WP Manifestindependent plugin directory
manifest / updates / wp-buildhook-deploy

WP Buildhook Deploy WP Registry grade C-. High-severity findings · 1 findingWP RegistryHigh-severity findings · 1 findingOpen the reportC- releases

WordPress plugin to trigger build hooks and deploy your static site.

by Justin W Hall · github.com/justinwhall/wp-buildhook-deploy · website

★ 161stars
28forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/justinwhall/wp-buildhook-deploy/archive/refs/heads/master.zip

👋 This plugin has been forked and is now maintained by Static Fuse.

======================================================================================

Look for improvments and more great WordPress + Gatsby workflow support. Questions? Submit an issue at the new repo or find me on twitter --> @justinwhall

WP Buildhook Deploy ("LittleBot Netlify")

This plugin was formerly know as "LittleBot Netlify". It was renamed to avoid confusion as it can be used to trigger build hooks at, say, AWS Amplify, GitHub or any service that provides a WebHook – not just Netlify.

Connect your WordPress website to Netlify (or any service that provides a buildhook) by triggering stage and or production build hooks on post save and or update. This plugin is not tied to Netlify, you can connect other CI systems with webhooks enabled like CircleCI, Travis, AWS Amplify, etc.

Installation

  • Download or clone repository
  • Move wp-buildhook-deploy to your plugins directory or zip and upload
  • Activate plugin
  • Add at least one buildhook URL to the setings page Settings > WP BuildHook Deploy

Using Netlify? (It's awesome BTW)

  • Create at least one site at Netlify
  • Create a build hook for each site (or just one if you're just using one site)
  • Add build hook to the Settings > WP BuildHook Deploy
  • Your WordPress site will call your build hook(s) when publishing, updating or deleting a post

Gatsby + WordPress + Netlify Starter

Gatsby + WordPress + Netlify Starter is a plug and play starter to get up and running with continuous deployment from your WordPress site to Netlify with Gatsby.

Gatsby + WordPress + Live Previews

Checkout this Gatsby theme. This could also be used with this plugin to publish to Netlify, AWS Amplify etc when publishing/updating/deleting/etc WordPress Posts/pages.

Q & A

Q Do you need two sites at Netlify?

A No. This plugin will call your build hook and build your Gatsby (or whatever) site no matter what. The starter mentioned above facilitates a two environment Gatsby set up but other than that, this plugin is totally front end agnostic and you could just as easy trigger one build hook by only adding one build hook URL.

Q Does this plugin support Gutenberg?

A This plugin supports both GutenLOVERS and GutenHATERS. How? It supports Gutenberg as that is what the WordPress editing experience is now. Don't like Gutenberg? This plugin also supports the Classic Editor.

Q Can I use this plugin with other similar system to Netlify like for example AWS Amplify?

A YES. You can use a CI like Amplify, Circle, Travis etc. Depending on what you are trying to do, the plugin may still work as it just calls a webhook URL with some logic around various publishing hooks.

Releases

2 releases.

Tag
Published
0.9.1 latest
Jun 6, 2019 7 years ago
Jun 6, 2019 7 years ago

These releases are tags only. The author does not attach a packaged zip, so there are no download counts to report.

C- grade

Security

WP Buildhook Deploy 0.9.1 · audited by WP Registry

High-severity findings.

1 high
Audited release
0.9.1
Findings
1
Worst severity
high
Content hash
9a3cef854586fd586290be62…

Findings

  • high Contributor can publish posts by adding 'deploy' to the save request (publish_posts bypass)

    missing_capability

    LBN_Post::insert_post() is hooked to wp_insert_post_data and sets $data['post_status']='publish' whenever $postarr['deploy'] is set, with no current_user_can('publish_posts') check. In the classic editor save flow (post.php action=editpost -> edit_post() -> wp_update_post()), $postarr is built from $_POST, so a Contributor (who core restricts to 'pending') can add deploy=1 and have the post published immediately. save_post then fires the configured Netlify build hooks, pushing the unreviewed content to the static production site.

    includes/class-lbn-post.php:101-116

    Recommendation

    Only honour 'deploy' when current_user_can( 'publish_post', $post_id ) (or publish_posts for the post type) and a dedicated nonce is valid; otherwise leave post_status untouched.

WP Registry hashes the installable build and reports on that exact bytes-for-bytes copy. Embargoed findings are withheld until they are disclosed, so a clean verdict means nothing public is outstanding. WP Manifest does not audit code itself.