.0K Jul 20 23:03 vendor
    -rw-r--r--  1 wordpress wordpress 1.9K Jul 20 23:03 woocommerce.php
    
    ls -lah wp-content/plugins/wordpress-seo
    total 144K
    drwxr-xr-x 13 wordpress wordpress 4.0K Jul 24 15:37 .
    drwxr-xr-x 15 wordpress wordpress 4.0K Aug  5 12:19 ..
    drwxr-xr-x 22 wordpress wordpress 4.0K Jul 24 15:37 admin
    drwxr-xr-x  4 wordpress wordpress 4.0K Jul 24 15:37 blocks
    -rw-r--r--  1 wordpress wordpress 1010 Jul 24 15:37 changelog.md
    drwxr-xr-x  3 wordpress wordpress 4.0K Jul 24 15:37 css
    drwxr-xr-x  4 wordpress wordpress 4.0K Jul 24 15:37 images
    drwxr-xr-x  5 wordpress wordpress 4.0K Jul 24 15:37 inc
    -rw-r--r--  1 wordpress wordpress   38 Jul 24 15:37 index.php
    drwxr-xr-x  3 wordpress wordpress 4.0K Jul 24 15:37 js
    drwxr-xr-x  4 wordpress wordpress 4.0K Jul 24 15:37 lib
    -rw-r--r--  1 wordpress wordpress  33K Jul 24 15:37 license.txt
    drwxr-xr-x  3 wordpress wordpress 4.0K Jul 24 15:37 packages
    -rw-r--r--  1 wordpress wordpress  18K Jul 24 15:37 readme.txt
    drwxr-xr-x 55 wordpress wordpress 4.0K Jul 24 15:37 src
    drwxr-xr-x  3 wordpress wordpress 4.0K Jul 24 15:37 vendor
    drwxr-xr-x  6 wordpress wordpress 4.0K Jul 24 15:37 vendor_prefixed
    -rw-r--r--  1 wordpress wordpress 2.1K Jul 24 15:37 wpml-config.xml
    -rw-r--r--  1 wordpress wordpress  18K Jul 24 15:37 wp-seo-main.php
    -rw-r--r--  1 wordpress wordpress 1.7K Jul 24 15:37 wp-seo.php

    Why does WP-CLI think these plugins were installed using git?

  5. swissspidy commented on Aug 5, 2026

    @swissspidy
    Member

    Because WP_Automatic_Updater::is_vcs_checkout() from WordPress core said so. It's not WP-CLI. Again, that function has a filter, so it's possible that something is hooking into this filter to make the check more strict.

    Try using --skip-plugins as I suggested above.

    If it's coming from a mu-plugin (for example one added by your hosting provider), you could also try something like this (untested):

    test.php file:

    <?php
    
    WP_CLI::add_wp_hook(
        'automatic_updates_is_vcs_checkout',
        '__return_false',
        PHP_INT_MAX
    );

    Then run wp --require=test.php plugin update --all

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions