LLMs.txt and LLMs-Full.txt Generator Security & Risk Analysis

wordpress.org/plugins/llms-full-txt-generator

Generate llms.txt and llms-full.txt files for WordPress to guide AI and LLMs. Fully compatible with Yoast SEO, Rank Math, SEOPress, and All in One SEO …

3K active installs v2.0.7 PHP 7.0+ WP 5.0+ Updated Mar 13, 2026
ai-llmllmsrankmathseotxt-generator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is LLMs.txt and LLMs-Full.txt Generator Safe to Use in 2026?

Generally Safe

Score 100/100

LLMs.txt and LLMs-Full.txt Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "llms-full-txt-generator" plugin v2.0.7 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, the consistent use of prepared statements for SQL queries, and proper output escaping are strong indicators of secure coding practices. Furthermore, the plugin doesn't appear to have any known vulnerabilities or a history of past security issues, suggesting a history of responsible development and maintenance.

However, the static analysis does reveal a few areas that warrant attention. The lack of nonce checks for any of its entry points, including its REST API routes, presents a potential security concern. While capability checks are present for some REST API routes, the absence of nonces means that attackers could potentially replay requests or craft malicious requests that might be executed without proper session validation. The presence of file operations and external HTTP requests, while not inherently insecure, always carries a degree of risk if not handled with extreme care regarding user-supplied input or untrusted data sources.

Overall, the plugin is well-coded in many aspects. The main area for improvement lies in the implementation of nonce checks to further bolster its security against various attack vectors. The vulnerability history is a positive sign, but the existing entry points, particularly the REST API routes, should be re-evaluated for nonce protection to ensure robust security.

Key Concerns

  • No nonce checks on entry points
  • Capability checks present but no nonces on REST API
Vulnerabilities
None known

LLMs.txt and LLMs-Full.txt Generator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

LLMs.txt and LLMs-Full.txt Generator Release Timeline

v2.0.2
v2.0.1
v2.0
v1.9
Code Analysis
Analyzed Mar 16, 2026

LLMs.txt and LLMs-Full.txt Generator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
3
File Operations
4
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped4 total outputs
Attack Surface

LLMs.txt and LLMs-Full.txt Generator Attack Surface

Entry Points5
Unprotected0

REST API Routes 5

GET/wp-json/llms/v1/initial_config/includes\class-llms-license.php:16
POST/wp-json/llms/v1/update_licence_key/includes\class-llms-license.php:22
GETPOST/wp-json/llms/v1/settingsincludes\class-llms-rest-api.php:13
POST/wp-json/llms/v1/generateincludes\class-llms-rest-api.php:19
POST/wp-json/llms/v1/delete/(?P<file>[\w\.\-]+)includes\class-llms-rest-api.php:25
WordPress Hooks 9
actionadmin_menuincludes\class-llms-admin.php:6
actionadmin_enqueue_scriptsincludes\class-llms-admin.php:7
actionadmin_initincludes\class-llms-admin.php:8
actionupdate_option_llms_full_txt_generator_update_frequencyincludes\class-llms-generator.php:12
actionrest_api_initincludes\class-llms-license.php:11
actionbefore_woocommerce_initincludes\class-llms-loader.php:26
filtercron_schedulesincludes\class-llms-loader.php:27
actionrest_api_initincludes\class-llms-rest-api.php:8
actionbefore_woocommerce_initllms-txt-generator.php:23
Maintenance & Trust

LLMs.txt and LLMs-Full.txt Generator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 13, 2026
PHP min version7.0
Downloads27K

Community Trust

Rating90/100
Number of ratings8
Active installs3K
Developer Profile

LLMs.txt and LLMs-Full.txt Generator Developer Profile

rankth

1 plugin · 3K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LLMs.txt and LLMs-Full.txt Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/llms-full-txt-generator/build/index.js/wp-content/plugins/llms-full-txt-generator/build/index.css
Script Paths
/wp-content/plugins/llms-full-txt-generator/build/index.js
Version Parameters
llms-full-txt-generator/build/index.css?ver=llms-full-txt-generator/build/index.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="llms-react-root"
JS Globals
window.llmsData
REST Endpoints
/wp-json/llms/v1/initial_config//wp-json/llms/v1/update_licence_key/
FAQ

Frequently Asked Questions about LLMs.txt and LLMs-Full.txt Generator