AI Enabler Security & Risk Analysis

wordpress.org/plugins/ai-enabler

Revolutionize WordPress websites with AI Enabler Plugin: Embed ChatGPT's dynamic forms & widgets for engaging, AI-driven user experiences.

0 active installs v1.2.7 PHP 7.4+ WP 6.2+ Updated Sep 12, 2025
aiform-builderimage-generationtext-generationvoice-generation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AI Enabler Safe to Use in 2026?

Generally Safe

Score 100/100

AI Enabler has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "ai-enabler" plugin v1.2.7 exhibits a generally good security posture with a strong adherence to secure coding practices. The code analysis indicates a very low risk of cross-site scripting (XSS) and SQL injection vulnerabilities, as 99% of outputs are properly escaped and all SQL queries utilize prepared statements. The absence of any recorded vulnerabilities or CVEs further strengthens this positive assessment, suggesting a well-maintained and secure codebase.

However, there are specific areas that introduce risk. The presence of two AJAX handlers without authentication checks presents a significant attack vector. Attackers could potentially exploit these endpoints to perform unauthorized actions or gain information, especially if they can be triggered by unauthenticated users. The use of the `unserialize()` function, while only present twice, is a known security risk as it can lead to remote code execution if provided with malicious input. While taint analysis shows no unsanitized paths, the potential for exploitation of `unserialize` remains if input validation is not robust elsewhere.

In conclusion, "ai-enabler" v1.2.7 is a plugin with a strong foundation in secure coding. The lack of historical vulnerabilities is a testament to its quality. Nevertheless, the two unprotected AJAX endpoints and the use of `unserialize()` are critical areas that require immediate attention to mitigate potential security risks and maintain its otherwise excellent security profile.

Key Concerns

  • AJAX handlers without authentication checks
  • Use of unserialize() function
Vulnerabilities
None known

AI Enabler Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

AI Enabler Release Timeline

v1.2.7Current
v1.2.5
v1.2.4
v1.2.2
v1.2.1
v1.2.0
v1.1.0
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

AI Enabler Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
2
178 escaped
Nonce Checks
8
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
1

Dangerous Functions Found

unserialize$rgfb_llm_logs = unserialize($all_meta_data['rgfb_llm_logs'][0]);admin/templates/logs.tpl.php:92
unserialize$rgfb_llm_logs = unserialize($all_meta_data['rgfb_llm_logs'][0]);includes/controller.php:133

Bundled Libraries

TinyMCE

Output Escaping

99% escaped180 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
rgfb_form_list_callback (admin/admin.php:284)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

AI Enabler Attack Surface

Entry Points9
Unprotected2

AJAX Handlers 7

authwp_ajax_save_rgfb_form_builderadmin/admin.php:22
authwp_ajax_update_rgfb_form_builderadmin/admin.php:25
authwp_ajax_rgfb_save_settingsadmin/admin.php:34
authwp_ajax_rgfb_get_settings_screenadmin/admin.php:35
noprivwp_ajax_rgfb_get_settings_screenadmin/admin.php:36
authwp_ajax_rgfb_save_llm_logsadmin/admin.php:39
noprivwp_ajax_rgfb_save_llm_logsadmin/admin.php:40

Shortcodes 2

[ai_enabler] includes/controller.php:14
[ai_enabler] includes/controller.php:43
WordPress Hooks 6
actionadmin_enqueue_scriptsadmin/admin.php:16
actionadmin_menuadmin/admin.php:19
filterrgfb_form_builder_listadmin/admin.php:28
filterrgfb_form_builder_settingsadmin/admin.php:31
filterrgfb_llm_logsadmin/admin.php:44
actionwp_enqueue_scriptsincludes/controller.php:13
Maintenance & Trust

AI Enabler Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedSep 12, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AI Enabler Developer Profile

Avner Brodsky

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AI Enabler

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ai-enabler/assets/css/bootstrap/bootstrap.min.css/wp-content/plugins/ai-enabler/assets/css/jquery-confirm/jquery-confirm.css/wp-content/plugins/ai-enabler/assets/css/style.css/wp-content/plugins/ai-enabler/assets/css/slick-carousel/slick.min.css/wp-content/plugins/ai-enabler/assets/css/slick-carousel/slick-theme.min.css/wp-content/plugins/ai-enabler/assets/js/slick-carousel/slick.min.js/wp-content/plugins/ai-enabler/assets/js/jquery-ui/jquery-ui.js/wp-content/plugins/ai-enabler/assets/js/form-builder/form-builder.js+6 more
Script Paths
/wp-content/plugins/ai-enabler/assets/js/slick-carousel/slick.min.js/wp-content/plugins/ai-enabler/assets/js/jquery-ui/jquery-ui.js/wp-content/plugins/ai-enabler/assets/js/form-builder/form-builder.js/wp-content/plugins/ai-enabler/assets/js/jquery-confirm/jquery-confirm.js/wp-content/plugins/ai-enabler/assets/js/script.js/wp-content/plugins/ai-enabler/assets/js/add_form.js+2 more
Version Parameters
ai-enabler/assets/css/bootstrap/bootstrap.min.css?ver=ai-enabler/assets/css/jquery-confirm/jquery-confirm.css?ver=ai-enabler/assets/css/style.css?ver=ai-enabler/assets/css/slick-carousel/slick.min.css?ver=ai-enabler/assets/css/slick-carousel/slick-theme.min.css?ver=ai-enabler/assets/js/slick-carousel/slick.min.js?ver=ai-enabler/assets/js/jquery-ui/jquery-ui.js?ver=ai-enabler/assets/js/form-builder/form-builder.js?ver=ai-enabler/assets/js/jquery-confirm/jquery-confirm.js?ver=ai-enabler/assets/js/script.js?ver=ai-enabler/assets/js/add_form.js?ver=ai-enabler/assets/js/settings.js?ver=ai-enabler/assets/js/logs.js?ver=ai-enabler/assets/plugins/fontawesome/6.6.0/css/all.css?ver=

HTML / DOM Fingerprints

CSS Classes
rgfb-custom-stylergfb-custom-script
Data Attributes
data-rgfb-form-id
JS Globals
rgFormBuilderAjax
REST Endpoints
/wp-json/rgfb-ai-enabler/v1/forms/wp-json/rgfb-ai-enabler/v1/settings
FAQ

Frequently Asked Questions about AI Enabler