
AI Security & Risk Analysis
wordpress.org/plugins/aiAI features, experiments and capabilities for WordPress.
Is AI Safe to Use in 2026?
Generally Safe
Score 100/100AI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'ai' plugin version 0.5.0 demonstrates a generally strong security posture, with robust use of WordPress security features like nonce and capability checks. The plugin also avoids common pitfalls such as dangerous function usage and external HTTP requests. Its SQL queries are exclusively prepared, and a high percentage of output is properly escaped, indicating a good understanding of secure coding practices.
However, a significant concern arises from the taint analysis, which identified one flow with an unsanitized path. While this did not result in a high or critical severity finding and there are no recorded vulnerabilities, it represents a potential avenue for malicious input if not handled carefully. The presence of file operations without further context also warrants attention, as these can sometimes be associated with insecure practices if not implemented with strict sanitization and validation.
Given the complete absence of known vulnerabilities and a proactive approach to security features, the plugin is relatively safe. The primary weakness lies in the single unsanitized path identified in the taint analysis. This plugin is a good example of a developer who understands many security principles, but there's a specific area that needs verification to ensure it doesn't become a point of exploitation.
Key Concerns
- Flow with unsanitized path found
AI Security Vulnerabilities
AI Release Timeline
AI Code Analysis
Output Escaping
Data Flow Analysis
AI Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 33
Maintenance & Trust
AI Maintenance & Trust
Maintenance Signals
Community Trust
AI Alternatives
Abilities Bridge
abilities-bridge
MCP server for WordPress. Connect Claude AI or OpenAI to execute WordPress Abilities with configurable permissions.
Inhale: MCP Abilities by Respira
inhale-mcp-abilities
A small settings page that lets WordPress site administrators choose which registered abilities are exposed to the default MCP server.
AI Workflow Automation – AI Agent Hub
ai-workflow-automation-ai-agent-hub
AI-powered WordPress hub: 80+ abilities, MCP server, block editor AI experiments, RBAC, JWT auth, and workflows.
WebSamurai
websamurai
AI-powered features for WordPress with Model Context Protocol (MCP) server support and Advanced Chat
Agent Toolbelt – Safe Site Operations for AI Agents
agent-toolbelt
Safe hands for your site's AI agent: guarded maintenance operations with dry-run, confirm tokens, a full audit log, and automatic rollback.
AI Developer Profile
38 plugins · 15.3M total installs
How We Detect AI
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ai/build/index.js/wp-content/plugins/ai/build/style.css/wp-content/plugins/ai/build/index.jsai/build/index.js?ver=ai/build/style.css?ver=HTML / DOM Fingerprints
<!-- Example Experiment: AI Plugin Active -->window.ai/wp-json/ai/v1/example