JumpsuitAI – llms.txt + Markdown Endpoints Security & Risk Analysis

wordpress.org/plugins/jumpsuitai-llms-txt

Generate /llms.txt, /llms-full.txt & .md endpoints for AI/LLMs in WordPress. Works with Yoast SEO, Rank Math, SEOPress & All in One SEO.

100 active installs v1.1.4 PHP 7.2+ WP 5.0+ Updated Feb 17, 2026
aicontent-discoveryllms-txtmarkdownseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is JumpsuitAI – llms.txt + Markdown Endpoints Safe to Use in 2026?

Generally Safe

Score 100/100

JumpsuitAI – llms.txt + Markdown Endpoints has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The jumpsuit-llms-txt plugin v1.1.4 exhibits a generally good security posture with no known vulnerabilities recorded and a strong emphasis on prepared SQL statements and capability checks. The absence of an attack surface from AJAX handlers, REST API routes, shortcodes, and cron events is a significant positive, as is the complete lack of external HTTP requests and file operations, which eliminates common attack vectors. However, the presence of one dangerous function, `preg_replace(/e)`, warrants attention. While no unsanitized taint flows were identified, this function, if not handled with extreme care, can be a source of regular expression denial-of-service (ReDoS) vulnerabilities or unintended code execution if user-supplied data is not properly validated and escaped before being passed to it. The 65% output escaping rate, while not critically low, suggests there's room for improvement to prevent potential cross-site scripting (XSS) vulnerabilities in the remaining 35% of outputs.

Despite the single dangerous function and slightly lower than ideal output escaping, the plugin's robust use of prepared statements, nonce checks, and capability checks, combined with its zero-known CVE history, suggests a conscious effort towards secure coding. The bundled Freemius library, while present, is also a standard component and its version (v1.0) is not flagged as inherently problematic without further context on its specific usage and known vulnerabilities. Overall, the plugin is in a relatively strong security state, but the noted `preg_replace(/e)` usage and the output escaping percentage are areas that could be further scrutinized and hardened to achieve an even higher level of security.

Key Concerns

  • Dangerous function: preg_replace(/e)
  • Output escaping: 65% properly escaped
Vulnerabilities
None known

JumpsuitAI – llms.txt + Markdown Endpoints Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

JumpsuitAI – llms.txt + Markdown Endpoints Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
12 prepared
Unescaped Output
44
83 escaped
Nonce Checks
4
Capability Checks
7
File Operations
0
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

preg_replace(/e)preg_replace( '#<em[^>]*>(.*?)</ejumpsuitai-llms-txt.php:897

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared12 total queries

Output Escaping

65% escaped127 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
handle_import_settings (jumpsuitai-llms-txt.php:1769)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

JumpsuitAI – llms.txt + Markdown Endpoints Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionafter_uninstalljumpsuitai-llms-txt.php:114
actioninitjumpsuitai-llms-txt.php:219
actioninitjumpsuitai-llms-txt.php:221
actioninitjumpsuitai-llms-txt.php:222
filterquery_varsjumpsuitai-llms-txt.php:223
actioninitjumpsuitai-llms-txt.php:224
actiontemplate_redirectjumpsuitai-llms-txt.php:226
actionadmin_menujumpsuitai-llms-txt.php:228
actionadmin_initjumpsuitai-llms-txt.php:229
actionadmin_initjumpsuitai-llms-txt.php:230
actionadmin_post_jsai_llmstxt_save_assignmentsjumpsuitai-llms-txt.php:231
actionadmin_post_jsai_llmstxt_assign_untaggedjumpsuitai-llms-txt.php:232
actionadmin_post_jsai_llmstxt_importjumpsuitai-llms-txt.php:233
actionadd_meta_boxesjumpsuitai-llms-txt.php:236
actionsave_postjumpsuitai-llms-txt.php:237
actionsave_postjumpsuitai-llms-txt.php:243
Maintenance & Trust

JumpsuitAI – llms.txt + Markdown Endpoints Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 17, 2026
PHP min version7.2
Downloads653

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

JumpsuitAI – llms.txt + Markdown Endpoints Developer Profile

Brad Phillips

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect JumpsuitAI – llms.txt + Markdown Endpoints

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jumpsuitai-llms-txt/js/freemius.js/wp-content/plugins/jumpsuitai-llms-txt/js/public.js
Script Paths
/wp-content/plugins/jumpsuitai-llms-txt/js/freemius.js/wp-content/plugins/jumpsuitai-llms-txt/js/public.js
Version Parameters
jumpsuitai-llms-txt/js/freemius.js?ver=jumpsuitai-llms-txt/js/public.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- JumpsuitAI – llms.txt + Markdown Endpoints -->
REST Endpoints
/wp-json/jumpsuitai-llms-txt/v1/llms/wp-json/jumpsuitai-llms-txt/v1/markdown
FAQ

Frequently Asked Questions about JumpsuitAI – llms.txt + Markdown Endpoints