Better Robots.txt – AI-Ready Crawl Control & Bot Governance Security & Risk Analysis

wordpress.org/plugins/better-robots-txt

Replace the default WordPress robots.txt workflow with a smarter, structured version you can preview before publishing, with Free, Pro, and Premium ed …

6K active installs v3.0.0 PHP 7.4+ WP 5.0+ Updated Mar 10, 2026
ai-crawlersbot-blockerllms-txtrobots-txtseo
99
A · Safe
CVEs total2
Unpatched0
Last CVEFeb 14, 2023
Download
Safety Verdict

Is Better Robots.txt – AI-Ready Crawl Control & Bot Governance Safe to Use in 2026?

Generally Safe

Score 99/100

Better Robots.txt – AI-Ready Crawl Control & Bot Governance has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Feb 14, 2023Updated 24d ago
Risk Assessment

The 'better-robots-txt' plugin version 3.0.0 exhibits a generally good security posture, with a notable absence of critical or high severity taint flows and all SQL queries utilizing prepared statements. The plugin also demonstrates good practices regarding nonce and capability checks for its entry points. However, there are several areas that warrant caution. The presence of 9 file operations, coupled with one flow identified with an unsanitized path, suggests a potential risk of arbitrary file access or manipulation if not carefully handled. Furthermore, the vulnerability history reveals two past CVEs, one of high and one of medium severity, with types including Cross-Site Request Forgery and Missing Authorization. While there are currently no unpatched vulnerabilities, this history indicates a past tendency for these types of security flaws, which requires ongoing vigilance. The bundled Freemius library at v1.0 also represents a potential risk if it contains known vulnerabilities or is outdated.

Key Concerns

  • Flow with unsanitized paths
  • Bundled outdated library (Freemius v1.0)
  • Vulnerability history (1 high, 1 medium CVE)
  • Unescaped output (17% of 40 outputs)
Vulnerabilities
2

Better Robots.txt – AI-Ready Crawl Control & Bot Governance Security Vulnerabilities

CVEs by Year

1 CVE in 2019
2019
1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2023-25706medium · 5.4Cross-Site Request Forgery (CSRF)

Robots.txt optimization <= 1.4.5 - Cross Site Request Forgery

Feb 14, 2023 Patched in 1.4.6 (343d)

Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update

Feb 25, 2019 Patched in 1.2.6 (1793d)
Code Analysis
Analyzed Mar 16, 2026

Better Robots.txt – AI-Ready Crawl Control & Bot Governance Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
7
33 escaped
Nonce Checks
6
Capability Checks
9
File Operations
9
External Requests
3
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared2 total queries

Output Escaping

83% escaped40 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
save_options (admin\controllers\SettingsController.php:81)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Better Robots.txt – AI-Ready Crawl Control & Bot Governance Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_better_robots_dismiss_legacy_noticebootstrap\Bootstrap.php:98
WordPress Hooks 17
actiondo_robotsadmin\controllers\RobotsController.php:32
actiontemplate_redirectadmin\controllers\RobotsController.php:35
actionwp_headadmin\controllers\RobotsController.php:37
actiondo_robotsadmin\controllers\RobotsControllerLegacy.php:20
actionafter_license_changebetter-robots-txt.php:64
actionafter_license_deactivationbetter-robots-txt.php:66
actionafter_account_deletebetter-robots-txt.php:68
actionafter_uninstallbetter-robots-txt.php:70
actionrobots_txt_check_license_statusbetter-robots-txt.php:72
actionplugins_loadedbetter-robots-txt.php:80
actionadmin_noticesbetter-robots-txt.php:84
actionadmin_noticesbootstrap\Bootstrap.php:96
filterconnect_messagebootstrap\FreemiusManager.php:36
actioninitbootstrap\PluginManager.php:41
actionadmin_menubootstrap\Settings.php:45
actionadmin_enqueue_scriptsbootstrap\Settings.php:46
filterscript_loader_tagbootstrap\Settings.php:49

Scheduled Events 1

robots_txt_check_license_status
Maintenance & Trust

Better Robots.txt – AI-Ready Crawl Control & Bot Governance Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 10, 2026
PHP min version7.4
Downloads305K

Community Trust

Rating90/100
Number of ratings102
Active installs6K
Developer Profile

Better Robots.txt – AI-Ready Crawl Control & Bot Governance Developer Profile

Pagup

17 plugins · 33K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
439 days
View full developer profile
Detection Fingerprints

How We Detect Better Robots.txt – AI-Ready Crawl Control & Bot Governance

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/better-robots-txt/assets/css/backend.css/wp-content/plugins/better-robots-txt/assets/js/backend.js
Script Paths
/wp-content/plugins/better-robots-txt/vendor/freemius/wordpress-sdk/start.php
Version Parameters
better-robots-txt/assets/css/backend.css?ver=better-robots-txt/assets/js/backend.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Better Robots.txt – AI-Ready Crawl Control & Bot Governance