
Bulk NoIndex & NoFollow Toolkit Security & Risk Analysis
wordpress.org/plugins/bulk-noindex-nofollow-toolkit-by-mad-fishBulk set the noindex / nofollow robots tag for posts, pages, categories, and author URLs. Easily identify thin content and noindex it fast.
Is Bulk NoIndex & NoFollow Toolkit Safe to Use in 2026?
Generally Safe
Score 97/100Bulk NoIndex & NoFollow Toolkit has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "bulk-noindex-nofollow-toolkit-by-mad-fish" plugin v2.30 presents a mixed security posture. While it demonstrates good practices in handling SQL queries with prepared statements and a very low rate of unescaped outputs, several significant concerns arise from the static analysis. The plugin has a considerable attack surface consisting of 6 AJAX handlers, all of which lack proper authentication checks. This is a critical weakness that could allow unauthenticated users to trigger potentially sensitive actions.
The vulnerability history is also a concern, with a total of 5 known CVEs, all of which were medium severity. The common vulnerability types being Cross-site Scripting and Missing Authorization, directly correlate with the findings of unprotected AJAX handlers. The fact that all past vulnerabilities are currently patched is a positive, but the recurring nature of these vulnerability types suggests a potential ongoing weakness in how user input is handled and access is controlled.
In conclusion, the plugin has strengths in its SQL handling and output escaping. However, the lack of authorization checks on a significant portion of its AJAX endpoints, coupled with a history of similar vulnerabilities, creates a substantial risk of unauthorized actions and potential cross-site scripting attacks if not addressed. Users should be cautious and ensure the latest patches are applied, but the fundamental architectural flaw in unprotected AJAX handlers requires remediation.
Key Concerns
- AJAX handlers without auth checks
- 5 medium severity CVEs in history
- 71% properly escaped outputs
Bulk NoIndex & NoFollow Toolkit Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Bulk NoIndex & NoFollow Toolkit <= 2.16 - Reflected Cross-Site Scripting
Bulk NoIndex & NoFollow Toolkit <= 2.15 - Reflected Cross-Site Scripting
Bulk NoIndex & NoFollow Toolkit <= 2.01 - Reflected Cross-Site Scripting via tab, order, and orderby
Bulk NoIndex & NoFollow Toolkit <= 1.42 - Reflected Cross-Site Scripting via 's'
Bulk NoIndex & NoFollow Toolkit <= 1.5 - Missing Authorization
Bulk NoIndex & NoFollow Toolkit Release Timeline
Bulk NoIndex & NoFollow Toolkit Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Bulk NoIndex & NoFollow Toolkit Attack Surface
AJAX Handlers 6
WordPress Hooks 7
Maintenance & Trust
Bulk NoIndex & NoFollow Toolkit Maintenance & Trust
Maintenance Signals
Community Trust
Bulk NoIndex & NoFollow Toolkit Alternatives
Auto Focus Keyword for SEO
auto-focus-keyword-for-seo
Automatically fill missing Yoast SEO or Rank Math focus keywords from post titles. Batch sync, exclusions, and Pro auto-sync.
TextBulker (IA Redaction)
textbulker
Official plugin for TextBulker.com – inject SEO metadata via REST API when publishing AI-generated content.
SEO Rocket Integration
seo-rocket-integration
Publish SEO-optimized articles from SEO Rocket with automatic Yoast SEO and Rank Math metadata sync.
Unique Slug Checker
unique-slug-checker
Prevent duplicate slugs in WordPress with real-time detection for editors and SEO plugins.
Noindex Parameters
noindex-parameters
Prevent search engines from indexing URLs with specific parameters. Compatible with Rank Math, Yoast SEO, and WordPress core.
Bulk NoIndex & NoFollow Toolkit Developer Profile
1 plugin · 2K total installs
How We Detect Bulk NoIndex & NoFollow Toolkit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bulk-noindex-nofollow-toolkit-by-mad-fish/admin/css/bulk-noindex-toolkit.css/wp-content/plugins/bulk-noindex-nofollow-toolkit-by-mad-fish/admin/js/bulk-noindex-toolkit.js/wp-content/plugins/bulk-noindex-nofollow-toolkit-by-mad-fish/admin/js/bulk-noindex-toolkit.jsbulk-noindex-nofollow-toolkit-by-mad-fish/admin/css/bulk-noindex-toolkit.css?ver=bulk-noindex-nofollow-toolkit-by-mad-fish/admin/js/bulk-noindex-toolkit.js?ver=HTML / DOM Fingerprints
<!-- robots meta tag updated by Mad Fish bulk noindex plugin https://www.madfishdigital.com/wp-plugins/ -->data-bnitk-noindexdata-bnitk-nofollowdata-bnitk-update-typebulkToolKitAjaxUrlbulkNoindexToolkitObject/wp-json/bnitkmfd/v1/update/post/wp-json/bnitkmfd/v1/update/bulk/posts/wp-json/bnitkmfd/v1/update/term/wp-json/bnitkmfd/v1/update/bulk/terms/wp-json/bnitkmfd/v1/update/author/wp-json/bnitkmfd/v1/update/bulk/authors