
MCPner LLMs.txt Generator Security & Risk Analysis
wordpress.org/plugins/llms-txt-generator-by-mcpnerMake your website AI-ready with LLM-optimized content files. Generate llms.txt files for ChatGPT, Claude, and other AI systems.
Is MCPner LLMs.txt Generator Safe to Use in 2026?
Generally Safe
Score 100/100MCPner LLMs.txt Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "llms-txt-generator-by-mcpner" v1.4.5 exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. While the code analysis indicates a strong adherence to output escaping and a lack of dangerous functions or bundled libraries, the presence of 10 AJAX handlers without authentication checks represents a substantial attack surface that could be exploited by unauthenticated users. This is the most critical finding, as it allows for direct interaction with the plugin's core functionality without any form of verification.
Furthermore, the static analysis revealed that 100% of the detected SQL queries are not using prepared statements, posing a risk of SQL injection vulnerabilities. While taint analysis did not reveal any critical or high severity flows, the presence of unsanitized paths is a red flag that warrants attention, especially when combined with unescaped SQL queries. The vulnerability history is currently clean, with no recorded CVEs, which is a positive indicator. However, the code-level risks, particularly the unprotected AJAX endpoints and raw SQL queries, overshadow this positive aspect. The plugin shows good practices in output escaping and nonce checks, but the lack of authorization on the majority of its entry points is a severe deficiency that needs immediate remediation.
Key Concerns
- 100% AJAX handlers without auth checks
- 100% SQL queries without prepared statements
- 2 flows with unsanitized paths
MCPner LLMs.txt Generator Security Vulnerabilities
MCPner LLMs.txt Generator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
MCPner LLMs.txt Generator Attack Surface
AJAX Handlers 10
WordPress Hooks 17
Scheduled Events 1
Maintenance & Trust
MCPner LLMs.txt Generator Maintenance & Trust
Maintenance Signals
Community Trust
MCPner LLMs.txt Generator Alternatives
GEO Pilot – AI Search Optimization & llms.txt
geo-pilot
Prepare your WordPress site for the AI Search era. Auto-generate a dynamic llms.txt file, optimize content for tokens, and rank in AI Overviews.
CiteHQ
citehq
llms.txt for WordPress. Help ChatGPT, Claude & Perplexity discover and cite your content. One-click setup.
GetCited — AI Visibility
getcited
Optimize for AI search. The AI visibility plugin — manage crawlers, generate llms.txt, track citability.
IntentDeep Virtual Files – AI-Ready: Robots.txt, Security.txt, Ads.txt, LLMS.txt
intentdeep-virtual-files
Create robots.txt, ads.txt, security.txt, llms.txt & JSON files with AI-ready content generation (ChatGPT, Claude, Gemini) at any path. No FTP needed.
WB AI SEO
wb-ai-seo
Create and manage your /llms.txt file to help AI search engines like ChatGPT, Claude, and Perplexity understand your website.
MCPner LLMs.txt Generator Developer Profile
1 plugin · 80 total installs
How We Detect MCPner LLMs.txt Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/llms-txt-generator-by-mcpner/admin/css/mcpner-llmstxt-admin.css/wp-content/plugins/llms-txt-generator-by-mcpner/admin/js/mcpner-llmstxt-admin.jsllms-txt-generator-by-mcpner/admin/css/mcpner-llmstxt-admin.css?ver=llms-txt-generator-by-mcpner/admin/js/mcpner-llmstxt-admin.js?ver=HTML / DOM Fingerprints
mcpnerLLMSTxtAdmin