
Crawler Record Security & Risk Analysis
wordpress.org/plugins/crawler-recordCrawler Record tells you the last time each of the most common search/chat bots visited (Google, ChatGPT, etc)- and the pages at which they looked.
Is Crawler Record Safe to Use in 2026?
Generally Safe
Score 100/100Crawler Record has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "crawler-record" plugin v0.9.1 demonstrates a generally good security posture, with no known vulnerabilities or CVEs in its history. The static analysis reveals a clean codebase with a complete absence of dangerous functions and external HTTP requests. Crucially, all SQL queries are properly prepared, mitigating a common attack vector. The plugin also incorporates capability checks, indicating an awareness of WordPress security best practices.
However, there are a few areas that warrant attention. The taint analysis identified one flow with an unsanitized path, which, while not classified as critical or high severity, represents a potential risk that should be addressed to further harden the plugin. Additionally, the plugin lacks nonce checks on its entry points. While the current attack surface appears minimal with zero AJAX handlers, REST API routes, shortcodes, or cron events, the absence of nonces on any future or unforeseen entry points could become a security concern.
Overall, "crawler-record" v0.9.1 is a relatively secure plugin, particularly due to its clean SQL handling and lack of historical vulnerabilities. The main recommendations for improvement involve addressing the unsanitized path identified in the taint analysis and implementing nonce checks as a defensive measure against potential future vulnerabilities, even with a small current attack surface.
Key Concerns
- Flow with unsanitized path
- Missing nonce checks on entry points
Crawler Record Security Vulnerabilities
Crawler Record Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Crawler Record Attack Surface
WordPress Hooks 5
Maintenance & Trust
Crawler Record Maintenance & Trust
Maintenance Signals
Community Trust
Crawler Record Alternatives
Unblock CSS & JS for Googlebot
unblock-cs-jss-for-googlebot
Modifies robots.txt to allow Googlebot access JS and CSS files.
WP Robots Txt
wp-robots-txt
WP Robots Txt Allows you to edit the content of your robots.txt file.
Head Meta Data
head-meta-data
Adds a custom set of <meta> tags to the <head> section of all posts & pages.
Robots.txt Editor
robots-txt-editor
Robots.txt for WordPress
Companion Sitemap Generator – HTML & XML
companion-sitemap-generator
Easy to use XML and HTML sitemap generator + Robots editor
Crawler Record Developer Profile
1 plugin · 50 total installs
How We Detect Crawler Record
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
crawler-record/style.css?ver=crawler-record/script.js?ver=HTML / DOM Fingerprints
<!-- Crawler Record: Begin Record --><!-- Crawler Record: End Record -->