
LLMs.txt Curator Security & Risk Analysis
wordpress.org/plugins/llms-txt-curatorCurate, score, and maintain your llms.txt with quality scoring, description suggestions, change detection, and AI crawler analytics.
Is LLMs.txt Curator Safe to Use in 2026?
Generally Safe
Score 100/100LLMs.txt Curator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "llms-txt-curator" plugin v1.4.6 demonstrates several positive security practices, including the exclusive use of prepared statements for all SQL queries and proper output escaping for all identified outputs. The absence of known vulnerabilities and a clean vulnerability history further suggest a generally well-maintained codebase. However, there are notable security concerns that detract from its overall security posture. Specifically, the plugin exposes two AJAX handlers that lack authentication checks, creating a potential attack vector for unauthorized actions. While the REST API routes are protected by permission callbacks, these unprotected AJAX endpoints represent a direct risk. The taint analysis, though limited in scope, identified flows with unsanitized paths, which, even without critical or high severity ratings in this analysis, warrant attention as they could be exploited under different conditions or with more complex inputs.
In conclusion, "llms-txt-curator" v1.4.6 exhibits strengths in its secure handling of database queries and output rendering. The lack of past vulnerabilities is a positive indicator. Nevertheless, the presence of unprotected AJAX endpoints introduces a significant security weakness that could be exploited. The identified unsanitized paths, even if currently low risk, highlight a potential area for improvement. These factors, combined, suggest a moderately secure plugin with specific, addressable vulnerabilities that require immediate attention to mitigate potential risks.
Key Concerns
- Unprotected AJAX handlers
- Taint flow with unsanitized paths
LLMs.txt Curator Security Vulnerabilities
LLMs.txt Curator Release Timeline
LLMs.txt Curator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
LLMs.txt Curator Attack Surface
AJAX Handlers 2
REST API Routes 4
WordPress Hooks 17
Scheduled Events 1
Maintenance & Trust
LLMs.txt Curator Maintenance & Trust
Maintenance Signals
Community Trust
LLMs.txt Curator Alternatives
GEO Pilot – AI Search Optimization & llms.txt
geo-pilot
Prepare your WordPress site for the AI Search era. Auto-generate a dynamic llms.txt file, optimize content for tokens, and rank in AI Overviews.
citelayer® – AI SEO & Visibility | llms.txt, Bot Analytics, Schema.org
citelayer
Get found by ChatGPT, Perplexity & AI search. AI Visibility, llms.txt, Schema.org — make your site the answer AI recommends.
LLMs.txt Generator – AI Visibility
aiready-llms-txt-generator
Generate and publish llms.txt for AI assistants like ChatGPT, Claude and Perplexity. Free standalone mode; Pro API mode adds WooCommerce drill-down.
GetCited — AI Visibility
getcited
Optimize for AI search. The AI visibility plugin — manage crawlers, generate llms.txt, track citability.
IA SEO Generator
ia-seo-generator
Make your site visible to AI: serve an AI-ready /llms.txt (no root). Appear in answers on ChatGPT, Perplexity, Claude, Gemini, Copilot, Comet.
LLMs.txt Curator Developer Profile
1 plugin · 0 total installs
How We Detect LLMs.txt Curator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/llms-txt-curator/assets/css/llms-txt-curator.css/wp-content/plugins/llms-txt-curator/assets/js/llms-txt-curator.js/wp-content/plugins/llms-txt-curator/assets/js/llms-txt-curator-admin.js/wp-content/plugins/llms-txt-curator/assets/css/llms-txt-curator-admin.css# Generated by LLMs.txt Curator for WordPressllms-txt-curator/assets/css/llms-txt-curator.css?ver=llms-txt-curator/assets/js/llms-txt-curator.js?ver=llms-txt-curator/assets/js/llms-txt-curator-admin.js?ver=llms-txt-curator/assets/css/llms-txt-curator-admin.css?ver=HTML / DOM Fingerprints
llms-txt-curator-admin-wrap<!-- Generated by LLMs.txt Curator for WordPress -->data-llmscu-actiondata-llmscu-page-iddata-llmscu-post-idllmscu_admin_paramsllmscu_generator_settings