Amirhossein Hosseinpouramirhp
CV
Active PHP tool · Open source

upload-url-to-server

Upload one file. Move everything else. Delete it.

A single PHP file you drop onto a server when the usual tools are missing. The server pulls a file straight from a URL, or you push from your computer, browse FTP and SFTP, or sync two servers. When you are done, it deletes itself.

Latest release Source on GitHub

MIT licence, published under BlackSwan, my own label. The most starred repository I have written. Figures from the GitHub API, 30 September 2026.

On GitHub2020 to today

What it does

Sometimes you need a file on a server and there is no SSH, wget is disabled, or the server cannot reach the source. You have a browser, a URL, and maybe FTP details.

Server-side pull

Paste a URL and the server downloads it straight to disk, with size, elapsed time and an estimate. It can unpack zip and tar archives, and install WordPress in one step.

Relay around a block

If your server cannot reach the source, a second server running the same file fetches it, and your server downloads it from there.

FTP, FTPS and SFTP

Browse, upload, rename, move and delete on a remote server, and view or edit text files, from the browser. Credentials are sent per request and never stored on the server.

Compare and sync

Diff two trees by path relative to each root, local or remote, and copy only what is missing or different, with Stop and Retry per file.

A command line too

The same file runs from PHP CLI: php upload.php --url=… --name=…, including relay and sync.

Self-destruct

One click removes the file. It has no login by design, so it is meant to be uploaded, used and deleted.

Why one file

Because the servers it is for are the ones where installing anything else is the problem.

Locked-down shared hosting, cPanel and DirectAdmin boxes, managed WordPress: places where you can upload a file and open it in a browser, and not much else. So there is no Composer, no build step and no framework. The front end and a small JSON API are served from the same upload.php. The optional code editor loads only when you open it.

It started in November 2020 as a page that pulled one URL onto a server. Progress came in version 2, the self-destruct switch in 2024, WordPress install mode in January 2025, and FTP, relay and sync in 2026. It still honours the original rule: whatever it grows into has to fit in one file.

A floor I got wrong

Version 3.8.1 lowered the PHP requirement from 7.4 back to 7.0. The only newer construct left was ??, and the 7.4 check had been blocking hosts that ran the script fine. For PHP 5.6 there is a separate minimal build that only pulls from a URL.

The scanner problem

A file that writes files and updates itself looks like a web shell to a malware scanner. Three releases in 2026 were spent proving otherwise without weakening it.

3.6.0 stopped rewriting itself in place after DirectAdmin's ClamAV flagged it. 3.6.3 cleared an Imunify360 detection, php.dropper.file: the editor had moved file contents as base64, and base64 decoded into a file write is exactly what a dropper does. It now uses percent-encoding in both directions, and no base64 data is left in the file.

3.8.0 brought in-place updates back, done carefully: the release is looked up and downloaded over strict TLS from a URL built on the server and pinned to GitHub, checked to be valid PHP, then swapped in atomically. If any step fails, the running file is untouched.

// 3.6.3: the editor's transport, before and after
// before: looks like a dropper to a behavioural scanner
file_put_contents($path, base64_decode($body));

// after: the same bytes, percent-encoded both ways
file_put_contents($path, rawurldecode($body));

// 3.8.0: an update must parse before it replaces anything
token_get_all($new, TOKEN_PARSE); // throws on invalid PHP
rename($tmp, __FILE__);         // atomic swap
Simplified from the changelog of 3.6.3 and 3.8.0.

Getting started

PHP 7.0 or later with cURL. ZipArchive for zip files; SFTP needs cURL with SFTP or the ssh2 extension.

  1. Download

    Get upload.php from the latest release.

  2. Upload it

    Put it in the folder you want to work in, with FTP or the hosting file manager.

  3. Open it

    Visit https://yoursite.com/upload.php and choose a mode from the sidebar.

  4. Delete it

    Press Self-Destruct. If it has to stay for a while, protect it with server-level Basic Auth or give it an unguessable name.

# or from the command line
php upload.php --url=https://wordpress.org/latest.zip --name=wp.zip --wpinstall

Releases

32 tagged releases since November 2020, 22 of them in 2026. Each has notes on GitHub.

VersionReleasedWhat changed
3.8.210 Aug 2026Bulk save from the FTP explorer to this server.
3.8.110 Aug 2026PHP floor lowered to 7.0; nested paths fixed in the legacy build.
3.8.020 Jul 2026Folder create, delete and rename everywhere; verified in-place update; PHP 5.6 legacy build.
3.6.316 Jul 2026Imunify360 false positive cleared.
3.4.02 Jun 2026Upload into the open folder, from PC, URL or relay.
3.0.01 Jun 2026FTP uploads, sync queue with Stop and Retry, saved connections.
2.0.030 Apr 2026Relay mode.
148 Jan 2025WordPress install mode, archive extraction.
1318 Aug 2024Self-destruct.
2.016 May 2021Real-time progress.
1.0.014 Nov 2020First version.

A selection of 11 of the 32. The numbering restarted at 1.9.2 in April 2026, the day after version 18; every release is on GitHub.

branch main 6 active projects ↑ 113 releases open-source/upload-url-to-server.md Sari --:-- UTC+3:30 its@amirhp.com