
Botless Core Security & Risk Analysis
wordpress.org/plugins/botless-coreProtect your embedded HTML videos from unwanted bot traffic. Save bandwidth by blocking bots from downloading video content.
Is Botless Core Safe to Use in 2026?
Generally Safe
Score 100/100Botless Core has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The botless-core plugin v1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices with a high percentage of SQL queries using prepared statements and properly escaped output. The absence of critical or high-severity taint flows, file operations, and external HTTP requests is also a significant strength, indicating a generally well-developed codebase with minimal exposure to common attack vectors. The plugin also shows a history of no known vulnerabilities, which is a positive indicator of its maturity and the diligence of its developers.
However, a significant concern arises from the static analysis of its attack surface. The plugin exposes three AJAX handlers, all of which lack authentication checks. This creates a substantial risk, as any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure if these handlers are not adequately secured internally. While nonce checks and capability checks are present, their absence on these entry points makes them vulnerable to unauthorized access. The lack of any recorded vulnerabilities in its history, while generally good, could also be a double-edged sword; it might mean the plugin hasn't been extensively targeted or audited for specific weaknesses, particularly concerning its unauthenticated AJAX endpoints.
In conclusion, botless-core v1.0.1 has strong foundations in secure coding but suffers from a critical oversight in securing its AJAX endpoints. The lack of authentication on these three entry points represents a clear and present danger that should be addressed immediately. The rest of the code appears robust, but this single weakness significantly elevates the overall risk profile of the plugin.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without auth checks
- AJAX handlers without auth checks
Botless Core Security Vulnerabilities
Botless Core Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Botless Core Attack Surface
AJAX Handlers 3
WordPress Hooks 9
Maintenance & Trust
Botless Core Maintenance & Trust
Maintenance Signals
Community Trust
Botless Core Alternatives
FV Flowplayer Video Player
fv-wordpress-flowplayer
WordPress's most reliable, easy to use and feature-rich video player. Supports responsive design, HTML5, playlists, ads, stats, Vimeo and YouTube.
HTML5 Video Player – Embed and Play Videos in Custom Player
html5-video-player
HTML5 Video Player Plugin lets you embed responsive videos in WordPress. It’s easy to use, fast, and supports MP4, WebM, OGG, FLV, Youtube and Vimeo.
ClickCease Click Fraud Protection
clickcease-click-fraud-protection
Protect your website and ad campaigns from bots, competitors, and click fraud with ClickCease's advanced fraud prevention and real-time monitoring.
FV Player 8
fv-player
WordPress's most reliable, easy to use and feature-rich video player. Supports playlists, ads, stats and user video position saving.
Video gallery and Player
html5-videogallery-plus-player
Easy to add and display your HTML5, YouTube, Vimeo vedio gallery with Magnific Popup to your website. Also work with Gutenberg shortcode block.
Botless Core Developer Profile
1 plugin · 10 total installs
How We Detect Botless Core
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/botless-core/assets/css/botless-core-admin.css/wp-content/plugins/botless-core/assets/js/lib/chart.umd.js/wp-content/plugins/botless-core/assets/js/botless-core.js/wp-content/plugins/botless-core/assets/js/lib/chart.umd.js/wp-content/plugins/botless-core/assets/js/botless-core.jsbotless-core/assets/css/botless-core-admin.css?ver=botless-core/assets/js/botless-core.js?ver=HTML / DOM Fingerprints
botless-core-admin-wrapdata-botless-core-noncebotlessCorebotless_core_ajax_object/wp-json/botless-core/v1/settings/wp-json/botless-core/v1/save-settings/wp-json/botless-core/v1/logs/wp-json/botless-core/v1/clear-logs