
Instant Image Generator (AI Image by Gemini, Dall-E and One Click Image from Unsplash, Openverse, Pixabay, Pexels, Giphy) Security & Risk Analysis
wordpress.org/plugins/ai-imageSearch millions of stock photos, generate AI images with OpenAI & Gemini, browse GIFs, and import directly to your Media Library.
Is Instant Image Generator (AI Image by Gemini, Dall-E and One Click Image from Unsplash, Openverse, Pixabay, Pexels, Giphy) Safe to Use in 2026?
Generally Safe
Score 97/100Instant Image Generator (AI Image by Gemini, Dall-E and One Click Image from Unsplash, Openverse, Pixabay, Pexels, Giphy) has a strong security track record. Known vulnerabilities have been patched promptly.
The "ai-image" plugin v2.1.0 presents a mixed security posture. On the positive side, all output appears to be properly escaped, and there are no identified critical or high severity taint flows. The plugin also demonstrates a good number of capability checks and nonce checks. However, significant concerns arise from the substantial attack surface, with 11 out of 15 AJAX handlers lacking authentication checks. This opens the door for unauthenticated users to potentially trigger plugin functionality, which could be exploited if specific AJAX actions are vulnerable.
Further investigation into the SQL queries reveals that none are using prepared statements, which is a critical oversight and could lead to SQL injection vulnerabilities. The presence of a past critical vulnerability categorized as 'Unrestricted Upload of File with Dangerous Type' is also a red flag. While currently unpatched CVEs are zero, this historical pattern suggests a potential for insecure file handling. The high number of external HTTP requests (21) could also introduce risks if the plugin doesn't properly validate or sanitize data received from external sources.
In conclusion, while the plugin has some strengths in output handling and a lack of critical taint flows, the unprotected AJAX endpoints, raw SQL queries, and historical critical vulnerability type indicate a medium to high risk. Remediation efforts should prioritize securing AJAX handlers, implementing prepared statements for all SQL queries, and thoroughly auditing file upload functionalities.
Key Concerns
- Unprotected AJAX handlers
- SQL queries without prepared statements
- Past critical vulnerability: Unrestricted Upload
- Flows with unsanitized paths
- File operations detected
- High number of external HTTP requests
Instant Image Generator (AI Image by Gemini, Dall-E and One Click Image from Unsplash, Openverse, Pixabay, Pexels, Giphy) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Instant Image Generator <= 1.5.2 - Unauthenticated Arbitrary File Upload
Instant Image Generator (AI Image by Gemini, Dall-E and One Click Image from Unsplash, Openverse, Pixabay, Pexels, Giphy) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Instant Image Generator (AI Image by Gemini, Dall-E and One Click Image from Unsplash, Openverse, Pixabay, Pexels, Giphy) Attack Surface
AJAX Handlers 15
WordPress Hooks 14
Maintenance & Trust
Instant Image Generator (AI Image by Gemini, Dall-E and One Click Image from Unsplash, Openverse, Pixabay, Pexels, Giphy) Maintenance & Trust
Maintenance Signals
Community Trust
Instant Image Generator (AI Image by Gemini, Dall-E and One Click Image from Unsplash, Openverse, Pixabay, Pexels, Giphy) Alternatives
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
Image Hub – Free Images from Unsplash, Pixabay, Pexels, Openverse & Giphy
image-hub
Access and manage royalty-free images from Unsplash, Pixabay, Pexels, Openverse & Giphy without leaving your WordPress dashboard.
Stock Images by Indietech
stock-images-by-indietech
Integrate stock photos directly into your WordPress Media Library. Search and import high-quality images from multiple sources.
LS Stock Portfolio
ls-stock-portfolio
Display Adobe Stock, Unsplash and Pixabay portfolios in responsive masonry or grid layouts with Lightbox and load-more functionality.
FLS Stock Photo Importer
fls-stock-photo-importer
Search Pexels, Pixabay and Openverse images from the WordPress editor and import them directly into your Media Library.
Instant Image Generator (AI Image by Gemini, Dall-E and One Click Image from Unsplash, Openverse, Pixabay, Pexels, Giphy) Developer Profile
24 plugins · 251K total installs
How We Detect Instant Image Generator (AI Image by Gemini, Dall-E and One Click Image from Unsplash, Openverse, Pixabay, Pexels, Giphy)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ai-image/assets/admin/css/biggopti.css/wp-content/plugins/ai-image/assets/admin/js/biggopti.js/wp-content/plugins/ai-image/build/admin/index.css/wp-content/plugins/ai-image/build/admin/index.js/wp-content/plugins/ai-image/assets/admin/js/biggopti.js/wp-content/plugins/ai-image/build/admin/index.jsai-image/build/admin/index.css?ver=ai-image/build/admin/index.js?ver=ai-image-admin-api-biggopti?ver=HTML / DOM Fingerprints
bdthemes-ai-image-containerdata-ai-image-idAIImageAdminApiBiggoptiConfig/wp-json/ai-image/v1/get_gallery/wp-json/ai-image/v1/save_image/wp-json/ai-image/v1/get_providers/wp-json/ai-image/v1/get_settings/wp-json/ai-image/v1/save_settings