UpdateProof is a free local tool for safer site maintenance.
Start with one simple workflow: check your site, test important pages, review the update evidence, and approve changes only when you are ready. Learn about the broader UpdateProof roadmap at
https://updateproof.zerofrik.com/.
The Free/Base release helps developers and maintenance agencies establish an evidence-based update workflow before an update:
- Records WordPress and PHP versions.
- Records active plugins and the active theme without collecting their source code.
- Detects available WordPress, plugin, and theme updates using WordPress native update APIs.
- Runs a small, transparent set of deterministic checks and gives a low, review-recommended, or high-risk signal.
- Lets administrators configure up to four critical same-site URLs for manual preflight checks.
- Records HTTP status, response time, and a privacy-safe HTML fingerprint before and after a deployment attempt.
- Creates a selectable plugin/theme deployment plan with an explicit approval step.
- Applies selected plugin and theme updates through WordPress native upgrader APIs.
- Records post-deployment checks and a local deployment history.
- Optionally connects to an administrator-owned browser worker for real Chromium screenshots of up to three public pages.
- Captures a baseline and reports pixel-level visual differences after an update, with screenshots stored in the site's uploads directory.
- Exposes site metadata, the latest snapshot, and update inventory through a read-only REST API.
- Lets an administrator generate and revoke a per-site API token.
The Free/Base plugin does not create a staging site, run synthetic form or WooCommerce tests, schedule updates, automatically roll back a failed update, or provide multi-site/team management. Those are planned Pro/service capabilities.
- Upload the zerofrik-maintenance-safety-agent folder to /wp-content/plugins/, or install the plugin ZIP from Plugins > Add New > Upload Plugin.
- Activate the plugin.
- Open UpdateProof in the WordPress admin.
- Run a safety check.
- Generate a site token only if you are connecting the site to an external service.
- Optional: configure an administrator-owned browser worker under Visual regression, save a baseline, and run a visual check.
The visual-regression screen can generate a one-time worker token. Copy it to the worker server as
UPDATEPROOF_WORKER_TOKEN, restart the worker, and leave the saved token unchanged in WordPress. To rotate it later, use Generate and replace token, update the worker environment variable, restart the worker, and test again.