Addlly AI – AI Content Writer and 1 Click AI Blog Generator Security & Risk Analysis

wordpress.org/plugins/addlly

Create SEO-optimized blogs in one click with the best AI writer for WordPress. Get topic suggestions, keywords, meta tags, FAQ schema.

0 active installs v1.0.2 PHP 7.4+ WP 5.0+ Updated Dec 19, 2024
ai-contentai-writercontent-creationcontent-generatorseo-optimization
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Addlly AI – AI Content Writer and 1 Click AI Blog Generator Safe to Use in 2026?

Generally Safe

Score 92/100

Addlly AI – AI Content Writer and 1 Click AI Blog Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'addlly' plugin v1.0.2 exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and vulnerabilities in its history is a positive indicator. Furthermore, the plugin demonstrates strong practices in SQL query handling, utilizing prepared statements exclusively, and a very high percentage (98%) of properly escaped output, minimizing the risk of cross-site scripting (XSS) vulnerabilities. The presence of nonce checks on all 29 AJAX handlers is also a significant strength, protecting against cross-site request forgery (CSRF) attacks.

However, there are a few areas that warrant attention. The plugin makes 3 external HTTP requests, which, while not inherently a vulnerability, can be a vector for potential issues if the external endpoints are compromised or if the data sent is not handled securely. More critically, the taint analysis revealed 9 flows with unsanitized paths, and while classified as not critical or high severity in this analysis, unsanitized paths can often lead to unexpected behavior or potential exploits, especially when combined with other factors. The absence of capability checks on its numerous AJAX handlers is a notable concern; while nonces prevent CSRF, they do not restrict which user roles can trigger these actions. A privileged user might be able to exploit an AJAX action intended for lower-privileged users if capability checks are missing.

In conclusion, 'addlly' v1.0.2 has several strong security features, particularly in its SQL and output handling, and its lack of past vulnerabilities is promising. The main areas for improvement lie in the implementation of capability checks for its AJAX actions to ensure proper authorization, and a closer review of the 9 taint flows with unsanitized paths to confirm their low risk in practice. The external HTTP requests should also be monitored for any security implications.

Key Concerns

  • 9 taint flows with unsanitized paths
  • No capability checks on AJAX handlers
  • 3 external HTTP requests
Vulnerabilities
None known

Addlly AI – AI Content Writer and 1 Click AI Blog Generator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Addlly AI – AI Content Writer and 1 Click AI Blog Generator Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Addlly AI – AI Content Writer and 1 Click AI Blog Generator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
531 escaped
Nonce Checks
29
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

98% escaped541 total outputs
Data Flows · Security
9 unsanitized

Data Flow Analysis

9 flows9 with unsanitized paths
addlly_regenerate_content_callback (inc\ajax-functions.php:373)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Addlly AI – AI Content Writer and 1 Click AI Blog Generator Attack Surface

