Compare

Six solutions for WordPress plugin distribution, each with a different philosophy. See how Troy compares.

Six Tools, One Goal

There are several ways to distribute WordPress plugins outside WordPress.org. Each tool takes a different approach. Some embed a library into every plugin; others replace the entire ecosystem.

Troy takes a middle path: one client plugin, one server plugin, full control. Your plugins update from your infrastructure, and the same plugin file can stay listed on WordPress.org.

Use the comparison table below to see exactly where each solution stands.

Troy

Private distribution

Can stay listed on WP.orgLow complexityv1.7.1184 (9 months)

Freemius

Hosted monetization platform

Free version only on WP.orgMedium complexityv2.13.4 (~11 years)

EDD + SL

Easy Digital Downloads + Software Licensing

eCommerce + licensing + updates

Can stay listed on WP.orgMedium complexityv3.9.7 (~14 years)

PUC

Plugin Update Checker

Per-plugin update library

Cannot be listed on WP.orgMedium complexityv5.7 (~16 years)

FAIR

Federated And Independent Repositories

WP.org replacement client

Can stay listed on WP.orgHigh complexityv1.4.1 (~3 years)

Git Updater

Git-hosted updates

Can stay listed on WP.orgLow complexityv14.4.2.2 (~13 years)
Rotate your phone for easier comparison reading.
Feature
Distribution
Who owns the server?
Plugin distribution
Theme distribution
Private plugins
One installer ZIP, many plugins
Cost model
Per-plugin integration effort
License
WordPress.org
Can stay listed on WP.org
Your updates from a WP.org listing
Plugin data hidden from WP.org
Hide a plugin from all update checks
Security
Who sees your update requests?
Updater security patch rollout
Forced auto-updates (no site-owner opt-in)
Encrypted communication (HTTPS)
Package checksum verification
Sanitizes banners/icons from a rogue server
Blocks WP.org until Client is up
Privacy
Sends the site URL
Fingerprinting
Sends all installed plugins
Anonymous statistics
Anonymous ZIP requests
Updates
Dependency management
Server-side compatibility checks
Multiple versions hosted
Pre-release channels
Update check batching
What gets installed on users' sites
Scales with more plugins
Composer support (for Bedrock sites)
Hosting
Estimated server capacity
Server required
Self-hosting complexity
Automatic failover if server is down
Server sync (multi-host)
Rate limiting risk
Authentication on users' sites
Publisher admin
Setup speed
Import from GitHub or WP.org
Slug and ZIP management
Beta/tag control in admin
Gutenberg readme builder
Logo and header image management
Translation management
Logging UI
Per-plugin statistics
Global statistics
WP-CLI support
On user sites
Readme display in WordPress
Changelog display in WordPress
Plugin banner and icon in WordPress
Protection from locking-out
Public plugin browser
Translation updates
Usage analytics
Troy
You
⚠ Planned (2026)
Under 10 KB, fetches latest version at install
Free (self-hosted)
Add 1 line to your plugin file
MIT
Same files can stay listed
WP.org never sees your plugin
Opt-in header to disable all communications
Only your own server
Standalone. One update covers all plugins
Blocked on Server and Client. Site owner must opt in
Forced. HTTP is rejected
Packages and Composer now; Client planned (2027)
Blocks hostile SVGs and animated images
Optional MU-plugin (site managers)
No. Rotating IDs, limited statistics
Only your server's plugins
Rotating weekly ID to communicate
Rotating weekly ID to communicate
Via Packages and a plugin header
Serves the latest version your site can run
Site owner picks a channel (stable or beta) via one line in wp-config.php
All plugins in one request
One shared plugin (Troy Client)
Same single client, any number of servers
Native Composer 2 repository (Bedrock-ready)
50k–500k Client sites
Any WordPress site
Low
Controlled by your host
⚠ Planned. Origin headers are ready
Your server, no limits
None required (public by design)
About 30 seconds to set up a plugin
Gutenberg: slugs, versions, ZIP upload
Tag, Beta, or Unreleased per version
Edit sections in the block editor
Logo and banner on the plugin post
⚠ Planned (2026)
Full UI with auto-refresh
⚠ Planned (2026)
Secure and non-animated
Hides Deactivate while dependents exist
⚠ Planned (2027)
⚠ Planned (2026)
Anonymous: PHP, WP, and language breakdown
Freemius
Freemius
