ChatBot Blocker by CellarWeb Security & Risk Analysis

wordpress.org/plugins/cellarweb-chatbot-blocker

ChatBot Blocker by CellarWeb adds commands to the WordPress virtual robots.txt file to block various chatbots from using your site content.

10 active installs v2.02 PHP 7.2+ WP 5.5+ Updated Aug 30, 2024
aichatbotchatgptrobotsrobots-txt
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ChatBot Blocker by CellarWeb Safe to Use in 2026?

Generally Safe

Score 92/100

ChatBot Blocker by CellarWeb has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "cellarweb-chatbot-blocker" plugin, version 2.02, presents a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) is a significant strength, as it limits the potential entry points for malicious actors. Furthermore, the code signals indicate no dangerous functions, all SQL queries use prepared statements, and there are no file operations or external HTTP requests, which are all positive indicators of secure coding practices. The lack of any recorded vulnerabilities or CVEs further reinforces this perception of a secure plugin.

However, a notable concern arises from the "Output escaping" metric, where only 10% of the 10 total outputs are properly escaped. This suggests a potential weakness where untrusted data could be echoed into the output stream without sufficient sanitization, potentially leading to cross-site scripting (XSS) vulnerabilities. While taint analysis showed no unsanitized flows, the low percentage of proper output escaping is a direct indicator of a risk that could be exploited if a pathway for unsanitized data were to exist. The absence of nonce checks and capability checks, while not explicitly problematic given the lack of an attack surface, could become a concern if new entry points were introduced in future versions without these security measures.

In conclusion, the plugin is well-developed from a structural security perspective, with a minimal attack surface and secure data handling for database interactions and file operations. The primary weakness lies in the inadequate output escaping, which presents a tangible risk. The clean vulnerability history is a testament to the developers' efforts, but the output escaping issue warrants attention to fully solidify the plugin's security.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

ChatBot Blocker by CellarWeb Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ChatBot Blocker by CellarWeb Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

10% escaped10 total outputs
Attack Surface

ChatBot Blocker by CellarWeb Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_initcellarweb-chatbot-blocker.php:54
actionadmin_noticescellarweb-chatbot-blocker.php:55
actionnetwork_admin_initcellarweb-chatbot-blocker.php:56
actionnetwork_admin_noticescellarweb-chatbot-blocker.php:57
actionadmin_menucellarweb-chatbot-blocker.php:182
actionadmin_initcellarweb-chatbot-blocker.php:183
filteradmin_footer_textcellarweb-chatbot-blocker.php:212
filterrobots_txtcellarweb-chatbot-blocker.php:305
actionwp_enqueue_scriptscellarweb-chatbot-blocker.php:389
filterrobots_txtcellarweb-chatbot-blocker.php:406
Maintenance & Trust

ChatBot Blocker by CellarWeb Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedAug 30, 2024
PHP min version7.2
Downloads892

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ChatBot Blocker by CellarWeb Developer Profile

Rick Hellewell

16 plugins · 1K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ChatBot Blocker by CellarWeb

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cellarweb-chatbot-blocker/css/settings.css
Version Parameters
cellarweb-chatbot-blocker/css/settings.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about ChatBot Blocker by CellarWeb