
security-txt Security & Risk Analysis
wordpress.org/plugins/security-txtA plugin for serving 'security.txt' in WordPress 6.1.1+.
Is security-txt Safe to Use in 2026?
Generally Safe
Score 85/100security-txt has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'security-txt' plugin v1.0.6 exhibits a very strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface points, dangerous functions, or unsanitized taint flows is a significant positive indicator. Furthermore, the exclusive use of prepared statements for SQL queries and proper output escaping demonstrates a commitment to secure coding practices in these critical areas.
The plugin's history is equally commendable, with no known CVEs, patched or unpatched. This lack of historical vulnerabilities suggests either a very robust development process or a less appealing target for attackers, though the former is more likely given the other positive indicators. The limited file operations and lack of external HTTP requests also contribute to a reduced attack surface.
While the plugin's current state appears highly secure, it's worth noting the complete absence of nonces and capability checks. For a plugin with zero entry points and no external interactions, this might not pose an immediate risk. However, as plugins evolve or their intended functionality expands, these could become crucial for maintaining security. Overall, 'security-txt' v1.0.6 demonstrates excellent security practices, with minimal to no immediate security concerns identified in the provided data.
security-txt Security Vulnerabilities
security-txt Code Analysis
Output Escaping
security-txt Attack Surface
WordPress Hooks 3
Maintenance & Trust
security-txt Maintenance & Trust
Maintenance Signals
Community Trust
security-txt Alternatives
wp-security-txt
wp-security-txt
A plugin for serving 'security.txt' in WordPress 4.9+, based on configuration settings.
Security.txt Manager
security-txt-manager
Create and manage your security.txt from within WordPress. The easiest way to manage security policy.
Generate Security.txt
generate-security-txt
With a security.txt file, ethical hackers can easily send you a notification when they have found a vulnerability on your website.
Wordfence Security – Firewall, Malware Scan, and Login Security
wordfence
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.
Hostinger Tools
hostinger
Simplified WordPress management. Manage site info, maintenance, security, & redirects.
security-txt Developer Profile
1 plugin · 10 total installs
How We Detect security-txt
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
securitytxt_form_funcSecurity TXT is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 2 of the License, or
any later version.Security TXT is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.You should have received a copy of the GNU General Public License
along with Security TXT. If not, see https://www.gnu.org/licenses/gpl-3.0.en.html.name="sdottxt_content"name="sdottxt_delete_data"value="Yes"value="No"