⚠ ~7% of sale revenue
⚠ Bundle the SDK into each plugin
Proprietary
⚠ Free/premium split required
⚠ Your plugin info is sent to WP.org
⚠ Freemius servers (collects site + user data)
⚠ Bundled. Every developer must release an update
Site-owner toggle only
⚠ Falls back to HTTP if SSL fails
⚠ All plugins and themes
Statistics yes, anonymous no
⚠ Checks, but won't offer an older compatible version
⚠ Per-site opt-in checkbox (requires Freemius account)
One request per plugin
~147 library files added to each plugin
⚠ Another SDK copy per plugin
Unlimited (hosted)
None (Freemius hosts it)
None, hosted
Built-in (hosted)
No limits (hosted)
License key per plugin
Hosted product setup
Manual setup per plugin
Hosted build uploads
Hosted beta program
Hosted icons
Hosted dashboard
⚠ Via WP.org (free version)
⚠ Via WP.org (free version)
⚠ Via WP.org (free version)
⚠ Locked-in. The updater dies if you deactivate the plugin
Detailed (opt-in, tracks individual sites)
EDD + SLEasy Digital Downloads + Software Licensing
You
⚠ $599–999/yr (Professional+ pass)
Embed an update script into each plugin
GPLv2+
Free build can stay listed
⚠ Your plugin info is sent to WP.org
⚠ Your store server
⚠ Bundled. Every developer must release an update
Site-owner toggle only
Depends on your store URL
⚠ Checks on site only; no older version offered if incompatible
⚠ Per-product opt-in checkbox in admin tools
One request per plugin
~620-line update script added to each plugin
⚠ Another update script per plugin
Depends on your server
WordPress + EDD + SL
Medium (WordPress + 2 plugins to manage)
Controlled by your host
Your server, no limits
License key required (no key = no updates)
Product + download config
Manual upload + product config
Product download files
Beta file per license
Per-product sales
⚠ Store-wide sales
From readme.txt
⚠ Locked-in. The updater dies if you deactivate the plugin
Sales data only (no site-level insight)
PUCPlugin Update Checker
No server — a library in each plugin
Requires your own server or private Git repos
Free
⚠ Bundle the library into each plugin
MIT
⚠ PUC-powered build cannot be listed
⚠ Hidden only while the plugin is active
⚠ Your server or Git host, depending on setup
⚠ Bundled. Every developer must release an update
⚠ Developer can force it on every site (v5.7+)
⚠ HTTP metadata URLs allowed
⚠ Beta versions skipped unless the developer enables them in code
One request per plugin
~40 library files added to each plugin
⚠ Another library copy per plugin
Your server or Git host
⚠ Optional
Low (JSON file) or none (Git)
Controlled by your host or Git host
⚠ Git mode at ~60 req/hr without auth token; JSON has no host limit
None for JSON; tokens in Git mode
Library + JSON or Git
Manual JSON or Git setup
In code
Trigger only, no commands
From readme.txt in repo
From readme.txt or JSON metadata
From JSON metadata or local assets
⚠ Locked-in. The updater dies if you deactivate the plugin
Built-in
FAIRFederated And Independent Repositories
The provider
Mirrors the WP.org directory
Free
N/A
MIT / GPLv2
Bypasses WP.org entirely
AspireCloud (default provider)
Standalone. One update covers all plugins
⚠ Inherits WordPress.org forced security updates
HTTPS in practice, not enforced
Single redirect
One shared plugin (FAIR Connect)
One plugin, one mirror
N/A
AspireCloud, or Beacon + FAIR DID
High (AspireCloud). Beacon hosts files; DID/PLC stays with FAIR
Controlled by your host
Your server, no limits
None required
Mirror or Beacon ingest
Mirror + DID/source install
Logs stored in database, no UI
From WP.org
From WP.org
From WP.org
Fair Explorer
Git Updater
The Git host
⚠ Only via private Git repos
Free for public repos; $19.95/yr for private/auth
Add Git host lines to your plugin file
GPL-3.0
⚠ Your plugin info is sent to WP.org
⚠ GitHub/GitLab/etc. sees every request
Standalone. One update covers all plugins
Site-owner toggle only
⚠ HTTPS required for zip installs only
⚠ Only via Git version tags
One request per plugin per host
One shared plugin (Git Updater)
One plugin, any Git host
Limited by Git host rate limits
None
Handled by Git host
⚠ GitHub: ~60 req/hr without auth token
⚠ Git tokens for private repos + rate limits
Headers in the plugin file
N/A (is the source)
Git tags only
From readme.txt
From readme.txt
From .wordpress-org file or assets/ folder
No lock. The client can be turned off anytime

