
CrawlForMe Security & Risk Analysis
wordpress.org/plugins/wp-crawlformeEasily check your wordpress blog whenever you want to find any broken links. This plugin uses the CrawlForMe plateform.
Is CrawlForMe Safe to Use in 2026?
Generally Safe
Score 85/100CrawlForMe has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-crawlforme" v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates an absence of known CVEs and a clean vulnerability history, suggesting good development practices or a lack of discovered vulnerabilities to date. The static analysis reveals no direct attack surface through common entry points like AJAX, REST API, shortcodes, or cron events. It also reports no dangerous functions, file operations, or external HTTP requests, which are generally positive indicators.
However, significant concerns arise from the code analysis regarding data handling and security checks. The plugin executes a single SQL query that is not using prepared statements, which is a critical vulnerability risk that could lead to SQL injection. Furthermore, a substantial number of output operations (61) are not properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. While nonce and capability checks are present, their limited number in relation to the output operations suggests a potential gap in comprehensive security validation for user-generated or dynamic content.
In conclusion, while the plugin benefits from a clean vulnerability history and a lack of exposed attack vectors, the identified raw SQL query and widespread unescaped output are serious security flaws. These weaknesses, if exploited, could lead to data breaches and site compromise. Developers should prioritize addressing the SQL injection and XSS vulnerabilities immediately. The absence of critical or high severity taint flows is a positive, but the static analysis findings are too significant to ignore.
Key Concerns
- SQL query without prepared statements
- High percentage of unescaped output
CrawlForMe Security Vulnerabilities
CrawlForMe Code Analysis
SQL Query Safety
Output Escaping
CrawlForMe Attack Surface
WordPress Hooks 2
Maintenance & Trust
CrawlForMe Maintenance & Trust
Maintenance Signals
Community Trust
CrawlForMe Alternatives
SEO Repair Kit – AI Chatbot, Schema Manager, SEO Content Monitoring, GSC Integration, Keyword & Rank Tracking
seo-repair-kit
The ultimate WordPress plugin for SEO automation - from link fixing to AI-powered schema generation and chatbot support.
CubeMage Smart Link Checker
cubemage-smart-link-checker
A lightweight broken link checker for WordPress. Detects 404 errors, monitors affiliate links, and scans content with adjustable server load settings.
Link Checker Professional
link-checker
An easy to use link checker for WordPress to detect broken links and images on your website.
Check for Broken Links
check-for-broken-links
Check for Broken Links is a WordPress plugin that helps you find and fix broken links on your website.
Broken Links Repair By Hexometer
broken-link-repair
Broken Links Repair Plugin disables the bad links in your content immediately upon detection by Hexometer.com scanner.
CrawlForMe Developer Profile
3 plugins · 30 total installs
How We Detect CrawlForMe
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-crawlforme/css/wp_crawlforme-admin.css/wp-content/plugins/wp-crawlforme/css/wp_crawlforme.css/wp-content/plugins/wp-crawlforme/js/wp_crawlforme-admin.js/wp-content/plugins/wp-crawlforme/js/wp_crawlforme.js/wp-content/plugins/wp-crawlforme/js/wp_crawlforme.js/wp-content/plugins/wp-crawlforme/js/wp_crawlforme-admin.jswp-crawlforme/css/wp_crawlforme-admin.css?ver=wp-crawlforme/css/wp_crawlforme.css?ver=wp-crawlforme/js/wp_crawlforme-admin.js?ver=wp-crawlforme/js/wp_crawlforme.js?ver=HTML / DOM Fingerprints
wp_crawlforme-admin-formdata-wp_crawlforme_rest_urlwp_crawlforme_settingswp_crawlforme_plugin_url/wp-json/wp_crawlforme/v1/settings