
WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek Security & Risk Analysis
wordpress.org/plugins/ai-content-generationWP Wand is a powerful AI Content Writer for WordPress. Your AI Co-Pilot for generating content, powered by OpenAI, Claude, OpenRouter and Deepseek.
Is WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek Safe to Use in 2026?
Mostly Safe
Score 76/100WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek is generally safe to use. 2 past CVEs were resolved.
The "ai-content-generation" plugin v1.3.07 presents a mixed security posture. While it demonstrates good practices in many areas, such as a high percentage of properly escaped outputs and the use of prepared statements for most SQL queries, there are significant concerns. The presence of 18 AJAX handlers, with 2 lacking authentication checks, creates a notable attack surface that could be exploited by unauthenticated users. Furthermore, the taint analysis reveals 2 flows with unsanitized paths, indicating potential for directory traversal or other path-related vulnerabilities, even if no critical or high-severity issues were flagged in this specific analysis. The plugin's vulnerability history is a major red flag, with two known medium-severity CVEs, one of which remains unpatched. The recurring "Missing Authorization" vulnerability type suggests a systemic issue in how the plugin handles user permissions, which is directly reflected in the static analysis findings. Overall, the plugin has some strengths in code hygiene, but the unpatched vulnerability and the unprotected AJAX endpoints represent immediate and significant risks.
Key Concerns
- Unpatched CVE
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Recurring Missing Authorization vulnerability type
WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek <= 1.3.07 - Missing Authorization
WP Wand <= 1.2.5 - Missing Authorization
WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek Release Timeline
WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek Attack Surface
AJAX Handlers 18
WordPress Hooks 45
Maintenance & Trust
WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek Maintenance & Trust
Maintenance Signals
Community Trust
WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek Alternatives
BotWriter – AI Writer & Content Generator
botwriter
AI Writer & content generator for WordPress & WooCommerce. Auto blogging, AI writing plugin, product descriptions and SEO content.
Opace AI Scribe: SEO Content Creator & Humaizer for OpenAI & Anthropic
ai-scribe-the-chatgpt-powered-seo-content-creation-wizard
AI SEO content creator and humanizer for OpenAI and Anthropic models. SEO articles with GPT-5, Sonnet 4.5 & 4o images. Works with Yoast & Rank Math.
Easy GPT for WP | AI Content Generator
easy-gpt-for-wp
Generate SEO content for WordPress with GPT models from OpenAI, DeepSeek and Gemini. Includes auto updates, translations, moderation, Yoast & WooC …
AIPress – OpenAI, ChatGPT Content Creator, Image Generator
aipress
This is a plugin that uses OpenAI's GPT-3 and chatGPT models to generate AI-powered content on your WordPress site.
WebPlanetSoft AI Content Gen – Google Gemini AI Writer, SEO Blog Post & Content Generator
webplanet-ai-content-gen
Create high-quality SEO content with AI. The ultimate AI writer for manual blog posts, smart previews, and auto-categories using Google Gemini.
WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek Developer Profile
4 plugins · 21K total installs
How We Detect WP Wand – Unlimited Content Generation using AI – for OpenAI, Claude, Openrouter and Deepseek
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ai-content-generation/assets/css/style.css/wp-content/plugins/ai-content-generation/assets/js/app.js/wp-content/plugins/ai-content-generation/assets/js/chunk-vendors.js/wp-content/plugins/ai-content-generation/assets/js/chunk-common.js/wp-content/plugins/ai-content-generation/assets/css/quill.snow.css/wp-content/plugins/ai-content-generation/assets/css/quill.bubble.css/wp-content/plugins/ai-content-generation/assets/js/app.js/wp-content/plugins/ai-content-generation/assets/js/chunk-vendors.js/wp-content/plugins/ai-content-generation/assets/js/chunk-common.jsai-content-generation/assets/css/style.css?ver=ai-content-generation/assets/js/app.js?ver=ai-content-generation/assets/js/chunk-vendors.js?ver=ai-content-generation/assets/js/chunk-common.js?ver=ai-content-generation/assets/css/quill.snow.css?ver=ai-content-generation/assets/css/quill.bubble.css?ver=HTML / DOM Fingerprints
ai-content-generator-wrapperai-content-generator-editorThis is the main wrapper for the AI Content Generator plugin.data-ai-generator-iddata-ai-generator-typeai_content_generator_params/wp-json/ai-content-generation/v1/generate/wp-json/ai-content-generation/v1/save[ai_content_generator]