
AI Experiments Security & Risk Analysis
wordpress.org/plugins/aiAI experiments and capabilities for WordPress.
Is AI Experiments Safe to Use in 2026?
Generally Safe
Score 100/100AI Experiments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'ai' plugin version 0.5.0 demonstrates a generally strong security posture, with robust use of WordPress security features like nonce and capability checks. The plugin also avoids common pitfalls such as dangerous function usage and external HTTP requests. Its SQL queries are exclusively prepared, and a high percentage of output is properly escaped, indicating a good understanding of secure coding practices.
However, a significant concern arises from the taint analysis, which identified one flow with an unsanitized path. While this did not result in a high or critical severity finding and there are no recorded vulnerabilities, it represents a potential avenue for malicious input if not handled carefully. The presence of file operations without further context also warrants attention, as these can sometimes be associated with insecure practices if not implemented with strict sanitization and validation.
Given the complete absence of known vulnerabilities and a proactive approach to security features, the plugin is relatively safe. The primary weakness lies in the single unsanitized path identified in the taint analysis. This plugin is a good example of a developer who understands many security principles, but there's a specific area that needs verification to ensure it doesn't become a point of exploitation.
Key Concerns
- Flow with unsanitized path found
AI Experiments Security Vulnerabilities
AI Experiments Code Analysis
Output Escaping
Data Flow Analysis
AI Experiments Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 33
Maintenance & Trust
AI Experiments Maintenance & Trust
Maintenance Signals
Community Trust
AI Experiments Alternatives
Abilities Bridge
abilities-bridge
MCP server for WordPress. Connect Claude AI or OpenAI to execute WordPress Abilities with configurable permissions.
Angie – Agentic AI for WordPress (Beta)
angie
Angie Code: Your expert WordPress developer, powered by AI. Build anything you can imagine without writing a single line of code.
Notification for Telegram
notification-for-telegram
Sends notifications to Telegram users or groups, when some events occur in WordPress.
AutoWP – AI Content Writer & Rewriter
autowp-ai-content-writer-rewriter
AI Content Writer & Rewriter. Write content with AI from zero. Import content from RSS, Wordpress, Google News and rewrite with AI.
LLMs.txt Generator
llms-txt-generator
Optimize your WordPress content for AI discovery and interaction through the llms.txt file, the robots.txt for AI engines.
AI Experiments Developer Profile
34 plugins · 14.9M total installs
How We Detect AI Experiments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ai/build/index.js/wp-content/plugins/ai/build/style.css/wp-content/plugins/ai/build/index.jsai/build/index.js?ver=ai/build/style.css?ver=HTML / DOM Fingerprints
<!-- Example Experiment: AI Plugin Active -->window.ai/wp-json/ai/v1/example