With a security.txt file, ethical hackers can easily send you a notification when they have found a vulnerability on your website.
As of April 2026, Generate Security.txt is a WordPress security plugin with 400 active installations and a 5/5 rating from 1 reviews. It has been downloaded 4.7K+ times in total. Requires WordPress 6.3+ and PHP false+. Available on WordPress.org since 2024. Actively maintained — updated within the last month. Support resolution rate: 0%. Top alternative: Wordfence Security – Firewall, Malware….
Security.txt is an open standard (RFC 9116) that allows ethical hackers and security researchers to contact you when they have found a vulnerability on your website.
The principle is simple and effective: contact information is put into a txt file and placed in a fixed location in your website’s directory structure (well-known folder). In this way, contact can easily be made.
This plugin helps you to create and place the security.txt file without any knowledge of the open standard. This makes you easily accessible in case something is wrong with your website.
This plugin is completely free to use and does not include any advertisements or paid version.
| WordPress | 6.3+ requiredTested up to 6.9.4 |
| PHP | false+ required |
Capability filter added
Nonce checks added
Pubkey store changed to .well-known directory
Archive.org request only for public websites
Plugin data sourced from WordPress.org. Analysis and metrics by PluginSift.