
AI Security & Risk Analysis
wordpress.org/plugins/aiAI features, experiments and capabilities for WordPress.
Is AI Safe to Use in 2026?
Generally Safe
Score 100/100AI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'ai' plugin version 0.5.0 demonstrates a generally strong security posture, with robust use of WordPress security features like nonce and capability checks. The plugin also avoids common pitfalls such as dangerous function usage and external HTTP requests. Its SQL queries are exclusively prepared, and a high percentage of output is properly escaped, indicating a good understanding of secure coding practices.
However, a significant concern arises from the taint analysis, which identified one flow with an unsanitized path. While this did not result in a high or critical severity finding and there are no recorded vulnerabilities, it represents a potential avenue for malicious input if not handled carefully. The presence of file operations without further context also warrants attention, as these can sometimes be associated with insecure practices if not implemented with strict sanitization and validation.
Given the complete absence of known vulnerabilities and a proactive approach to security features, the plugin is relatively safe. The primary weakness lies in the single unsanitized path identified in the taint analysis. This plugin is a good example of a developer who understands many security principles, but there's a specific area that needs verification to ensure it doesn't become a point of exploitation.
Key Concerns
- Flow with unsanitized path found
AI Security Vulnerabilities
AI Release Timeline
AI Code Analysis
Output Escaping
Data Flow Analysis
AI Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 33
Maintenance & Trust
AI Maintenance & Trust
Maintenance Signals
Community Trust
AI Alternatives
Abilities Bridge
abilities-bridge
MCP server for WordPress. Connect Claude AI or OpenAI to execute WordPress Abilities with configurable permissions.
AI Workflow Automation – AI Agent Hub
ai-workflow-automation-ai-agent-hub
AI-powered WordPress hub: 80+ abilities, MCP server, block editor AI experiments, RBAC, JWT auth, and workflows.
WebSamurai
websamurai
AI-powered features for WordPress with Model Context Protocol (MCP) server support and Advanced Chat
Angie – Agentic AI (Beta)
angie
Angie Code: Your expert WordPress developer, powered by AI. Build anything you can imagine without writing a single line of code.
Notification for Telegram
notification-for-telegram
Sends notifications to Telegram users or groups, when some events occur in WordPress.
AI Developer Profile
36 plugins · 14.9M total installs
How We Detect AI
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ai/build/index.js/wp-content/plugins/ai/build/style.css/wp-content/plugins/ai/build/index.jsai/build/index.js?ver=ai/build/style.css?ver=HTML / DOM Fingerprints
<!-- Example Experiment: AI Plugin Active -->window.ai/wp-json/ai/v1/example