
AgentMark Security & Risk Analysis
wordpress.org/plugins/agentmarkAI-Ready Markdown Endpoints & llms.txt discovery for WordPress. Clean, machine-readable content for AI agents and RAG systems.
Is AgentMark Safe to Use in 2026?
Generally Safe
Score 100/100AgentMark has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The agentmark plugin v1.0.0 demonstrates strong security practices in its static analysis. It has a minimal attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. Crucially, all SQL queries are properly prepared, and all output is correctly escaped, indicating a solid defense against common injection and XSS vulnerabilities. The presence of nonce and capability checks further strengthens its security posture by enforcing proper authorization. The plugin also avoids file operations and external HTTP requests, reducing potential attack vectors.
Despite these positive findings, the taint analysis revealed one flow with an unsanitized path. While this flow was not classified as critical or high severity, it represents a potential area of concern that warrants attention. The plugin's vulnerability history is clean, with no known CVEs, which is a positive indicator of its current security state. However, a lack of historical data makes it difficult to predict future vulnerabilities.
In conclusion, agentmark v1.0.0 is generally well-secured based on the provided static analysis. Its adherence to secure coding practices like prepared statements and output escaping is commendable. The single unsanitized path in the taint analysis is the primary weakness identified and should be investigated and remediated to maintain a robust security profile. The absence of historical vulnerabilities is a good sign but should be monitored over time.
Key Concerns
- Unsanitized path in taint flow
AgentMark Security Vulnerabilities
AgentMark Release Timeline
AgentMark Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
AgentMark Attack Surface
WordPress Hooks 11
Maintenance & Trust
AgentMark Maintenance & Trust
Maintenance Signals
Community Trust
AgentMark Alternatives
JumpsuitAI – llms.txt + Markdown Endpoints
jumpsuitai-llms-txt
Generate /llms.txt, /llms-full.txt & .md endpoints for AI/LLMs in WordPress. Works with Yoast SEO, Rank Math, SEOPress & All in One SEO.
Markdown for AI Agents
markdown-for-ai-agents
Serve clean Markdown versions of WordPress content to AI agents using HTTP content negotiation.
Mescio for Agents
mescio-for-agents
Mescio for Agents serves your WordPress content as clean Markdown to AI agents and GPT crawlers. Human visitors never notice a thing.
md4AI
md4ai
Optimise content for generative engines (GEO) by serving custom Markdown and a site-wide llms.txt.
Botkibble
botkibble
Serves every published post and page as Markdown for AI agents and crawlers. No configuration, no API keys. Activate and it works.
AgentMark Developer Profile
2 plugins · 40 total installs
How We Detect AgentMark
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/agentmark/assets/css/style.css/wp-content/plugins/agentmark/assets/js/script.js/wp-content/plugins/agentmark/assets/js/script.jsagentmark/assets/css/style.css?ver=agentmark/assets/js/script.js?ver=HTML / DOM Fingerprints
agentmark-settings-pagedata-agentmark-post-idagentmark_settingsAgentMark/wp-json/agentmark/v1/posts/wp-json/agentmark/v1/post//wp-json/agentmark/v1/settings