iRobots.txt SEO Security & Risk Analysis

wordpress.org/plugins/irobotstxt-seo

iRobots.txt SEO is a SEO optimized, secure and customizable robots.txt virtual file creator.

300 active installs v1.1.2 PHP + WP 2.7+ Updated Jun 13, 2010
robotrobots-txtseosite-mapsitemap
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEJan 20, 2026
Safety Verdict

Is iRobots.txt SEO Safe to Use in 2026?

Use With Caution

Score 63/100

iRobots.txt SEO has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jan 20, 2026Updated 15yr ago
Risk Assessment

The irobotstxt-seo plugin, version 1.1.2, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by not exposing a significant attack surface through AJAX, REST API, shortcodes, or cron events, and all identified SQL queries utilize prepared statements. Furthermore, the taint analysis indicates no critical or high severity flows with unsanitized paths. However, a major concern is the complete lack of output escaping for all 21 identified output points. This suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site's output.

The plugin's vulnerability history reveals a past medium-severity Cross-Site Scripting vulnerability, which aligns with the static analysis findings regarding unescaped output. The fact that this vulnerability is listed as currently unpatched and has a future dated "last vulnerability" of 2026-01-20 is highly concerning and likely indicates a data entry error in the provided history. Assuming this points to a real, unpatched vulnerability, it significantly elevates the risk. The absence of capability checks is also a weakness, as it means actions performed by the plugin may not be properly restricted to authorized users.

In conclusion, while the plugin avoids common entry point vulnerabilities and uses prepared statements for database operations, the pervasive lack of output escaping and the presence of at least one unpatched medium-severity vulnerability represent significant security risks. The future date for the last vulnerability is a red flag that warrants further investigation, but based on the provided data, a user of this plugin should be aware of potential XSS and unauthorized access issues.

Key Concerns

  • Unpatched CVE (Medium Severity)
  • All outputs unescaped
  • No capability checks
Vulnerabilities
1

iRobots.txt SEO Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-68840medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

iRobots.txt SEO <= 1.1.2 - Reflected Cross-Site Scripting

Jan 20, 2026Unpatched
Code Analysis
Analyzed Mar 16, 2026

iRobots.txt SEO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
0 escaped
Nonce Checks
5
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped21 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<irobotstxt-seo> (irobotstxt-seo.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

iRobots.txt SEO Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedirobotstxt-seo.php:27
actioninitirobotstxt-seo.php:28
actionadmin_menuirobotstxt-seo.php:32
filterplugin_action_linksirobotstxt-seo.php:33
Maintenance & Trust

iRobots.txt SEO Maintenance & Trust

Maintenance Signals

WordPress version tested2.9.2
Last updatedJun 13, 2010
PHP min version
Downloads34K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

iRobots.txt SEO Developer Profile

markbeljaars

2 plugins · 700 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect iRobots.txt SEO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- Generated by iRobots.txt SEO -->
FAQ

Frequently Asked Questions about iRobots.txt SEO