How Troy Compares

Five head-to-head breakdowns. Each one covers what the other tool is genuinely good at, what its architecture costs you, and what Troy does instead.

Troy vs. Freemius

Freemius is a monetization platform first and an update service second. It handles licensing, payments, and delivery as one hosted bundle, which is genuinely the fastest way to start selling a plugin.

That convenience is rented. It costs roughly 7% of every sale, and every plugin you ship has to carry a ~147-file SDK. Your users' site URLs, WordPress versions, and full plugin and theme lists travel to Freemius servers, not yours, on every update check.

Troy is self-hosted and MIT-licensed, and collects nothing that can fingerprint a site.

The split is clean. If you need payments handled for you, Freemius is the only turnkey option on this page. If you already sell your own work, Troy gives you the update half without the revenue cut or the data collection.

What Troy collects
Every release you ship
~147 SDK files, every single time
Every update check
Site URLWordPress versionPlugin and theme list
Freemius servers
not yours

The payload never gets smaller. It has been this consistent for years.

Troy vs. EDD + Software Licensing

Easy Digital Downloads is a full eCommerce platform that happens to deliver updates. If you want a storefront, a cart, and licensing in one place, that bundling is the point.

Updates are not sold separately, though. Software Licensing only arrives with the Professional+ pass at $599–999/yr on renewal, so the update service carries the cost of the whole store.

EDD also ships telemetry of its own. A weekly check-in sends sales and refund totals, customer count, and every active plugin to Awesome Motive. The settings toggle is labelled Yes, I want to help!

Troy delivers updates and stops there. No storefront, no telemetry, and no site URLs leaving your infrastructure.

Adding plugins to Troy Server
Your store
EDD + Software Licensing
What “help” sends each week
Weekly revenueCustomer countAll active plugins
Awesome Motive

Troy vs. Plugin Update Checker

Plugin Update Checker is free, MIT, and has roughly 16 years of production use behind it. For a single plugin it is hard to beat.

The cost arrives with the second plugin. PUC is a library, so its ~40 PHP files ship inside every plugin that uses it. Ten plugins means ten copies in memory, ten HTTP requests per update cycle, and ten separate patches the day a vulnerability lands.

It also ties the updater to its host. Deactivate the plugin and updates stop, because the update service lives inside it. That is lock-in wearing different clothes. Troy Client hides Deactivate while dependents exist, so the updater cannot be dropped by accident.

Listing is the other divide. A PUC-powered build cannot stay on WordPress.org, because it replaces .org's updater for that plugin. Troy's header is inert metadata, so the same file can stay listed.

Since v5.7 a plugin author can also switch on forced background updates for every site running their plugin (allowAutoupdateField()). That is the developer opting in on the site owner's behalf. Troy blocks the autoupdate flag on both Server and Client, so site owners update when they choose.

How Troy Client works
your build~0 files
some-forms-plugin/
└─vendor/plugin-update-checker/+40
some-seo-plugin/
└─vendor/plugin-update-checker/+40
some-backup-plugin/
└─vendor/plugin-update-checker/+40
some-caching-plugin/
└─vendor/plugin-update-checker/+40
some-security-plugin/
└─vendor/plugin-update-checker/+40
…and 5 more, each carrying its own copy
~0
files loaded
0
update requests
0
patches per CVE

Troy vs. FAIR

FAIR is the most ambitious project on this page. It aims to replace the WordPress.org supply chain outright rather than sit beside it.

