Authentication
Send an API key as a bearer token. The key must carry the sites.view permission; a key without it is refused with 403, not 404.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/sites/{siteId}/wordpress \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
What WordPress is on the package, what version, whether an update is waiting, and — in one read — which of the eleven WordPress operations the package type permits. One read gates eleven buttons, so a customer never learns their plan's shape by pressing one and reading a refusal. `is_latest` is **tri-state**: null means the vendor did not say, which is not "out of date". `update_available` is the flag a screen should act on, because it is derived from the vendor's update object being non-empty rather than from a comparison between two version strings nobody parsed — ⛔ `{}` is how this platform says *"no update"*, and it is falsy, so the presence of the key is not the signal. Reading what is installed is **not** gated on a capability: a screen has to be able to render *"your plan does not include plugin management"* beside the list of what is installed. `404` for a site with no vendor hosting package. Requires `sites.view`.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
siteId (path) | Uuid | Yes | Site ID (UUIDv7). |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
installed | boolean | Yes | Whether WordPress is on the package at all. |
version | string | Yes | The installed version, or `""` when the vendor did not state one. |
is_latest | boolean | Yes | ⛔ **Tri-state.** Null means the vendor did not say, which is **not** "out of date": rendering an unknown as out of date invites a customer to run a core update on a live site fo… |
is_multisite | boolean | Yes | Whether the install is a WordPress network. |
update_available | boolean | Yes | The flag a screen should act on. Derived from the vendor's update object being non-empty rather than from a comparison between two version strings nobody parsed — ⛔ `{}` is how… |
update_version | string | Yes | The version waiting, or `""` when the install is current. |
site_url | string | Yes | The URL WordPress believes it is served from. |
wizard_required | boolean | Yes | Whether the install has never been through WordPress's own setup wizard — a half-installed site, not a broken one. |
unavailable_reason | string<, database, config, unreadable, not-routed> | Yes | ⛔ **Read this before rendering `installed`.** Empty means `installed` is authoritative. Non-empty means it is **not**: the probe failed and we could not determine the answer, so… |
capabilities | object | Yes | Which of the eleven WordPress operations this package type permits, keyed by our **stable machine identifiers** — never a vendor string and never display text, so they are usabl… |
Errors this endpoint can return
401 · 403 · 404 · 429 · 503