
Generate Security.txt Security & Risk Analysis
wordpress.org/plugins/generate-security-txtWith a security.txt file, ethical hackers can easily send you a notification when they have found a vulnerability on your website.
Is Generate Security.txt Safe to Use in 2026?
Generally Safe
Score 100/100Generate Security.txt has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "generate-security-txt" plugin version 1.0.10 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and avoids bundled libraries, which can often introduce vulnerabilities. The absence of any known vulnerabilities in its history is also a significant strength, suggesting a generally well-maintained codebase. However, several concerns warrant attention, primarily stemming from its attack surface. A significant portion of its AJAX handlers lack authentication checks, creating potential entry points for unauthorized actions. While taint analysis didn't reveal critical or high severity issues, the presence of a flow with unsanitized paths indicates a potential risk of data manipulation if that path were to be exploited through an unauthenticated AJAX handler. The limited number of capability checks, coupled with the unprotected AJAX handlers, further amplifies this risk.
Key Concerns
- Unprotected AJAX handlers
- Flow with unsanitized paths
- File operations without auth
- External HTTP requests without auth
- Low percentage of properly escaped output
Generate Security.txt Security Vulnerabilities
Generate Security.txt Code Analysis
Output Escaping
Data Flow Analysis
Generate Security.txt Attack Surface
AJAX Handlers 4
WordPress Hooks 14
Scheduled Events 3
Maintenance & Trust
Generate Security.txt Maintenance & Trust
Maintenance Signals
Community Trust
Generate Security.txt Alternatives
Security.txt Manager
security-txt-manager
Create and manage your security.txt from within WordPress. The easiest way to manage security policy.
wp-security-txt
wp-security-txt
A plugin for serving 'security.txt' in WordPress 4.9+, based on configuration settings.
security-txt
security-txt
A plugin for serving 'security.txt' in WordPress 6.1.1+.
Wordfence Security – Firewall, Malware Scan, and Login Security
wordfence
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.
Hostinger Tools
hostinger
Simplified WordPress management. Manage site info, maintenance, security, & redirects.
Generate Security.txt Developer Profile
1 plugin · 400 total installs
How We Detect Generate Security.txt
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/generate-security-txt/js/generate-security-txt-admin.js/wp-content/plugins/generate-security-txt/css/generate-security-txt-admin.css/wp-content/plugins/generate-security-txt/css/jquery-ui.css/wp-content/plugins/generate-security-txt/js/generate-security-txt-admin.jsgenerate-security-txt/css/generate-security-txt-admin.css?ver=generate-security-txt/css/jquery-ui.css?ver=generate-security-txt/js/generate-security-txt-admin.js?ver=HTML / DOM Fingerprints
data-page-name="security_txt_generator"window.securitytxt