
Addlly AI – AI Content Writer and 1 Click AI Blog Generator Security & Risk Analysis
wordpress.org/plugins/addllyCreate SEO-optimized blogs in one click with the best AI writer for WordPress. Get topic suggestions, keywords, meta tags, FAQ schema.
Is Addlly AI – AI Content Writer and 1 Click AI Blog Generator Safe to Use in 2026?
Generally Safe
Score 92/100Addlly AI – AI Content Writer and 1 Click AI Blog Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'addlly' plugin v1.0.2 exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and vulnerabilities in its history is a positive indicator. Furthermore, the plugin demonstrates strong practices in SQL query handling, utilizing prepared statements exclusively, and a very high percentage (98%) of properly escaped output, minimizing the risk of cross-site scripting (XSS) vulnerabilities. The presence of nonce checks on all 29 AJAX handlers is also a significant strength, protecting against cross-site request forgery (CSRF) attacks.
However, there are a few areas that warrant attention. The plugin makes 3 external HTTP requests, which, while not inherently a vulnerability, can be a vector for potential issues if the external endpoints are compromised or if the data sent is not handled securely. More critically, the taint analysis revealed 9 flows with unsanitized paths, and while classified as not critical or high severity in this analysis, unsanitized paths can often lead to unexpected behavior or potential exploits, especially when combined with other factors. The absence of capability checks on its numerous AJAX handlers is a notable concern; while nonces prevent CSRF, they do not restrict which user roles can trigger these actions. A privileged user might be able to exploit an AJAX action intended for lower-privileged users if capability checks are missing.
In conclusion, 'addlly' v1.0.2 has several strong security features, particularly in its SQL and output handling, and its lack of past vulnerabilities is promising. The main areas for improvement lie in the implementation of capability checks for its AJAX actions to ensure proper authorization, and a closer review of the 9 taint flows with unsanitized paths to confirm their low risk in practice. The external HTTP requests should also be monitored for any security implications.
Key Concerns
- 9 taint flows with unsanitized paths
- No capability checks on AJAX handlers
- 3 external HTTP requests
Addlly AI – AI Content Writer and 1 Click AI Blog Generator Security Vulnerabilities
Addlly AI – AI Content Writer and 1 Click AI Blog Generator Release Timeline
Addlly AI – AI Content Writer and 1 Click AI Blog Generator Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Addlly AI – AI Content Writer and 1 Click AI Blog Generator Attack Surface
AJAX Handlers 29
WordPress Hooks 10
Maintenance & Trust
Addlly AI – AI Content Writer and 1 Click AI Blog Generator Maintenance & Trust
Maintenance Signals
Community Trust
Addlly AI – AI Content Writer and 1 Click AI Blog Generator Alternatives
SmartScript AI
smartscript-ai
An AI-powered WordPress plugin that generates content directly within your post editor using OpenAI's GPT-3 technology.
BotWriter – AI Writer & Content Generator
botwriter
AI Writer & content generator for WordPress & WooCommerce. Auto blogging, AI writing plugin, product descriptions and SEO content.
AI Content Generator For Elementor
ai-auto-content-generator-for-elementor
Create and improve Elementor content instantly using Chrome’s built-in AI. Generate, rewrite, and optimize text directly in the editor.
Easy GPT for WP | AI Content Generator
easy-gpt-for-wp
Generate SEO content for WordPress with GPT models from OpenAI, DeepSeek and Gemini. Includes auto updates, translations, moderation, Yoast & WooC …
AiContify
aicontify
A free AI-powered plugin for generating high-quality content directly in the WordPress editor using the AiContify AI model.
Addlly AI – AI Content Writer and 1 Click AI Blog Generator Developer Profile
1 plugin · 0 total installs
How We Detect Addlly AI – AI Content Writer and 1 Click AI Blog Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/addlly/assets/lib/css/bootstrap.min.css/wp-content/plugins/addlly/assets/lib/css/sweetalert.min.css/wp-content/plugins/addlly/assets/lib/css/toastr.min.css/wp-content/plugins/addlly/assets/css/admin.css/wp-content/plugins/addlly/assets/css/social-media-posts.css/wp-content/plugins/addlly/assets/css/tinymceEditor.css/wp-content/plugins/addlly/assets/lib/js/bootstrap.min.js/wp-content/plugins/addlly/assets/lib/js/sweetalert.min.js+5 more/wp-content/plugins/addlly/assets/lib/js/bootstrap.min.js/wp-content/plugins/addlly/assets/lib/js/sweetalert.min.js/wp-content/plugins/addlly/assets/lib/js/toastr.min.js/wp-content/plugins/addlly/assets/js/addlly.js/wp-content/plugins/addlly/assets/js/addlly-tinymce-editor.js/wp-content/plugins/addlly/assets/js/social-media-posts.js+1 moreaddlly/assets/lib/css/bootstrap.min.css?ver=addlly/assets/lib/css/sweetalert.min.css?ver=addlly/assets/lib/css/toastr.min.css?ver=addlly/assets/css/admin.css?ver=addlly/assets/css/social-media-posts.css?ver=addlly/assets/css/tinymceEditor.css?ver=addlly/assets/lib/js/bootstrap.min.js?ver=addlly/assets/lib/js/sweetalert.min.js?ver=addlly/assets/lib/js/toastr.min.js?ver=addlly/assets/js/addlly.js?ver=addlly/assets/js/addlly-tinymce-editor.js?ver=addlly/assets/js/social-media-posts.js?ver=addlly/assets/js/one-click-blog-writer.js?ver=HTML / DOM Fingerprints
addlly-contentaddlly-logoaddlly-main-navaddlly-nav-linkaddlly-post-titleaddlly-post-contentdata-addlly-modalAddllyAdminaddllyaddlly_paramsaddlly_tinymce_paramsaddlly_one_click_paramsaddlly_social_media_params