The FAIR Package Manager gives WordPress sites a way to pull plugins and themes from decentralized mirrors — with cryptographic verification and less data flowing to Automattic's servers.
Here is a scene we have had more than once in the past year: a compliance officer at a health system or a university IT director asks, mid-discovery call, whether our WordPress builds “phone home” on plugin updates. The honest answer has always been yes — WordPress.org’s repository is the source, Automattic controls it, and every update check sends metadata back to their infrastructure. Most shops accept that tradeoff without a second thought. Our institutional clients often cannot.
That calculus now has a concrete alternative worth tracking. On August 2, 2026, the FAIR Package Manager project — incubated under the Linux Foundation — pushed the most recent commit to its core WordPress plugin, fair-plugin, inside a GitHub organization that now spans 23 repositories. FAIR lets site owners and hosts pull plugins and themes from decentralized, self-hostable mirror nodes rather than solely from WordPress.org. It adds cryptographic supply-chain verification to each package and reduces the telemetry that flows to Automattic-controlled servers. Companion tools under active development include the fair-explorer browser and the aspirecloud aggregator, which together form the plumbing for a working federated ecosystem.
The project is honest about where it stands: functional, not yet a drop-in replacement for the .org repository for most shops. Adoption is early. The mirror network is thin. Shops that need every plugin in the known WordPress universe available on day one will be disappointed. That is not the point right now.
FAIR addresses something the mainstream WordPress conversation mostly sidesteps: every plugin update from WordPress.org is a phone-home to vendor-controlled infrastructure, and for regulated clients, that is a procurement question, not just a philosophy question.
The timing is not incidental. The Automattic/WP Engine litigation made WordPress.org’s reliability a legitimate board-level question for organizations with WordPress in their stack. FAIR did not emerge because of that fight, but it lands squarely in the window it opened. A Linux Foundation project building a federated, cryptographically verified alternative to a single vendor’s package repository is a structurally different answer than either “trust Automattic” or “self-host everything from scratch.”
For our practice, the clients who should be watching FAIR now are the ones already asking the compliance question — health systems with BAAs in place, PBS affiliates with donor data on-site, universities under state data-residency requirements. For general WordPress shops, this is a project to revisit in twelve months, when the mirror network has more depth and the integration story is more complete.
We will keep an eye on the fair-explorer and aspirecloud work as they mature. For now, FAIR is the right answer in early form — which is earlier than most of our institutional clients need it, and exactly early enough to start the conversation before they ask us why we didn’t.
