AI Flash Tune Security & Risk Analysis

wordpress.org/plugins/ai-flash-tune

A WordPress plugin to turn WooCommerce drop-offs into conversions with AI-powered funnel analysis and optimization.

100 active installs v1.0.0 PHP 7.4+ WP 5.8+ Updated Feb 14, 2026
aianalyticsconversion-optimizationfunnelwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AI Flash Tune Safe to Use in 2026?

Generally Safe

Score 100/100

AI Flash Tune has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'ai-flash-tune' plugin v1.0.0 exhibits a concerning security posture primarily due to its unprotected attack surface. All 16 identified AJAX handlers lack authentication checks, presenting a significant risk of unauthorized access and manipulation of plugin functionality. While the plugin shows good practices in other areas, such as a high percentage of prepared SQL statements and properly escaped output, and no recorded vulnerability history, the absence of authorization on such a large number of entry points overshadows these strengths.

The static analysis reveals no critical or high-severity taint flows, and the vulnerability history is clean, which is positive. However, the lack of capability checks on all AJAX handlers and the absence of nonce checks on many of them (as implied by the total of 16 AJAX handlers and 12 nonce checks, meaning 4 handlers likely lack nonce checks as well) creates an environment where an attacker could potentially trigger any AJAX action without proper verification. The plugin's clean vulnerability history suggests it might be a new or less-targeted plugin, but relying on this for security is not advisable.

In conclusion, while 'ai-flash-tune' demonstrates good coding practices regarding SQL and output sanitization, its extensive and unprotected AJAX endpoint surface is a critical weakness. This plugin requires immediate attention to implement proper authentication and authorization mechanisms for all its AJAX handlers to mitigate the risk of unauthorized actions and potential exploitation.

Key Concerns

  • All AJAX handlers lack authentication checks
  • AJAX handlers without nonce checks
  • AJAX handlers without capability checks
Vulnerabilities
None known

AI Flash Tune Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AI Flash Tune Code Analysis

Dangerous Functions
0
Raw SQL Queries
11
101 prepared
Unescaped Output
140
813 escaped
Nonce Checks
12
Capability Checks
16
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

90% prepared112 total queries

Output Escaping

85% escaped953 total outputs
Data Flows
All sanitized

Data Flow Analysis

10 flows
<abandoned-carts> (includes\admin\abandoned-carts.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
16 unprotected

AI Flash Tune Attack Surface

Entry Points16
Unprotected16

AJAX Handlers 16

authwp_ajax_aiflt_track_funnel_pageai-flash-tune.php:123
noprivwp_ajax_aiflt_track_funnel_pageai-flash-tune.php:124
authwp_ajax_aiflt_save_page_speedai-flash-tune.php:127
noprivwp_ajax_aiflt_save_page_speedai-flash-tune.php:128
authwp_ajax_aiflt_log_behaviorai-flash-tune.php:129
noprivwp_ajax_aiflt_log_behaviorai-flash-tune.php:130
authwp_ajax_aiflt_track_simple_behaviorai-flash-tune.php:131
noprivwp_ajax_aiflt_track_simple_behaviorai-flash-tune.php:132
authwp_ajax_aiflt_get_ai_analysisai-flash-tune.php:133
noprivwp_ajax_aiflt_get_ai_analysisai-flash-tune.php:134
authwp_ajax_aiflt_get_funnel_dataai-flash-tune.php:135
authwp_ajax_aiflt_save_settingsai-flash-tune.php:136
noprivwp_ajax_aiflt_capture_guest_emailai-flash-tune.php:138
authwp_ajax_aiflt_capture_guest_emailai-flash-tune.php:139
authwp_ajax_aiflt_export_privacy_dataai-flash-tune.php:140
authwp_ajax_aiflt_get_segmented_funnel_dataai-flash-tune.php:141
WordPress Hooks 19
actionadmin_initai-flash-tune.php:96
actionadmin_initai-flash-tune.php:97
actionadmin_initai-flash-tune.php:98
actionadmin_initai-flash-tune.php:100
actionadmin_initai-flash-tune.php:104
actionaiflt_daily_cleanup_eventai-flash-tune.php:105
actionadmin_menuai-flash-tune.php:106
actionadmin_enqueue_scriptsai-flash-tune.php:107
actionadmin_initai-flash-tune.php:108
actionwoocommerce_thankyouai-flash-tune.php:111
actionwp_enqueue_scriptsai-flash-tune.php:113
actionwoocommerce_add_to_cartai-flash-tune.php:116
actionwoocommerce_after_cart_item_quantity_updateai-flash-tune.php:119
actionplugins_loadedai-flash-tune.php:145
actionadmin_noticesai-flash-tune.php:431
actionadmin_enqueue_scriptsai-flash-tune.php:469
actionwp_enqueue_scriptsai-flash-tune.php:725
filterwp_privacy_personal_data_exportersincludes\AIFLT_Privacy_Logic.php:18
filterwp_privacy_personal_data_erasersincludes\AIFLT_Privacy_Logic.php:21

Scheduled Events 1

aiflt_daily_cleanup_event
Maintenance & Trust

AI Flash Tune Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 14, 2026
PHP min version7.4
Downloads407

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

AI Flash Tune Developer Profile

tourbillonlabs

2 plugins · 500 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AI Flash Tune

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ai-flash-tune/assets/css/aiflt-admin-styles.css/wp-content/plugins/ai-flash-tune/assets/js/aiflt-admin-scripts.js/wp-content/plugins/ai-flash-tune/assets/js/aiflt-frontend-scripts.js
Script Paths
/wp-content/plugins/ai-flash-tune/assets/js/aiflt-admin-scripts.js/wp-content/plugins/ai-flash-tune/assets/js/aiflt-frontend-scripts.js
Version Parameters
ai-flash-tune/assets/css/aiflt-admin-styles.css?ver=ai-flash-tune/assets/js/aiflt-admin-scripts.js?ver=ai-flash-tune/assets/js/aiflt-frontend-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
ai-flash-tune-notice-barai-flash-tune-notice-errorai-flash-tune-notice-contentai-flash-tune-notice-button
JS Globals
aiflt_ajax_object
REST Endpoints
/wp-json/ai-flash-tune/v1/get-settings/wp-json/ai-flash-tune/v1/save-settings/wp-json/ai-flash-tune/v1/export-data/wp-json/ai-flash-tune/v1/get-funnel-data/wp-json/ai-flash-tune/v1/get-segmented-funnel-data/wp-json/ai-flash-tune/v1/get-ai-analysis/wp-json/ai-flash-tune/v1/log-behavior/wp-json/ai-flash-tune/v1/track-funnel-page/wp-json/ai-flash-tune/v1/save-page-speed/wp-json/ai-flash-tune/v1/track-simple-behavior/wp-json/ai-flash-tune/v1/capture-guest-email
FAQ

Frequently Asked Questions about AI Flash Tune