AI Content Plan Security & Risk Analysis

wordpress.org/plugins/ai-content-plan

Connect WordPress to AI Content Plan for AI publishing, publishing defaults, and optional WooCommerce content sharing.

0 active installs v1.0.0 PHP 7.4+ WP 5.8+ Updated Apr 9, 2026
ai-contentbloggingcontent-marketingeditorial-calendarwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AI Content Plan Safe to Use in 2026?

Generally Safe

Score 100/100

AI Content Plan has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "ai-content-plan" v1.0.0 plugin demonstrates a strong security posture based on the provided static analysis. All identified entry points, including 13 AJAX handlers, are protected with nonce and capability checks, indicating good development practices for handling user interactions. The code also avoids dangerous functions and adheres to secure SQL query practices by exclusively using prepared statements. Furthermore, all output is properly escaped, and there are no file operations or unsanitized taint flows detected, which are significant strengths. The plugin's vulnerability history is entirely clean, with no recorded CVEs, suggesting a history of secure development and maintenance.

While the plugin exhibits many positive security attributes, there are a couple of minor points of interest. The presence of two external HTTP requests could potentially introduce vulnerabilities if the external services are compromised or if the requests themselves are not handled securely. Although the static analysis did not flag any specific issues with these requests, it represents a small expansion of the attack surface outside of direct WordPress control. Overall, this plugin appears to be developed with security in mind, with a very low risk profile. Its strengths in input validation, output escaping, and the absence of known vulnerabilities far outweigh the minor concerns.

Key Concerns

  • External HTTP requests detected
Vulnerabilities
None known

AI Content Plan Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

AI Content Plan Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

AI Content Plan Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
266 escaped
Nonce Checks
13
Capability Checks
13
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped266 total outputs
Attack Surface

AI Content Plan Attack Surface

Entry Points13
Unprotected0

AJAX Handlers 13

authwp_ajax_aicp_disconnectadmin/class-aicp-admin.php:70
authwp_ajax_aicp_save_settingsadmin/class-aicp-admin.php:71
authwp_ajax_aicp_reconfigure_capabilitiesadmin/class-aicp-admin.php:72
authwp_ajax_aicp_save_sharing_settingsadmin/class-aicp-admin.php:73
authwp_ajax_aicp_refresh_statisticsincludes/class-aicp-statistics.php:34
authwp_ajax_aicp_generate_credentialsincludes/class-aicp-wizard.php:22
authwp_ajax_aicp_register_with_blogaiincludes/class-aicp-wizard.php:23
authwp_ajax_aicp_configure_output_channelincludes/class-aicp-wizard.php:24
authwp_ajax_aicp_configure_input_channelincludes/class-aicp-wizard.php:25
authwp_ajax_aicp_test_connectionincludes/class-aicp-wizard.php:26
authwp_ajax_aicp_save_capabilitiesincludes/class-aicp-wizard.php:27
authwp_ajax_aicp_test_woocommerceincludes/class-aicp-woocommerce.php:43
authwp_ajax_aicp_send_test_productincludes/class-aicp-woocommerce.php:44
WordPress Hooks 10
actionadmin_menuadmin/class-aicp-admin.php:66
actionadmin_enqueue_scriptsadmin/class-aicp-admin.php:67
actionadmin_initadmin/class-aicp-admin.php:68
actionadmin_initadmin/class-aicp-admin.php:69
actionrest_api_initincludes/class-aicp-rest-api.php:28
actionadmin_noticesincludes/class-aicp-wizard.php:329
actionplugins_loadedwordpress-aicp-bridge.php:145
actioninitwordpress-aicp-bridge.php:148
filterthe_authorwordpress-aicp-bridge.php:168
filterwp_prepare_attachment_for_jswordpress-aicp-bridge.php:169
Maintenance & Trust

AI Content Plan Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 9, 2026
PHP min version7.4
Downloads66

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AI Content Plan Developer Profile

Johan

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AI Content Plan

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ai-content-plan/admin/css/aicp-admin-styles.css/wp-content/plugins/ai-content-plan/admin/js/aicp-admin-scripts.js/wp-content/plugins/ai-content-plan/includes/css/aicp-frontend-styles.css
Script Paths
/wp-content/plugins/ai-content-plan/admin/js/aicp-admin-scripts.js
Version Parameters
ai-content-plan/admin/css/aicp-admin-styles.css?ver=ai-content-plan/admin/js/aicp-admin-scripts.js?ver=ai-content-plan/includes/css/aicp-frontend-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
aicp-settings-pageaicp-wizard-pageaicp-admin-wrapper
HTML Comments
<!-- AICP REST API Endpoint --><!-- AI Content Plan Plugin Activation/Deactivation Hooks -->
Data Attributes
data-aicp-api-urldata-aicp-plugin-version
JS Globals
window.AICP_Admin_Scriptswindow.AICP_API_URLwindow.AICP_PLUGIN_VERSION
REST Endpoints
/wp-json/aicp/v1/content/wp-json/aicp/v1/sync/wp-json/aicp/v1/settings
FAQ

Frequently Asked Questions about AI Content Plan