Booter – Bots & Crawlers Manager Security & Risk Analysis

wordpress.org/plugins/booter-bots-crawlers-manager

Booter - Bots & Crawlers Manager is a preventative measure (treatment in advance) and treatment of damages caused by crawlers and bots.

8K active installs v1.5.8 PHP + WP 4.0+ Updated Feb 16, 2026
hostingrate-limitrequestsecurityupress
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 25, 2026
Safety Verdict

Is Booter – Bots & Crawlers Manager Safe to Use in 2026?

Generally Safe

Score 99/100

Booter – Bots & Crawlers Manager has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 25, 2026Updated 1mo ago
Risk Assessment

The 'booter-bots-crawlers-manager' plugin, version 1.5.8, exhibits a generally positive security posture based on the static analysis. It has a limited attack surface with all identified entry points (AJAX handlers, cron events) appearing to have authorization checks. The absence of direct SQL injection vulnerabilities and taint flows is also a strong indicator of good coding practices. The plugin also demonstrates a good practice of using nonces and capability checks where appropriate.

However, there are areas for improvement. While the majority of SQL queries use prepared statements, 44% do not, presenting a potential risk for SQL injection if those non-prepared queries handle user-supplied data without proper sanitization. Similarly, over half of the output escaping is not properly handled, which could lead to cross-site scripting (XSS) vulnerabilities, especially if the unescaped output is rendered in a user-facing context. The presence of a past medium-severity vulnerability, despite being patched, suggests that the development team has addressed security issues, but it also implies that vulnerabilities have existed in the past, requiring continued vigilance.

Overall, the plugin appears to be developed with security in mind, but the unescaped output and the use of raw SQL queries without prepared statements are concerning areas that could be exploited. The plugin's history of a medium vulnerability should be considered, and the developers should continue to prioritize thorough sanitization and escaping of all user inputs and outputs to mitigate potential risks.

Key Concerns

  • SQL queries not using prepared statements
  • Output escaping not properly handled
  • Past medium severity vulnerability
Vulnerabilities
1

Booter – Bots & Crawlers Manager Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-24534medium · 4.3Missing Authorization

Booter <= 1.5.7 - Missing Authorization

Jan 25, 2026 Patched in 1.5.8 (32d)
Code Analysis
Analyzed Mar 16, 2026

Booter – Bots & Crawlers Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
4 prepared
Unescaped Output
42
51 escaped
Nonce Checks
3
Capability Checks
5
File Operations
13
External Requests
1
Bundled Libraries
0

SQL Query Safety

44% prepared9 total queries

Output Escaping

55% escaped93 total outputs
Attack Surface

Booter – Bots & Crawlers Manager Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_booter_disable_404_pluginsincludes\AjaxHandlers.php:20
authwp_ajax_booter_download_disavow_listincludes\AjaxHandlers.php:21
authwp_ajax_booter_get_bad_robots_listincludes\AjaxHandlers.php:22
WordPress Hooks 19
actionbooter_404_log_cleanupincludes\Log404.php:21
actionbooter_404_log_reportincludes\Log404.php:22
filtercron_schedulesincludes\Log404.php:23
actiontemplate_redirectincludes\Log404.php:24
actioninitincludes\Log404.php:25
actioninitincludes\Plugin.php:45
actionmuplugins_loadedincludes\RateLimiter.php:20
actionmuplugins_loadedincludes\RequestBlocker.php:21
filtercron_schedulesincludes\RobotsWriter.php:26
actionbooter_write_robots_fileincludes\RobotsWriter.php:27
actioninitincludes\RobotsWriter.php:28
actionadmin_initincludes\Settings.php:24
actionadmin_menuincludes\Settings.php:25
actionadmin_enqueue_scriptsincludes\Settings.php:26
actionadmin_noticesincludes\Settings.php:28
actionadmin_noticesincludes\Settings.php:29
actionadmin_bar_menuincludes\Settings.php:32
actionpre_update_option_booter_settingsincludes\Settings.php:33
actionpre_update_option_booter_settingsincludes\Settings.php:34

Scheduled Events 3

booter_404_log_cleanup
booter_404_log_report
booter_write_robots_file
Maintenance & Trust

Booter – Bots & Crawlers Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 16, 2026
PHP min version
Downloads69K

Community Trust

Rating88/100
Number of ratings13
Active installs8K
Developer Profile

Booter – Bots & Crawlers Manager Developer Profile

SecuPress

4 plugins · 65K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
156 days
View full developer profile
Detection Fingerprints

How We Detect Booter – Bots & Crawlers Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/booter-bots-crawlers-manager/assets/dist/js/notice.js/wp-content/plugins/booter-bots-crawlers-manager/assets/dist/js/options.js/wp-content/plugins/booter-bots-crawlers-manager/assets/dist/css/options.css
Script Paths
/wp-content/plugins/booter-bots-crawlers-manager/assets/dist/js/notice.js/wp-content/plugins/booter-bots-crawlers-manager/assets/dist/js/options.js
Version Parameters
booter-bots-crawlers-manager/assets/dist/js/notice.js?ver=booter-bots-crawlers-manager/assets/dist/js/options.js?ver=booter-bots-crawlers-manager/assets/dist/css/options.css?ver=

HTML / DOM Fingerprints

JS Globals
wp_booter_noticeswp_booter
FAQ

Frequently Asked Questions about Booter – Bots & Crawlers Manager