AI Ghostwriter Lite Security & Risk Analysis

wordpress.org/plugins/ai-ghostwriter

AI-powered content planning, generation, and publishing for WordPress using OpenAI GPT models.

0 active installs v2.0.2 PHP 7.4+ WP 5.0+ Updated Feb 1, 2026
aiautomationblogopenaiwriting
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AI Ghostwriter Lite Safe to Use in 2026?

Generally Safe

Score 100/100

AI Ghostwriter Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "ai-ghostwriter" v2.0.2 plugin presents a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by implementing nonce checks on all AJAX handlers and utilizing prepared statements for a significant majority of its SQL queries. Furthermore, all identified output operations are properly escaped, and there are no publicly known vulnerabilities associated with this plugin. The absence of bundled libraries also removes a common attack vector related to outdated dependencies.

However, the static analysis reveals a significant concern regarding taint analysis. All 8 analyzed taint flows exhibit unsanitized paths, with 8 classified as high severity. This indicates a substantial risk of data being improperly handled, potentially leading to vulnerabilities like Cross-Site Scripting (XSS) or Server-Side Request Forgery (SSRF) if these unsanitized inputs are used in sensitive operations. While no critical severity flows were found, the sheer number of high-severity unsanitized flows represents a notable area of concern that requires immediate attention and remediation.

In conclusion, while the plugin benefits from robust authentication checks on its entry points and diligent output escaping, the pervasive issue of unsanitized paths in taint flows is a critical weakness. The lack of historical vulnerabilities is a positive sign, suggesting a generally responsible development approach, but it does not mitigate the immediate risks identified in the current code. Developers should prioritize addressing these taint flow issues to strengthen the plugin's overall security.

Key Concerns

  • High severity unsanitized taint flows found
Vulnerabilities
None known

AI Ghostwriter Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AI Ghostwriter Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
13
23 prepared
Unescaped Output
0
120 escaped
Nonce Checks
22
Capability Checks
27
File Operations
1
External Requests
12
Bundled Libraries
0

SQL Query Safety

64% prepared36 total queries

Output Escaping

100% escaped120 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

8 flows8 with unsanitized paths
ajax_get_plan_items (ai-ghostwriter.php:541)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AI Ghostwriter Lite Attack Surface

Entry Points23
Unprotected0

AJAX Handlers 23

authwp_ajax_aigh_create_planai-ghostwriter.php:109
authwp_ajax_aigh_create_plan_from_keywordsai-ghostwriter.php:110
authwp_ajax_aigh_get_plansai-ghostwriter.php:111
authwp_ajax_aigh_get_plan_itemsai-ghostwriter.php:112
authwp_ajax_aigh_update_plan_itemai-ghostwriter.php:113
authwp_ajax_aigh_delete_plan_itemai-ghostwriter.php:114
authwp_ajax_aigh_update_plan_settingsai-ghostwriter.php:115
authwp_ajax_aigh_apply_keywordsai-ghostwriter.php:116
authwp_ajax_aigh_apply_keywords_sequentialai-ghostwriter.php:117
authwp_ajax_aigh_generate_articleai-ghostwriter.php:118
authwp_ajax_aigh_generate_batchai-ghostwriter.php:119
authwp_ajax_aigh_generateai-ghostwriter.php:120
authwp_ajax_aigh_save_draftai-ghostwriter.php:121
authwp_ajax_aigh_refine_articleai-ghostwriter.php:122
authwp_ajax_aigh_refine_articleai-ghostwriter.php:123
authwp_ajax_aigh_suggest_titlesai-ghostwriter.php:124
authwp_ajax_aigh_get_workflowsai-ghostwriter.php:126
authwp_ajax_aigh_get_workflowai-ghostwriter.php:127
authwp_ajax_aigh_save_workflowai-ghostwriter.php:128
authwp_ajax_aigh_delete_workflowai-ghostwriter.php:129
authwp_ajax_aigh_get_available_stepsai-ghostwriter.php:130
authwp_ajax_aigh_test_pipelineai-ghostwriter.php:133
authwp_ajax_aigh_analyze_styleai-ghostwriter.php:136
WordPress Hooks 3
actionadmin_menuai-ghostwriter.php:105
actionadmin_initai-ghostwriter.php:106
actionadmin_enqueue_scriptsai-ghostwriter.php:107
Maintenance & Trust

AI Ghostwriter Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 1, 2026
PHP min version7.4
Downloads92

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AI Ghostwriter Lite Developer Profile

arod13

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AI Ghostwriter Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ai-ghostwriter/assets/css/dashboard.css/wp-content/plugins/ai-ghostwriter/assets/css/planner.css/wp-content/plugins/ai-ghostwriter/assets/css/quick-generate.css/wp-content/plugins/ai-ghostwriter/assets/js/dashboard.js/wp-content/plugins/ai-ghostwriter/assets/js/planner.js/wp-content/plugins/ai-ghostwriter/assets/js/quick-generate.js/wp-content/plugins/ai-ghostwriter/assets/js/workflow-builder.js
Script Paths
/wp-content/plugins/ai-ghostwriter/assets/js/dashboard.js/wp-content/plugins/ai-ghostwriter/assets/js/planner.js/wp-content/plugins/ai-ghostwriter/assets/js/quick-generate.js/wp-content/plugins/ai-ghostwriter/assets/js/workflow-builder.js
Version Parameters
ai-ghostwriter/assets/css/dashboard.css?ver=ai-ghostwriter/assets/css/planner.css?ver=ai-ghostwriter/assets/css/quick-generate.css?ver=ai-ghostwriter/assets/js/dashboard.js?ver=ai-ghostwriter/assets/js/planner.js?ver=ai-ghostwriter/assets/js/quick-generate.js?ver=ai-ghostwriter/assets/js/workflow-builder.js?ver=

HTML / DOM Fingerprints

CSS Classes
aigh-dashboard-wrapaigh-planner-wrapaigh-quick-generate-wrap
Data Attributes
data-aigh-action
JS Globals
aigh_ajax_object
REST Endpoints
/wp-json/ai-ghostwriter/v1/settings/wp-json/ai-ghostwriter/v1/plans/wp-json/ai-ghostwriter/v1/plan-items/wp-json/ai-ghostwriter/v1/workflows/wp-json/ai-ghostwriter/v1/steps
FAQ

Frequently Asked Questions about AI Ghostwriter Lite