
Deployer for Git Security & Risk Analysis
wordpress.org/plugins/deployer-for-gitInstall and update plugins (and themes) hosted on your repo hosted on GitHub, Bitbucket, GitLab, or Gitea in a single click.
Is Deployer for Git Safe to Use in 2026?
Generally Safe
Score 100/100Deployer for Git has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "deployer-for-git" plugin v1.0.10 demonstrates some good security practices, notably its complete reliance on prepared statements for SQL queries and the absence of recorded vulnerabilities in its history. This suggests a development team that is aware of common database attack vectors and has a history of producing relatively secure code. However, the static analysis reveals significant concerns. The plugin exposes a REST API route without any permission callbacks, creating a critical entry point that could be exploited by unauthenticated users. Furthermore, a substantial percentage of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without adequate sanitization.
While there are no known CVEs or critical taint flows, the unprotected REST API endpoint and the high percentage of unescaped output represent immediate and serious security risks. The lack of a robust attack surface in terms of AJAX handlers, shortcodes, and cron events is a positive, but it does not mitigate the danger posed by the vulnerable REST API. The presence of a bundled Freemius library also warrants attention, as outdated bundled libraries can introduce vulnerabilities, though its specific version is not detailed here. The overall security posture is concerning due to the identified critical entry points, despite the absence of historical vulnerabilities and secure SQL practices.
Key Concerns
- REST API route without permission callback
- Significant portion of output not properly escaped
- Bundled outdated library (Freemius v1.0)
Deployer for Git Security Vulnerabilities
Deployer for Git Code Analysis
Bundled Libraries
Output Escaping
Deployer for Git Attack Surface
REST API Routes 1
WordPress Hooks 8
Maintenance & Trust
Deployer for Git Maintenance & Trust
Maintenance Signals
Community Trust
Deployer for Git Alternatives
Download Manager
download-manager
This File Management & Digital Store plugin will help you to control file downloads & sell digital products from your WP site.
Download Monitor
download-monitor
Powerful Download Manager Plugin for WordPress
Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
easy-digital-downloads
The #1 eCommerce plugin to sell digital products & subscriptions. Accept credit card payments with Stripe & PayPal and start your store today.
WP Offload Media Lite for Amazon S3, DigitalOcean Spaces, and Google Cloud Storage
amazon-s3-and-cloudfront
Copies files to Amazon S3, DigitalOcean Spaces or Google Cloud Storage as they are uploaded to the Media Library. Optionally configure Amazon CloudFro …
Bit integrations – Easy Automator with no-code automation, integrate Webhook and automate 300+ Platform
bit-integrations
Perfect Automation and integration plugin: Connect 300+ platforms and automate CRM, Email marketing tools, Google Sheets, Contact forms, LMS and more
Deployer for Git Developer Profile
1 plugin · 400 total installs
How We Detect Deployer for Git
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/deployer-for-git/assets/css/dfg-admin-style.css/wp-content/plugins/deployer-for-git/assets/css/dfg-frontend-style.css/wp-content/plugins/deployer-for-git/assets/js/dfg-admin.js/wp-content/plugins/deployer-for-git/assets/js/dfg-frontend.js/wp-content/plugins/deployer-for-git/freemius/start.php/wp-content/plugins/deployer-for-git/vendor/autoload.phpdeployer-for-git/assets/css/dfg-admin-style.css?ver=deployer-for-git/assets/css/dfg-frontend-style.css?ver=deployer-for-git/assets/js/dfg-admin.js?ver=deployer-for-git/assets/js/dfg-frontend.js?ver=HTML / DOM Fingerprints
dfg_alert_boxDO NOT REMOVE THIS IF, IT IS ESSENTIAL FOR THE `function_exists` CALL ABOVE TO PROPERLY WORK.data-dfg-package-iddfg_ajax_object/wp-json/deployer-for-git/v1/package/update