The run

Four stages, and you control two of them.

Nothing is written during the first two stages, so a refusal costs you nothing. The two stages that can change your site are the two you switch on yourself.

1Validate

The uploaded file and the ZIP structure are checked. Nothing has been extracted at this point and nothing has been written.

2Inspect

The plugin header is parsed and the declared platform requirements are tested against this install. A refusal here costs nothing to undo.

3Install

The validated archive is handed to WordPress's native upgrader. Replacement of an existing folder happens only if you ticked it.

4Record

A structured report is saved, and successful installs are activated only if you asked for that too. Both switches default to off.

Who it's for

Anyone who has uploaded the same ZIP twenty times.

The agency standard stack

Every new client site gets the same fifteen plugins. One batch, one report, and the report doubles as the record of what the site started with.

The staging rebuild

Staging has drifted and you are rebuilding it to match live. Replacement is a deliberate tick rather than a default, so the rebuild cannot quietly overwrite something you wanted to keep.

The site handover

The new owner wants to know exactly what is installed and where it came from. Download the CSV and the question is answered in one attachment.

?The inherited site

You have a folder of ZIPs from a previous developer and no idea which are valid. Run them through: the twelve refusals tell you which archives are broken before any of them touch the site.

Get the plugin See what it refuses