Download the PHP package survos/wordpress-bundle without Composer

On this page you can find all versions of the php package survos/wordpress-bundle. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package wordpress-bundle

survos/wordpress-bundle

Symfony bundle client for the WordPress REST API (/wp-json/wp/v2) — posts, pages, media, taxonomies, users, and custom post types — built on Symfony's own HttpClient.

Multi-site by design: one app routinely talks to more than one WordPress install, so sites are named in configuration and each gets its own client.

Why this exists

Two Survos apps integrated with WordPress in two unrelated ways (survos-sites/ff#5):

This bundle replaces both. It has no PSR-7 dependency of any kind, so nothing it brings in can pin psr/http-message.

Installation

Configuration

Every key is optional. With no sites at all, one site named default is registered from WORDPRESS_BASE_URL / WORDPRESS_USERNAME / WORDPRESS_APPLICATION_PASSWORD.

key default
default_site first configured site which site WordpressClientInterface resolves to
rest_prefix /wp-json REST root under the site URL
user_agent Survos WordpressBundle/1.0 … managed hosts block generic agents — identify the app
timeout 30 seconds
retry_enabled / max_retries true / 3 see Fetch strategy
cache_enabled / cache_max_ttl false / 3600 see Fetch strategy

Credentials are Application Passwords

application_password is a WordPress Application Password (Users → Profile → Application Passwords, core since WP 5.6), not the account password. The generated value contains spaces; paste it as-is. It is sent as HTTP Basic auth, so the site must be HTTPS.

Credentials are only needed for writes. Reading public posts, pages and media works with no credentials at all, and in that case no Authorization header is sent.

Usage

Choosing a site at runtime (a --site option, a per-tenant lookup) goes through the registry:

Endpoints

posts(), pages(), media(), categories(), tags(), comments(), users(), types(), statuses(), taxonomies() — plus resource() for anything else:

Every endpoint offers:

get(int $id, array $query = []) one record, as WordPress returned it
list(array $query = []) one page of records
page(array $query = []) same, plus total / totalPages from the X-WP-* headers
iterate(array $query = []) the whole collection, lazily, one page at a time
create() / update() / save() / delete() writes; save() creates or updates on the presence of an id
getDto() / listDto() / iterateDto() the same reads, hydrated into DTOs

Raw arrays are the contract; DTOs (WpPost, WpTerm, WpMedia, WpUser) are a convenience and each keeps its source array on ->raw. WordPress records carry arbitrary plugin/ACF keys that no DTO can enumerate, so unknown fields are never dropped and never cause a hydration failure. Text fields arrive as {"rendered": "…"} in the default context and as plain strings in others; the DTOs flatten both.

Uploading media

WordPress creates an attachment from the raw file bytes plus a Content-Disposition filename — not multipart, not JSON — and metadata cannot ride along in that request. upload() handles both halves:

Fetch strategy (retry / cache / rate limits)

Retry is on by default: transport errors and HTTP 500/502/503/504 are retried with exponential backoff (Symfony's RetryableHttpClient).

429 is deliberately excluded from that list. It surfaces as RateLimitException carrying the server's own Retry-After, so a caller — a Messenger consumer, a batch import — can reschedule itself with the real delay. Retrying it inside the HTTP client would swallow that signal. This is a live concern rather than a theoretical one: managed WordPress hosts (WP Engine among them) rate-limit /wp-json/ aggressively.

Caching (cache_enabled) wraps the client in Symfony's RFC 9111 CachingHttpClient via survos/fetch-bundle's shared factory. It is off by default, and that default is deliberate: WordPress core sends Cache-Control: no-cache on REST responses, so an RFC-9111 cache is a no-op against a stock install. Turn it on only for a site fronted by a CDN or a caching plugin that emits real freshness headers.

Errors

Everything thrown implements WordpressExceptionInterface. WordPress error bodies are structured — {"code":"rest_post_invalid_id","message":"…","data":{"status":404}} — and both the machine code and the human message are parsed onto the exception rather than collapsed into "Unexpected response":

AuthenticationException 401 / 403
NotFoundException 404 — the record, or the route
RateLimitException 429, with ->retryAfter
InvalidJsonException 2xx that wasn't JSON — a WAF challenge page, or a plugin echoing output
WordpressApiException everything else, and the base of all of the above

Console commands

wordpress:ping fetches the REST index and, when credentials are configured, verifies them against wp/v2/users/me — the fastest way to tell a wrong Application Password from a host that strips the Authorization header before it reaches PHP (the two are indistinguishable from the response alone).

Migrating from vnn/wordpress-rest-api-client

The surface was kept close on purpose, including save()'s create-or-update-on-id behaviour:

vnn this bundle
new WpClient(new GuzzleAdapter(new Client()), $url) + setCredentials(new WpBasicAuth(…)) configure the site; inject WordpressClientInterface
$client->posts()->get(66) $client->posts()->get(66)
$client->posts()->get() $client->posts()->list() — or iterate(), which actually pages
$client->posts()->save(['id' => 66, …]) $client->posts()->save(['id' => 66, …])
$client->media()->upload($path, $data) $client->media()->upload($path, $data)
$client->categories()->get(null, ['per_page' => 100]) $client->categories()->list(['per_page' => 100])
RuntimeException('Unexpected response') a typed exception carrying the WordPress error code

The one behavioural difference worth knowing: vnn's get() with no id returned a single page and silently stopped at WordPress' default of 10 records. list() does the same thing explicitly; iterate() is what you want when you meant "all of them".

Not included


All versions of wordpress-bundle with dependencies

PHP Build Version
Package Version
Requires php Version ^8.5
survos/fetch-bundle Version ^2.5
survos/kit-bundle Version ^2.5
symfony/config Version ^8.1
symfony/console Version ^8.1
symfony/dependency-injection Version ^8.1
symfony/http-client Version ^8.1
symfony/http-kernel Version ^8.1
symfony/mime Version ^8.1
symfony/string Version ^8.1
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package survos/wordpress-bundle contains the following files

Loading the files please wait ...