
WPBot Automator – Automation for WordPress Visual No-Code WorkFlow Builder Security & Risk Analysis
wordpress.org/plugins/wpbotAutomation plugin for WordPress with a visual no-code builder. Create automated workflows to connect WordPress, WooCommerce, WPForms, & more
Is WPBot Automator – Automation for WordPress Visual No-Code WorkFlow Builder Safe to Use in 2026?
Generally Safe
Score 100/100WPBot Automator – Automation for WordPress Visual No-Code WorkFlow Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wpbot' plugin v1.0.0 exhibits a generally good security posture with several strong practices. The code demonstrates a high level of output escaping (98%) and a significant portion of its SQL queries utilize prepared statements (44%), which helps mitigate common injection vulnerabilities. The absence of dangerous functions, file operations, and recorded historical vulnerabilities are also positive indicators. However, a notable concern is the presence of a REST API route lacking permission callbacks, creating a potential entry point that could be accessed without proper authorization. While taint analysis shows no critical or high severity unsanitized flows, this single unprotected REST API route warrants attention. The plugin's history of zero known CVEs is encouraging and suggests a history of secure development, but the single unprotected endpoint still represents a weakness in its otherwise robust security framework.
Key Concerns
- REST API route without permission callbacks
WPBot Automator – Automation for WordPress Visual No-Code WorkFlow Builder Security Vulnerabilities
WPBot Automator – Automation for WordPress Visual No-Code WorkFlow Builder Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPBot Automator – Automation for WordPress Visual No-Code WorkFlow Builder Attack Surface
AJAX Handlers 1
REST API Routes 9
WordPress Hooks 19
Maintenance & Trust
WPBot Automator – Automation for WordPress Visual No-Code WorkFlow Builder Maintenance & Trust
Maintenance Signals
Community Trust
WPBot Automator – Automation for WordPress Visual No-Code WorkFlow Builder Alternatives
Zapier for WordPress
zapier
Zapier saves you time on tedious tasks by moving info between WordPress and your other favorite apps, so you can focus on your most important work.
Zoho Flow – Integrate 100+ plugins with 1000+ business apps, no-code workflow automation
zoho-flow
Integrate your WordPress plugins with your business applications and automate workflows between them. A single platform for all your integrations.
theMarketer – Email marketing, Newsletters, Automation & Loyalty for Woocommerce
themarketer
Collect subscribers. Send newsletters. Create 1:1 personalised emails using dynamic blocks. Activate one of almost 30 predefined workflows.
Post Webhook – Send Post & Page data to any API or external service
post-webhook
Automate your content workflow by automatically sending post and page data to external services.
GoPublish: Publish from Google Docs to Any Site
gopublish-publish-from-google-docs-to-any-site
Publish directly from Google Docs™ to any website with SEO meta titles, descriptions, images, and format intact. Stop copy-pasting today!
WPBot Automator – Automation for WordPress Visual No-Code WorkFlow Builder Developer Profile
29 plugins · 26K total installs
How We Detect WPBot Automator – Automation for WordPress Visual No-Code WorkFlow Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpbot-automator/build/index.js/wp-content/plugins/wpbot-automator/build/index.css/wp-content/plugins/wpbot-automator/build/index.jswpbot-automator/build/index.asset.phpHTML / DOM Fingerprints
wpbot-automator-rootdata-enqueue-script="wpbot-automator-admin"wpbotAutomator/wpbot-automator/v1/workflows/wpbot-automator/v1/products/wpbot-automator/v1/test-action