AI Consigliere – Your AI assistant for WordPress content Security & Risk Analysis

wordpress.org/plugins/ai-consigliere

Use AI to analyze and improve the consistency of your WordPress taxonomies, directly from the admin panel. Requires your own OpenAI API key.

10 active installs v1.5.1 PHP 7.2.5+ WP 5.0+ Updated Dec 3, 2025
adminaigptopenaitools
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AI Consigliere – Your AI assistant for WordPress content Safe to Use in 2026?

Generally Safe

Score 100/100

AI Consigliere – Your AI assistant for WordPress content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'ai-consigliere' plugin v1.5.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. It demonstrates good practices by implementing prepared statements for all SQL queries and ensuring a high percentage of output is properly escaped, significantly reducing the risk of SQL injection and cross-site scripting vulnerabilities. The absence of known CVEs and the lack of critical or high severity taint flows further contribute to its favorable security profile. The plugin also correctly utilizes nonce checks for its AJAX handlers and avoids file operations, minimizing potential attack vectors.

However, a potential area for improvement lies in the lack of capability checks for its AJAX handlers. While nonce checks are present, relying solely on them for AJAX endpoints can be insufficient if the underlying functionality is sensitive and should be restricted to specific user roles. The presence of an external HTTP request, though not inherently a vulnerability, warrants careful review to ensure it is being made securely and to a trusted endpoint. Overall, the plugin is well-developed from a security perspective, but the absence of capability checks on AJAX handlers presents a minor but notable concern that could be addressed to further harden its security.

Key Concerns

  • AJAX handlers lack capability checks
Vulnerabilities
None known

AI Consigliere – Your AI assistant for WordPress content Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AI Consigliere – Your AI assistant for WordPress content Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
46 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

98% escaped47 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
aiconsigliere_check_taxonomy_callback (includes\class-ai-consigliere-core.php:125)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AI Consigliere – Your AI assistant for WordPress content Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_aiconsigliere_get_taxonomiesincludes\class-ai-consigliere-core.php:18
authwp_ajax_aiconsigliere_check_taxonomyincludes\class-ai-consigliere-core.php:19
authwp_ajax_aic_get_postsprompt\ai-consigliere-review-posts\ai-consigliere-review-posts.php:23
authwp_ajax_aic_review_postprompt\ai-consigliere-review-posts\ai-consigliere-review-posts.php:24
WordPress Hooks 8
actionplugins_loadedai-consigliere.php:24
actionadmin_menuincludes\class-ai-consigliere-core.php:12
actionadmin_initincludes\class-ai-consigliere-core.php:13
actionadmin_enqueue_scriptsincludes\class-ai-consigliere-core.php:14
filteraiconsigliere_get_openai_responseincludes\class-ai-consigliere-core.php:20
actionaiconsigliere_register_custom_promptsprompt\ai-consigliere-review-posts\ai-consigliere-review-posts.php:8
actionadmin_menuprompt\ai-consigliere-review-posts\ai-consigliere-review-posts.php:21
actionadmin_enqueue_scriptsprompt\ai-consigliere-review-posts\ai-consigliere-review-posts.php:22
Maintenance & Trust

AI Consigliere – Your AI assistant for WordPress content Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version7.2.5
Downloads577

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

AI Consigliere – Your AI assistant for WordPress content Developer Profile

Matteo Enna

14 plugins · 850 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect AI Consigliere – Your AI assistant for WordPress content

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ai-consigliere/includes/css/aic.css/wp-content/plugins/ai-consigliere/includes/js/aic.js/wp-content/plugins/ai-consigliere/prompt/ai-consigliere-review-posts/js/review.js
Script Paths
includes/js/aic.jsprompt/ai-consigliere-review-posts/js/review.js
Version Parameters
ai-consigliere/includes/css/aic.css?ver=ai-consigliere/includes/js/aic.js?ver=ai-consigliere/prompt/ai-consigliere-review-posts/js/review.js

HTML / DOM Fingerprints

CSS Classes
wrap
Data Attributes
id="post_type"id="post_select_container"id="ai-review-result"id="post_select"id="review-post"
JS Globals
AICONSIGLIEREAIC
REST Endpoints
/wp-json/ai-consigliere/v1/check-taxonomy/wp-json/ai-consigliere/v1/get-taxonomies
FAQ

Frequently Asked Questions about AI Consigliere – Your AI assistant for WordPress content