
wp-security-txt Security & Risk Analysis
wordpress.org/plugins/wp-security-txtA plugin for serving 'security.txt' in WordPress 4.9+, based on configuration settings.
Is wp-security-txt Safe to Use in 2026?
Generally Safe
Score 85/100wp-security-txt has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-security-txt plugin v1.0.0 exhibits an excellent security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events means the plugin has a minimal attack surface, with no apparent entry points that could be exploited. The code also demonstrates strong security practices, with all SQL queries using prepared statements and a very low number of file operations and external HTTP requests, which are generally well-handled. The lack of known CVEs and a clean vulnerability history further bolster its security profile, suggesting diligent development and adherence to security best practices.
Key Concerns
- Output escaping is not fully implemented
- No capability checks implemented
- No nonce checks implemented
wp-security-txt Security Vulnerabilities
wp-security-txt Code Analysis
Output Escaping
wp-security-txt Attack Surface
WordPress Hooks 10
Maintenance & Trust
wp-security-txt Maintenance & Trust
Maintenance Signals
Community Trust
wp-security-txt Alternatives
security-txt
security-txt
A plugin for serving 'security.txt' in WordPress 6.1.1+.
Security.txt Manager
security-txt-manager
Create and manage your security.txt from within WordPress. The easiest way to manage security policy.
Generate Security.txt
generate-security-txt
With a security.txt file, ethical hackers can easily send you a notification when they have found a vulnerability on your website.
Wordfence Security – Firewall, Malware Scan, and Login Security
wordfence
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.
Hostinger Tools
hostinger
Simplified WordPress management. Manage site info, maintenance, security, & redirects.
wp-security-txt Developer Profile
1 plugin · 60 total installs
How We Detect wp-security-txt
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-security-txt/admin/css/wp-security-txt-admin.css/wp-content/plugins/wp-security-txt/admin/js/wp-security-txt-repeater.min.js/wp-content/plugins/wp-security-txt/admin/js/wp-security-txt-validator.js/wp-content/plugins/wp-security-txt/admin/js/wp-security-txt-admin.js/wp-content/plugins/wp-security-txt/admin/js/wp-security-txt-repeater.min.js/wp-content/plugins/wp-security-txt/admin/js/wp-security-txt-validator.js/wp-content/plugins/wp-security-txt/admin/js/wp-security-txt-admin.jswp-security-txt-admin.css?ver=wp-security-txt-repeater.min.js?ver=wp-security-txt-validator.js?ver=wp-security-txt-admin.js?ver=HTML / DOM Fingerprints
<!-- The options-general.php menu uses the plugin slug for the ID --><!-- The options-general.php menu uses the plugin slug for the ID -->