Auto Robot – WP Autoblogging and RSS Feed News Aggregator Security & Risk Analysis

wordpress.org/plugins/auto-robot

Auto blogging and generate WordPress posts automatically from OpenAI ChatGPT, RSS Feed, Instagram, Youtube, Facebook, Twitter, Vimeo, Flickr and etc.

100 active installs v4.0.38 PHP + WP 4.0+ Updated Mar 1, 2026
rss-post-importerwordpress-aggregator-pluginwordpress-news-feed-pluginwp-aggregatorwp-rss-aggregator-feed-to-post
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Auto Robot – WP Autoblogging and RSS Feed News Aggregator Safe to Use in 2026?

Generally Safe

Score 100/100

Auto Robot – WP Autoblogging and RSS Feed News Aggregator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'auto-robot' plugin v4.0.38 presents a mixed security posture. On the positive side, it demonstrates good practices in SQL query handling, exclusively using prepared statements, and a high percentage of properly escaped outputs. The absence of known vulnerabilities in its history and the lack of critical or high severity taint flows are also strong indicators of a secure development process.

However, a significant concern is the presence of an unprotected AJAX handler. This creates a direct entry point for attackers that does not require authentication or authorization, potentially leading to unauthorized actions or information disclosure depending on its functionality. While the total attack surface is not excessively large, this single unprotected point is a critical weakness.

Overall, the plugin has a solid foundation with its secure coding practices in core areas like database interaction and output sanitization. The vulnerability history is excellent. The primary and most pressing concern is the unprotected AJAX handler, which requires immediate attention. Addressing this single vulnerability would significantly improve the plugin's security.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

Auto Robot – WP Autoblogging and RSS Feed News Aggregator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Auto Robot – WP Autoblogging and RSS Feed News Aggregator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
49
288 escaped
Nonce Checks
9
Capability Checks
8
File Operations
4
External Requests
6
Bundled Libraries
2

Bundled Libraries

Select2Freemius1.0

SQL Query Safety

100% prepared4 total queries

Output Escaping

85% escaped337 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
save_settings (admin\classes\class-admin-ajax.php:41)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Auto Robot – WP Autoblogging and RSS Feed News Aggregator Attack Surface

Entry Points9
Unprotected1

AJAX Handlers 9

authwp_ajax_auto_robot_save_campaignadmin\classes\class-admin-ajax.php:25
authwp_ajax_auto_robot_run_campaignadmin\classes\class-admin-ajax.php:26
authwp_ajax_auto_robot_select_integrationadmin\classes\class-admin-ajax.php:27
authwp_ajax_auto_robot_save_api_dataadmin\classes\class-admin-ajax.php:28
authwp_ajax_auto_robot_save_user_dataadmin\classes\class-admin-ajax.php:29
authwp_ajax_auto_robot_skip_premiumadmin\classes\class-admin-ajax.php:30
authwp_ajax_auto_robot_generate_campaignadmin\classes\class-admin-ajax.php:31
authwp_ajax_auto_robot_save_settingsadmin\classes\class-admin-ajax.php:32
authwp_ajax_auto_robot_review_dismissadmin\classes\class-admin-review.php:19
WordPress Hooks 32
actionadmin_menuadmin\abstracts\class-admin-module.php:46
actionadmin_headadmin\abstracts\class-admin-module.php:47
actionadmin_menu_editor-menu_replacedadmin\abstracts\class-admin-module.php:50
filterauto_robot_dataadmin\abstracts\class-admin-module.php:52
filterauto_robot_l10nadmin\abstracts\class-admin-module.php:53
filtersubmenu_fileadmin\abstracts\class-admin-module.php:54
actionadmin_enqueue_scriptsadmin\abstracts\class-admin-page.php:253
actioninitadmin\abstracts\class-admin-page.php:254
actionadmin_noticesadmin\classes\class-admin-review.php:18
actionadmin_menuadmin\classes\class-admin.php:34
actionadmin_menuadmin\classes\class-admin.php:110
actionadmin_menuadmin\classes\class-admin.php:134
actionadmin_menuadmin\classes\class-admin.php:158
actionadmin_menuadmin\classes\class-admin.php:182
actionadmin_menuadmin\classes\class-admin.php:206
actionadmin_menuadmin\classes\class-admin.php:230
actionadmin_menuadmin\classes\class-admin.php:254
actionadmin_menuadmin\classes\class-admin.php:279
actionadmin_menuadmin\classes\class-admin.php:303
actionadmin_menuadmin\classes\class-admin.php:329
actionadmin_initauto-robot-lite.php:119
actioncurrent_screenauto-robot-lite.php:127
filterscript_loader_tagauto-robot-lite.php:129
actionadmin_noticesauto-robot-lite.php:247
actionadmin_enqueue_scriptsauto-robot-lite.php:248
actionplugins_loadedauto-robot-lite.php:311
actionwp_enqueue_scriptsincludes\class-core.php:103
filtercron_schedulesincludes\class-schedule.php:45
actionrobot_cron_hookincludes\class-schedule.php:76
filterwp_mail_content_typeincludes\helpers\helper-report.php:133
filtercontent_save_preincludes\jobs\abstract-class-job.php:210
filtercontent_filtered_save_preincludes\jobs\abstract-class-job.php:211

Scheduled Events 1

robot_cron_hook
Maintenance & Trust

Auto Robot – WP Autoblogging and RSS Feed News Aggregator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 1, 2026
PHP min version
Downloads182K

Community Trust

Rating36/100
Number of ratings10
Active installs100
Alternatives

Auto Robot – WP Autoblogging and RSS Feed News Aggregator Alternatives

No alternatives data available yet.

Developer Profile

Auto Robot – WP Autoblogging and RSS Feed News Aggregator Developer Profile

wphobby

11 plugins · 200 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Auto Robot – WP Autoblogging and RSS Feed News Aggregator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-robot/assets/css/hide.css/wp-content/plugins/auto-robot/assets/css/admin.css/wp-content/plugins/auto-robot/assets/js/admin.js
Script Paths
/wp-content/plugins/auto-robot/assets/js/admin.js
Version Parameters
auto-robot/assets/css/hide.css?ver=auto-robot/assets/css/admin.css?ver=auto-robot/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
auto-robot-admin-noticeauto-robot-notice-pro
HTML Comments
<!-- Upgrade to Auto Robot Pro --><!-- Auto Robot -->
Data Attributes
data-campid
JS Globals
auto_robot_params
FAQ

Frequently Asked Questions about Auto Robot – WP Autoblogging and RSS Feed News Aggregator