# Run script during external plugin installation

**URL:** <https://discuss.elastic.co/t/run-script-during-external-plugin-installation/360938>\
**Category:** Kibana\
**Tags:** kibana-plugin-development\
**Created:** [June 6, 2024, 8:24am UTC](https://discuss.elastic.co/t/run-script-during-external-plugin-installation/360938 "2024-06-06T08:24:18Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sheereen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sheereen/32/122005_2.png) [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Post date:** [June 6, 2024, 8:24am UTC](https://discuss.elastic.co/t/run-script-during-external-plugin-installation/360938/1 "2024-06-06T08:24:18Z")

</div>

Hi,

I am developing a custom external plugin in Kibana using React.

As far as I know, anyone can install the plugin into Kibana, given they have access to /usr/share/kibana folder

I want to run a a script during my plugin installation, so that I can may be restrict plugin installation or ask for extra key/input from user to authorize the installation. How can I achieve this?

Thanks

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 17, 2024, 3:46pm UTC](https://discuss.elastic.co/t/run-script-during-external-plugin-installation/360938/2 "2024-06-17T15:46:51Z")

</div>

Hi @Sheereen,

I'm aware of the `setup` lifecycle function for a plugin, so perhaps you could use some saved context to see if this is the first time the plugin is being used. But I'm not aware of any way to do this on install. You would also need to be comfortable changing this between version as the plugin API isn't stable or backward compatible.

I'm not sure which actions you're wanting to do on installation, but I would ensure they adhere to the [security best practices](https://www.elastic.co/guide/en/kibana/current/security-best-practices.html)to avoid introducing a vulnerability that could impact your cluster.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![Sheereen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sheereen/32/122005_2.png) [@Sheereen](https://discuss.elastic.co/u/Sheereen)\
**Post date:** [June 28, 2024, 6:05am UTC](https://discuss.elastic.co/t/run-script-during-external-plugin-installation/360938/3 "2024-06-28T06:05:16Z")

</div>

Thanks a lot carly for the detailed explanation. 😀
