
GWD Connect Security & Risk Analysis
wordpress.org/plugins/graphic-web-design-incAutomatic backups, log monitoring with size alerts, uptime tracking, auto-updates, and a bulk migration REST API for WordPress.
Is GWD Connect Safe to Use in 2026?
Mostly Safe
Score 78/100GWD Connect is generally safe to use. 1 past CVE were resolved.
The "graphic-web-design-inc" plugin version 2.9 presents a mixed security posture. While it boasts a clean vulnerability history with no known CVEs, indicating good maintenance or a lack of past exploitable issues, the static analysis reveals significant concerns. A notable number of AJAX handlers (4 out of 4) lack authentication checks, creating a substantial attack surface that could be exploited by unauthenticated users. Furthermore, the presence of dangerous functions like 'exec' and 'unserialize' is always a red flag, as these can lead to arbitrary code execution if improperly handled. The taint analysis shows flows with unsanitized paths, although they are not currently categorized as critical or high severity, this still warrants attention for potential future exploitation. The plugin shows good practices in using prepared statements for SQL queries (78%) and has a decent number of nonce checks and capability checks. However, the number of unprotected entry points is concerning and outweighs the positive aspects. Overall, while the plugin hasn't had publicly disclosed vulnerabilities, the code itself contains elements that pose a latent risk, particularly the unprotected AJAX endpoints and dangerous function usage.
Key Concerns
- 4 AJAX handlers without auth checks
- Use of dangerous functions (exec, unserialize)
- Flows with unsanitized paths in taint analysis
- 60% properly escaped output
GWD Connect Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
GWD Connect <= 2.9 - Unauthenticated Limited Code Execution via update_agent
GWD Connect Release Timeline
GWD Connect Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
GWD Connect Attack Surface
AJAX Handlers 4
REST API Routes 2
WordPress Hooks 26
Scheduled Events 1
Maintenance & Trust
GWD Connect Maintenance & Trust
Maintenance Signals
Community Trust
GWD Connect Alternatives
Backup and Staging by WP Time Capsule
wp-time-capsule
Backup and Staging by WP Time Capsule is an automated incremental backup plugin that backs up your website changes as per your schedule to Dropbox, Go …
UpdraftPlus: WP Backup & Migration Plugin
updraftplus
Backup, restore or migrate your WordPress website to another host or domain. Schedule backups or run manually. Migrate in minutes.
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More
duplicator
The best WordPress backup and migration plugin. Quickly and easily backup ,migrate, copy, move, or clone your site from one location to another.
WP STAGING – WordPress Backup, Restore & Migration
wp-staging
Backup, restore, staging, and migration for WordPress. Create full-site backups and test updates safely. 100% Unit Tested.
BackupBliss – Backup & Migration with Free Cloud Storage
backup-backup
Backup, migrate, and create staging sites with free cloud storage and support.
GWD Connect Developer Profile
1 plugin · 20 total installs
How We Detect GWD Connect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/graphic-web-design-inc/css/gwd-connect-admin-style.css/wp-content/plugins/graphic-web-design-inc/js/gwd-connect-admin-script.js/wp-content/plugins/graphic-web-design-inc/js/gwd-connect-main-script.jsgraphic-web-design-inc/css/gwd-connect-admin-style.css?ver=graphic-web-design-inc/js/gwd-connect-admin-script.js?ver=graphic-web-design-inc/js/gwd-connect-main-script.js?ver=HTML / DOM Fingerprints
gwd-connect-admin-pagegwd-connect-status-tablegwd-connect-logs-table<!-- GWD Connect Plugin --><!-- GWD Connect Shortcode --><!-- End GWD Connect Shortcode -->data-gwd-connect-settingdata-gwd-connect-log-idgwdConnectAdminGwdConnectLogsGwdConnectBackups/wp-json/gwd-connect/v1/migrate/wp-json/gwd-connect/v1/settings/wp-json/gwd-connect/v1/logs[gwd_connect_status][gwd_connect_logs][gwd_connect_backups]