upload-url-to-server
Upload one file. Move everything else. Delete it.
A single PHP file you drop onto a server when the usual tools are missing. The server pulls a file straight from a URL, or you push from your computer, browse FTP and SFTP, or sync two servers. When you are done, it deletes itself.
MIT licence, published under BlackSwan, my own label. The most starred repository I have written. Figures from the GitHub API, 30 September 2026.
What it does
Sometimes you need a file on a server and there is no SSH, wget is disabled, or the server cannot reach the source. You have a browser, a URL, and maybe FTP details.
Server-side pull
Paste a URL and the server downloads it straight to disk, with size, elapsed time and an estimate. It can unpack zip and tar archives, and install WordPress in one step.
Relay around a block
If your server cannot reach the source, a second server running the same file fetches it, and your server downloads it from there.
FTP, FTPS and SFTP
Browse, upload, rename, move and delete on a remote server, and view or edit text files, from the browser. Credentials are sent per request and never stored on the server.
Compare and sync
Diff two trees by path relative to each root, local or remote, and copy only what is missing or different, with Stop and Retry per file.
A command line too
The same file runs from PHP CLI: php upload.php --url=… --name=…, including relay and sync.
Self-destruct
One click removes the file. It has no login by design, so it is meant to be uploaded, used and deleted.
Why one file
Because the servers it is for are the ones where installing anything else is the problem.
Locked-down shared hosting, cPanel and DirectAdmin boxes, managed WordPress: places where you can upload a file and open it in a browser, and not much else. So there is no Composer, no build step and no framework. The front end and a small JSON API are served from the same upload.php. The optional code editor loads only when you open it.
It started in November 2020 as a page that pulled one URL onto a server. Progress came in version 2, the self-destruct switch in 2024, WordPress install mode in January 2025, and FTP, relay and sync in 2026. It still honours the original rule: whatever it grows into has to fit in one file.
Version 3.8.1 lowered the PHP requirement from 7.4 back to 7.0. The only newer construct left was ??, and the 7.4 check had been blocking hosts that ran the script fine. For PHP 5.6 there is a separate minimal build that only pulls from a URL.
The scanner problem
A file that writes files and updates itself looks like a web shell to a malware scanner. Three releases in 2026 were spent proving otherwise without weakening it.
3.6.0 stopped rewriting itself in place after DirectAdmin's ClamAV flagged it. 3.6.3 cleared an Imunify360 detection, php.dropper.file: the editor had moved file contents as base64, and base64 decoded into a file write is exactly what a dropper does. It now uses percent-encoding in both directions, and no base64 data is left in the file.
3.8.0 brought in-place updates back, done carefully: the release is looked up and downloaded over strict TLS from a URL built on the server and pinned to GitHub, checked to be valid PHP, then swapped in atomically. If any step fails, the running file is untouched.
// 3.6.3: the editor's transport, before and after // before: looks like a dropper to a behavioural scanner file_put_contents($path, base64_decode($body)); // after: the same bytes, percent-encoded both ways file_put_contents($path, rawurldecode($body)); // 3.8.0: an update must parse before it replaces anything token_get_all($new, TOKEN_PARSE); // throws on invalid PHP rename($tmp, __FILE__); // atomic swap
Getting started
PHP 7.0 or later with cURL. ZipArchive for zip files; SFTP needs cURL with SFTP or the ssh2 extension.
Download
Get
upload.phpfrom the latest release.Upload it
Put it in the folder you want to work in, with FTP or the hosting file manager.
Open it
Visit
https://yoursite.com/upload.phpand choose a mode from the sidebar.Delete it
Press Self-Destruct. If it has to stay for a while, protect it with server-level Basic Auth or give it an unguessable name.
# or from the command line
php upload.php --url=https://wordpress.org/latest.zip --name=wp.zip --wpinstall
Releases
32 tagged releases since November 2020, 22 of them in 2026. Each has notes on GitHub.
| Version | Released | What changed |
|---|---|---|
| 3.8.2 | 10 Aug 2026 | Bulk save from the FTP explorer to this server. |
| 3.8.1 | 10 Aug 2026 | PHP floor lowered to 7.0; nested paths fixed in the legacy build. |
| 3.8.0 | 20 Jul 2026 | Folder create, delete and rename everywhere; verified in-place update; PHP 5.6 legacy build. |
| 3.6.3 | 16 Jul 2026 | Imunify360 false positive cleared. |
| 3.4.0 | 2 Jun 2026 | Upload into the open folder, from PC, URL or relay. |
| 3.0.0 | 1 Jun 2026 | FTP uploads, sync queue with Stop and Retry, saved connections. |
| 2.0.0 | 30 Apr 2026 | Relay mode. |
| 14 | 8 Jan 2025 | WordPress install mode, archive extraction. |
| 13 | 18 Aug 2024 | Self-destruct. |
| 2.0 | 16 May 2021 | Real-time progress. |
| 1.0.0 | 14 Nov 2020 | First version. |
A selection of 11 of the 32. The numbering restarted at 1.9.2 in April 2026, the day after version 18; every release is on GitHub.
// open-source/
More open source
The other projects with a page of their own. The rest, 56 in all, are in the explorer, each with its status and where the numbers come from.
- Receipt Uploader for WooCommerce1,000+ installs, rated 5.0 from 14
- upload-url-to-serverOne PHP file, 32 releases since 2020
- Justify It and Lorem SazAdobe XD plugins, 11,015 downloads, archived
- CF7 DatabaseContact Form 7 submissions, kept and exported
- Gravity Forms OTP VerificationA one-time code before the entry is saved
- Block External RequestWordPress's outbound calls, under control
- Slipnet for macOSA Mac client for a DNS-tunnelling VPN
- BDM, BlackSwan Download ManagerSegmented downloads on the Mac, with browser extensions
- Firefox add-onsFive published, 4.6 average rating