So now botghost is doing a pentest. But I dunno... my guess at the likelihood of doing a good job backfilling security into a codebase that wasn't built with that as a core concern is also low.
I suppose they could have logged only if a bot token was detected in output. But if you'd think to do that, then why not also just block the output?
Comprehensively unaware of the GDPR enforcement process also.
What will you google next, I wonder?