Entry Points29
Unprotected0

AJAX Handlers 29

authwp_ajax_addlly_generate_bloginc\ajax-functions.php:67
authwp_ajax_addlly_save_articleinc\ajax-functions.php:253
authwp_ajax_addlly_regenerate_contentinc\ajax-functions.php:371
authwp_ajax_addlly_generate_faqschemainc\ajax-functions.php:482
authwp_ajax_addlly_generate_googleAdCopyinc\ajax-functions.php:528
authwp_ajax_addlly_generate_socialContentinc\ajax-functions.php:574
authwp_ajax_addlly_generate_hashtagsinc\ajax-functions.php:621
authwp_ajax_addlly_train_articleinc\ajax-functions.php:688
authwp_ajax_addlly_get_img_base64inc\ajax-functions.php:756
authwp_ajax_addlly_auto_citationinc\ajax-functions.php:773
authwp_ajax_addlly_send_refund_requestinc\ajax-functions.php:844
authwp_ajax_addlly_get_article_refund_requestsinc\ajax-functions.php:896
authwp_ajax_addlly_get_version_historyinc\ajax-functions.php:919
authwp_ajax_addlly_article_previewinc\ajax-functions.php:948
authwp_ajax_addlly_get_or_generate_ai_imagesinc\ajax-functions.php:972
authwp_ajax_addlly_get_ai_generated_imagesinc\ajax-functions.php:1052
authwp_ajax_addlly_archive_articleinc\ajax-functions.php:1180
authwp_ajax_addlly_delete_articleinc\ajax-functions.php:1241
authwp_ajax_addlly_get_free_imagesinc\ajax-functions.php:1296
authwp_ajax_addlly_search_free_imagesinc\ajax-functions.php:1376
authwp_ajax_addlly_get_uploaded_imagesinc\ajax-functions.php:1424
authwp_ajax_addlly_save_upload_imagesinc\ajax-functions.php:1476
authwp_ajax_addlly_save_social_post_imageinc\ajax-functions.php:1561
authwp_ajax_addlly_search_articlesinc\ajax-functions.php:1624
authwp_ajax_addlly_logininc\ajax-functions.php:1852
authwp_ajax_addlly_search_refunds_listinc\ajax-functions.php:1969
authwp_ajax_addlly_upload_aibrand_imagesinc\ajax-functions.php:2004
authwp_ajax_addlly_get_aibrand_imagesinc\ajax-functions.php:2126
authwp_ajax_addlly_get_topic_suggestionsinc\ajax-functions.php:2251
WordPress Hooks 10
actionadmin_initaddlly.php:30
actionadmin_initaddlly.php:31
actionplugins_loadedaddlly.php:32
actionadmin_menuaddlly.php:34
actionadmin_enqueue_scriptsaddlly.php:35
actionwp_headaddlly.php:39
actionadmin_menuclasses\one-click-blog-writer.php:10
filterposts_whereinc\ajax-functions.php:1742
filterposts_whereinc\ajax-functions.php:1825
filterwp_kses_allowed_htmlinc\helpers.php:358
Maintenance & Trust

Addlly AI – AI Content Writer and 1 Click AI Blog Generator Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 19, 2024
PHP min version7.4
Downloads913

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

Addlly AI – AI Content Writer and 1 Click AI Blog Generator Developer Profile

addlly

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Addlly AI – AI Content Writer and 1 Click AI Blog Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/addlly/assets/lib/css/bootstrap.min.css/wp-content/plugins/addlly/assets/lib/css/sweetalert.min.css/wp-content/plugins/addlly/assets/lib/css/toastr.min.css/wp-content/plugins/addlly/assets/css/admin.css/wp-content/plugins/addlly/assets/css/social-media-posts.css/wp-content/plugins/addlly/assets/css/tinymceEditor.css/wp-content/plugins/addlly/assets/lib/js/bootstrap.min.js/wp-content/plugins/addlly/assets/lib/js/sweetalert.min.js+5 more
Script Paths
/wp-content/plugins/addlly/assets/lib/js/bootstrap.min.js/wp-content/plugins/addlly/assets/lib/js/sweetalert.min.js/wp-content/plugins/addlly/assets/lib/js/toastr.min.js/wp-content/plugins/addlly/assets/js/addlly.js/wp-content/plugins/addlly/assets/js/addlly-tinymce-editor.js/wp-content/plugins/addlly/assets/js/social-media-posts.js+1 more
Version Parameters
addlly/assets/lib/css/bootstrap.min.css?ver=addlly/assets/lib/css/sweetalert.min.css?ver=addlly/assets/lib/css/toastr.min.css?ver=addlly/assets/css/admin.css?ver=addlly/assets/css/social-media-posts.css?ver=addlly/assets/css/tinymceEditor.css?ver=addlly/assets/lib/js/bootstrap.min.js?ver=addlly/assets/lib/js/sweetalert.min.js?ver=addlly/assets/lib/js/toastr.min.js?ver=addlly/assets/js/addlly.js?ver=addlly/assets/js/addlly-tinymce-editor.js?ver=addlly/assets/js/social-media-posts.js?ver=addlly/assets/js/one-click-blog-writer.js?ver=

HTML / DOM Fingerprints

CSS Classes
addlly-contentaddlly-logoaddlly-main-navaddlly-nav-linkaddlly-post-titleaddlly-post-content
Data Attributes
data-addlly-modal
JS Globals
AddllyAdminaddllyaddlly_paramsaddlly_tinymce_paramsaddlly_one_click_paramsaddlly_social_media_params
FAQ

Frequently Asked Questions about Addlly AI – AI Content Writer and 1 Click AI Blog Generator