FAIR Connect is the site client, and it swaps out .org update checks, translations, and Add Plugins for a FAIR provider, AspireCloud by default. The update check still sends WordPress's full installed-plugin list to whichever provider you point it at.

Self-hosting the whole mirror means running AspireCloud, which is Laravel, PostgreSQL, and Redis. Fair Beacon will host a few package files on WordPress instead, but the DID and PLC directory stay inside FAIR's control plane. Fair Explorer, their public plugin and theme browser, is a genuine lead: Troy's equivalent is planned for 2027.

Troy makes the smaller bet. It doesn't replace WordPress.org, it runs alongside it. You key a plugin to your server, and the directory keeps working exactly as it did.

WordPress.org integration
FAIR Connect
WordPress.org
AspireCloud
Laravel, PostgreSQL, Redis

Update checks move. The full plugin list goes with them.

Troy
WordPress.org
still listed
Your server
keyed per plugin

Both paths stay open. The same plugin file works either way.

Troy vs. Git Updater

Git Updater pulls updates straight from GitHub, GitLab, Bitbucket, or Gitea. There is no server to run, which for a handful of public repositories is a real advantage.

Your Git host becomes the update infrastructure, and it inherits the problems of that job. It sees every update request from every site you ship to. Unauthenticated GitHub requests cap at 60 per hour. Private or authenticated repositories need a $19.95/yr license plus API tokens deployed on each site.

Troy imports from GitHub too, but serves from your own server. No rate limits, no tokens on user sites, and no third party watching the traffic.

GitHub integration
GitHub
GitLab
Bitbucket
Gitea
Sees every request
Every site you ship to
Unauthenticated GitHub cap0 / 60 per hr
Private or authenticated repos need a $19.95/yr license, plus API tokens on each site.

Quick Decision Matrix

Not sure which tool fits your use case? This matrix maps common goals to the best-fit solution.

Your Goal
Best Choice
Runner-up
Own the update server
Troy
EDD (you host the store)
Distribute private/commercial plugins
Troy
PUC (1–2 plugins, no server)
Keep a WordPress.org listing
Troy
Git Updater (public repos only)
Keep plugins off WordPress.org radar
Troy
PUC (also filters proactively)
Hide a plugin from all update checks
Troy (opt-in header)
—
No forced auto-updates without site-owner opt-in
Troy (blocked on Server and Client)
—
HTTPS only (no HTTP fallback)
Troy
—
Anonymous update and ZIP traffic (no site URLs)
Troy
—
No site fingerprinting from the update payload
Troy
Git Updater
Block .org until the updater client is up
Troy (Client Daemon)
—
Zero platform fees
Troy
PUC (also free, MIT)
Full data ownership (no 3rd-party hosting)
Troy
EDD (self-hosted, but phones home)
Lowest barrier to entry
Troy
PUC (no server, but ~40 files per plugin)
10+ plugins at scale
Troy
Git Updater
Set up a plugin in about 30 seconds
Troy
—
Install a suite from one small ZIP
Troy (Packages, under 10 KB)
—
Multiple PHP/WP version support
Troy
—
Network effect (one client, many repos)
Troy
—
Built-in analytics dashboard
Troy
Freemius (hosted, opt-in tracking)
Composer/Bedrock workflow
Troy (native Composer 2 repository)
PUC (manual composer.json config)
Public plugin browser
FAIR (Fair Explorer)
Troy (planned 2027)
Full admin UI for plugin management
Troy (Gutenberg: slugs, ZIPs, readme, assets)
EDD (full eCommerce UI)
Translation packs from your server
FAIR / Git Updater / PUC
Troy (planned 2026)
No dependency on external services
Troy
EDD (self-hosted)
Built-in licensing and payments
Freemius
EDD + SL
No client plugin on users' sites
PUC (but bundles ~40 files per plugin)
Freemius (bundles ~147 files per plugin)
No separate client install (at the cost of ~40 files per plugin)
PUC
EDD (update script per plugin)
No server maintenance, Git workflow
Git Updater
PUC (Git mode)

Why Is Troy Winning in Almost Every Category?

Because we learned from the others. We spent many days tearing apart every tool on this page, Troy included, cataloguing every feature gap, every silent data leak, every architectural shortcut. We know where Troy falls short too, and we're fixing it.