Robots.txt Extender Security & Risk Analysis

wordpress.org/plugins/robots-txt-extender

Dynamic robots.txt for Multisite! Change parameters, or don't, for each site of your network without losing the defaults from WordPress Includes.

10 active installs v1.0.0 PHP 7.0+ WP 5.0+ Updated Aug 22, 2020
crawlerrobotsrobots-txtrobotstxtspiders
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Robots.txt Extender Safe to Use in 2026?

Generally Safe

Score 85/100

Robots.txt Extender has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "robots-txt-extender" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. There are no identified entry points for external interaction such as AJAX handlers, REST API routes, or shortcodes, which significantly reduces the plugin's attack surface. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests, coupled with the use of prepared statements for all SQL queries, suggests adherence to secure coding practices. The lack of any historical vulnerabilities also points to a history of responsible development and maintenance.

However, a critical concern arises from the output escaping analysis, where 100% of outputs are not properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized data displayed to users could contain malicious scripts. While the plugin's limited attack surface and clean vulnerability history are positive, the lack of output escaping represents a significant security weakness that could be exploited. Developers should prioritize addressing this deficiency to mitigate potential XSS risks.

Key Concerns

  • Outputs not properly escaped
Vulnerabilities
None known

Robots.txt Extender Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Robots.txt Extender Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Robots.txt Extender Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_initrobots-txt-extender.php:98
filterrobots_txtrobots-txt-extender.php:99
Maintenance & Trust

Robots.txt Extender Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedAug 22, 2020
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Robots.txt Extender Developer Profile

bettoadami

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Robots.txt Extender

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
code
Data Attributes
robotsTxtExtender_settingsCode
FAQ

Frequently Asked Questions about Robots.txt Extender