
AI Engine – The Chatbot, AI Framework & MCP for WordPress Security & Risk Analysis
wordpress.org/plugins/ai-engineAI meets WordPress. Your site can now chat, write poetry, solve problems, and maybe make you coffee.
Is AI Engine – The Chatbot, AI Framework & MCP for WordPress Safe to Use in 2026?
Mostly Safe
Score 76/100AI Engine – The Chatbot, AI Framework & MCP for WordPress is generally safe to use. 22 past CVEs were resolved. Keep it updated.
The "ai-engine" plugin v3.4.4 exhibits a mixed security posture. On the positive side, the static analysis reveals no unprotected entry points (AJAX, REST API, shortcodes, cron events) and a high percentage of properly escaped output. The use of prepared statements for SQL queries is also commendable. However, the presence of the `unserialize` function is a significant concern, as deserialization of untrusted data is a common attack vector, and the static analysis did not identify any sanitization for this function.
The plugin's vulnerability history is alarming, with a substantial number of past CVEs (22 in total), including a significant number of critical and high-severity issues. The types of past vulnerabilities, such as Deserialization of Untrusted Data, Missing Authorization, SQL Injection, and Code Injection, directly align with potential risks flagged by the static analysis (e.g., `unserialize`). This history suggests a recurring pattern of security weaknesses within the plugin's development.
While the current version (v3.4.4) reports no currently unpatched vulnerabilities, the past track record and the presence of the `unserialize` function create a notable risk. The plugin developers have demonstrated a history of introducing vulnerabilities, and the static analysis indicates a specific risky function that could be exploited if not handled with extreme care and robust input validation. Therefore, while there are some good security practices in place, the past history and the presence of `unserialize` necessitate caution.
Key Concerns
- Presence of unserialize function
- High number of past critical CVEs
- High number of past high CVEs
- History of deserialization vulnerabilities
- History of SQL injection vulnerabilities
- History of code injection vulnerabilities
- History of missing/incorrect authorization vulnerabilities
AI Engine – The Chatbot, AI Framework & MCP for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
22 total CVEs
AI Engine – The Chatbot, AI Framework & MCP for WordPress <= 3.3.2 - Authenticated (Editor+) Arbitrary File Upload
AI Engine <= 3.3.2 - Authenticated (Editor+) Arbitrary File Upload via 'filename' Parameter in update_media_metadata Endpoint
AI Engine <= 3.3.2 - Authenticated (Subscriber+) Server-Side Request Forgery
AI Engine <= 3.1.8 - Authenticated (Editor+) Server-Side Request Forgery
AI Engine <= 3.1.8 - Authenticated (Subscriber+) PHP Object Injection via PHAR Deserialization
AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation
Ai Engine <= 2.9.5 - Missing Authorization to Unauthenticated Uploaded Files Disclosure And Deletion
AI Engine 2.9.3 - 2.9.4 - Authenticated (Subscriber+) Arbitrary File Upload
AI Engine <= 2.9.4 - Missing URL Scheme Validation to Authenticated (Subscriber+) Arbitrary File Read via simpleTranscribeAudio and get_audio Functions
AI Engine <= 2.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via `mwai_chatbot` Shortcode `id` Parameter
AI Engine 2.8.4 - Insecure OAuth Implementation
AI Engine 2.8.0 - 2.8.3 - Authenticated (Subscriber+) Insufficient Authorization to Privilege Escalation via MCP
AI Engine <= 2.6.3 - Authenticated (Admin+) SQL Injection
AI Engine <= 2.4.7 - Authenticated (Admin+) SQL Injection
AI Engine <= 2.5.0 - Authenticated (Admin+) Remote Code Execution
AI Engine <= 2.4.7 - Authenticated (Subscriber+) Server-Side Request Forgery
AI Engine: ChatGPT Chatbot <= 2.2.63 - Authenticated (Editor+) Arbitrary File Upload
AI Engine <= 2.1.4 - Authenticated (Editor+) Server-Side Request Forgery
AI Engine <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting
AI Engine <= 2.1.4 - Authenticated(Editor+) Arbitrary File Upload via add_image_from_url
AI Engine: ChatGPT Chatbot <= 1.9.98 - Unauthenticated Arbitrary File Upload via rest_upload
AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable <= 1.6.82 - Authenticated (Admin+) Stored Cross-Site Scripting
AI Engine – The Chatbot, AI Framework & MCP for WordPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
AI Engine – The Chatbot, AI Framework & MCP for WordPress Attack Surface
REST API Routes 13
Shortcodes 3
WordPress Hooks 82
Scheduled Events 4
Maintenance & Trust
AI Engine – The Chatbot, AI Framework & MCP for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
AI Engine – The Chatbot, AI Framework & MCP for WordPress Alternatives
AI Puffer – Your AI engine for WordPress (formerly AI Power)
gpt3-ai-content-generator
Your AI engine for WordPress. Chat, write, automate, and generate — all in one workspace.
Aimogen – AI Content Writer, Editor, Chat and Automation
aimogen
Connect your WordPress site with multiple AI models. Create chatbots, generate content, edit content and automate workflows using AI.
GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation
geeky-bot
Generate AI content without prompt, AI chatbot, WooCommerce lead generation, intelligent web search, and interactive customer engagement on your WordP …
AI Copilot – ChatGPT Chatbot & AI Engine for Post Automation
ai-copilot
Boost productivity with ChatGPT AI Engine: automate content creation, enhance Gutenberg editing, and deploy AI chatbots for smarter, faster workflows.
AI ChatBot with ChatGPT and Content Generator by AYS
ays-chatgpt-assistant
AI Writing Assistant, Chatbot, and virtual support all-in-one! Answer customer queries and generate content easily. Works with ChatGPT and Gemini.
AI Engine – The Chatbot, AI Framework & MCP for WordPress Developer Profile
27 plugins · 371K total installs
How We Detect AI Engine – The Chatbot, AI Framework & MCP for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ai-engine/assets/js/ai-engine-admin.js/wp-content/plugins/ai-engine/assets/css/ai-engine-admin.css/wp-content/plugins/ai-engine/assets/js/meow-kit.js/wp-content/plugins/ai-engine/assets/js/admin.js/wp-content/plugins/ai-engine/assets/js/ai-engine-admin.js/wp-content/plugins/ai-engine/assets/js/meow-kit.js/wp-content/plugins/ai-engine/assets/js/admin.jsai-engine/assets/js/ai-engine-admin.js?ver=ai-engine/assets/css/ai-engine-admin.css?ver=ai-engine/assets/js/meow-kit.js?ver=ai-engine/assets/js/admin.js?ver=HTML / DOM Fingerprints
mwai-settingsmwai-content-generatormwai-images-generatormwai-videos-generatormwai-playgroundmeowkit-admindata-module_generator_contentdata-module_generator_imagesdata-module_generator_videosdata-module_playgrounddata-module_suggestionsmeow_ai_admin_obj