Deploy Trigger for GitHub Security & Risk Analysis

wordpress.org/plugins/deploy-trigger-for-github

Trigger GitHub Actions workflows from WordPress when content changes. Perfect for headless WordPress setups.

10 active installs v1.4 PHP + WP 5.0+ Updated Sep 15, 2025
actionsdeploygithubheadlessworkflow
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Deploy Trigger for GitHub Safe to Use in 2026?

Generally Safe

Score 100/100

Deploy Trigger for GitHub has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "deploy-trigger-for-github" plugin v1.4 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs and the plugin's commitment to secure coding practices like using prepared statements for SQL queries and incorporating nonce checks are significant strengths. Furthermore, the limited attack surface and the high percentage of properly escaped output suggest that the developers have prioritized security in their implementation. However, a single external HTTP request, while not explicitly flagged as a vulnerability, warrants caution as it represents a potential point of interaction with external systems that could be exploited if not handled with robust validation and sanitization on the receiving end. The lack of any identified taint flows is a positive indicator, suggesting that data handling within the plugin is likely secure. Overall, this plugin appears to be well-secured, with only a minor area for potential scrutiny regarding its external HTTP request.

Key Concerns

  • External HTTP request present
Vulnerabilities
None known

Deploy Trigger for GitHub Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Deploy Trigger for GitHub Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Deploy Trigger for GitHub Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
10 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

83% escaped12 total outputs
Attack Surface

Deploy Trigger for GitHub Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_initdeploy-trigger-for-github.php:42
actionadmin_menudeploy-trigger-for-github.php:59
actiondepltrfo_errordeploy-trigger-for-github.php:122
actiondepltrfo_successdeploy-trigger-for-github.php:129
actioninitdeploy-trigger-for-github.php:137
actionsave_postdeploy-trigger-for-github.php:189
actionbefore_delete_postdeploy-trigger-for-github.php:209
Maintenance & Trust

Deploy Trigger for GitHub Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.6
Last updatedSep 15, 2025
PHP min version
Downloads565

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Deploy Trigger for GitHub Developer Profile

Facundo

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Deploy Trigger for GitHub

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
name="depltrfo_token"name="depltrfo_repo"name="depltrfo_workflow"name="depltrfo_ref"name="depltrfo_reset"name="depltrfo_reset_nonce"
FAQ

Frequently Asked Questions about Deploy Trigger for GitHub