Content Revalidation Tracker Security & Risk Analysis
wordpress.org/plugins/content-revalidation-trackerAuto-triggers frontend revalidation on post, page, user, or taxonomy updates. Ideal for Next.js and headless WordPress setups.
Is Content Revalidation Tracker Safe to Use in 2026?
Generally Safe
Score 100/100Content Revalidation Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'content-revalidation-tracker' plugin version 2.0.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface points, such as unprotected AJAX handlers, REST API routes, shortcodes, or cron events, is a significant strength. Furthermore, the code signals indicate a good adherence to secure coding practices, with no dangerous functions, all SQL queries utilizing prepared statements, and a very high percentage of output properly escaped. The presence of nonce and capability checks, although limited, is also a positive indicator. The plugin's vulnerability history is clean, with zero known CVEs, which suggests either a lack of historical vulnerabilities or a consistent effort in maintaining security.
However, there are minor areas for attention. The plugin makes two external HTTP requests, which, while not inherently insecure, represent potential attack vectors if not handled with proper validation and sanitization on the receiving end, especially if the data is user-controlled. Taint analysis shows only two flows analyzed, which is a very small sample size. While no critical or high severity issues were found in these flows, a more comprehensive taint analysis would provide greater assurance. The absence of any identified vulnerabilities in the past is excellent, but it's important to remain vigilant as new vulnerabilities can emerge. Overall, this plugin appears to be well-secured, with its primary potential weaknesses lying in the handling of external HTTP requests and the limited scope of the taint analysis.
Key Concerns
- External HTTP requests made by the plugin
- Limited scope of taint analysis flows
Content Revalidation Tracker Security Vulnerabilities
Content Revalidation Tracker Release Timeline
Content Revalidation Tracker Code Analysis
Output Escaping
Data Flow Analysis
Content Revalidation Tracker Attack Surface
WordPress Hooks 13
Maintenance & Trust
Content Revalidation Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Content Revalidation Tracker Alternatives
WPGraphQL for ACF
wpgraphql-acf
WPGraphQL for ACF seamlessly integrates Advanced Custom Fields with WPGraphQL.
Metronyx Headless CMS Connector
metronyx-headless-cms-connector
Transform your WordPress site into a powerful headless CMS for modern frontend frameworks like Next.js, React, Vue, and more.
WPGraphQL
wp-graphql
WPGraphQL adds a flexible and powerful GraphQL API to WordPress, enabling efficient querying and interaction with your site's data.
Headless Mode
headless-mode
Once you take the head off of WordPress, nobody needs to see it. This plugin hides the front end by redirecting to the shiny static (etc) site.
BabyLoveGrowth Integration
babylovegrowth-integration
Secure REST endpoint to publish posts from BabyLoveGrowth.ai backend via API key.
Content Revalidation Tracker Developer Profile
4 plugins · 120 total installs
How We Detect Content Revalidation Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/content-revalidation-tracker/public/css/crt-public.css/wp-content/plugins/content-revalidation-tracker/public/js/crt-public.js/wp-content/plugins/content-revalidation-tracker/public/js/crt-public.jscontent-revalidation-tracker/public/css/crt-public.css?ver=content-revalidation-tracker/public/js/crt-public.js?ver=