
Build Trigger for Gatsby Security & Risk Analysis
wordpress.org/plugins/build-trigger-gatsbyThis plugin will helps you to trigger a build of Gatsby at the time of post/page save or updates with different types.
Is Build Trigger for Gatsby Safe to Use in 2026?
Generally Safe
Score 100/100Build Trigger for Gatsby has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The build-trigger-gatsby plugin, version 1.0.4, presents a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no recorded vulnerability history, suggesting a history of secure development or prompt patching. The absence of taint analysis findings and file operations further contribute to a generally stable codebase.
However, significant concerns arise from the exposed attack surface. The plugin features two AJAX handlers, both of which lack any authentication or capability checks. This is a critical oversight, as it allows any user, including unauthenticated ones, to potentially interact with these handlers, leading to potential denial-of-service or unauthorized actions depending on their functionality. Furthermore, a worrying 67% of output escaping is not properly handled, creating a risk of cross-site scripting (XSS) vulnerabilities if the dynamic data processed by these handlers is not sufficiently sanitized before being rendered to the user.
In conclusion, while the plugin is free of known historical vulnerabilities and employs secure database practices, the unprotected AJAX endpoints and insufficient output escaping represent substantial security weaknesses that require immediate attention. The lack of nonce checks on these AJAX handlers exacerbates the risk.
Key Concerns
- AJAX handlers without auth checks
- Significant unescaped output
- AJAX handlers without nonce checks
Build Trigger for Gatsby Security Vulnerabilities
Build Trigger for Gatsby Code Analysis
Output Escaping
Build Trigger for Gatsby Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
Build Trigger for Gatsby Maintenance & Trust
Maintenance Signals
Community Trust
Build Trigger for Gatsby Alternatives
Publish to Netlify
publish-to-netlify
Easily deploy static sites to Netlify using WordPress as backend. This plugin builds your static website using Netlify webhooks to trigger the deploy …
Deploy Webhook Button
webhook-netlify-deploy
Easily deploy static sites using Wordpress and Netlify
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Build Trigger for Gatsby Developer Profile
2 plugins · 90 total installs
How We Detect Build Trigger for Gatsby
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/build-trigger-gatsby/assets/js/admin.js/wp-content/plugins/build-trigger-gatsby/assets/js/admin.jsbuild-trigger-for-gatsby/assets/js/admin.js?ver=HTML / DOM Fingerprints
name="ztbtfg_settings[ztbtfg_webhook_url]"name="ztbtfg_settings[ztbtfg_trigger_type]"value="Manual"value="Automatic"ztbtfg_frontend_ajax_object