
AI News Security & Risk Analysis
wordpress.org/plugins/ai-newsAutomatically generate AI-powered news articles using Google's Gemini API and publish them to your WordPress site.
Is AI News Safe to Use in 2026?
Generally Safe
Score 100/100AI News has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ai-news" v1.2.7 plugin exhibits a generally strong security posture based on the static analysis. A significant positive is the complete absence of unescaped output, robust use of nonce checks, and a substantial number of capability checks for its entry points. The fact that 100% of outputs are properly escaped is a major strength, mitigating risks of XSS vulnerabilities. Furthermore, the plugin has no recorded vulnerabilities (CVEs), indicating a history of stable and secure development.
However, there are areas for concern. The taint analysis revealed two flows with unsanitized paths. While classified as having no critical or high severity, unsanitized paths can still lead to vulnerabilities like path traversal or information disclosure if exploited in specific contexts. Additionally, over half of the SQL queries are not using prepared statements. While the total number of SQL queries is moderate, this practice can open the door to SQL injection vulnerabilities, especially if the inputs to these queries are not strictly validated elsewhere. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful review to ensure that data used in these operations is properly sanitized.
In conclusion, "ai-news" v1.2.7 has strong defensive coding practices in place, particularly regarding output handling and authentication checks for its AJAX endpoints. The lack of historical vulnerabilities is reassuring. The primary areas for improvement lie in addressing the identified unsanitized paths and ensuring all SQL queries utilize prepared statements to mitigate potential injection risks.
Key Concerns
- Unsanitized paths found in taint analysis
- SQL queries not using prepared statements
AI News Security Vulnerabilities
AI News Release Timeline
AI News Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
AI News Attack Surface
AJAX Handlers 19
WordPress Hooks 19
Scheduled Events 5
Maintenance & Trust
AI News Maintenance & Trust
Maintenance Signals
Community Trust
AI News Alternatives
Trendly AI Post – Trending Topics from Google News
trendly-ai-post
AI-powered WordPress plugin that generates SEO-optimized blog posts from trending Google News topics.
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
email-subscribers
Add subscription forms on the website and send newsletters & automatically send post notification about new blog posts once it gets published.
Brevo for WooCommerce
woocommerce-sendinblue-newsletter-subscription
All-in-one WooCommerce email marketing, automation, SMS, and CRM by Brevo. Grow your store with powerful marketing tools.
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce
wp-marketing-automations
Recover lost revenue with Cart Abandonment Recovery for WooCommerce. Increase retention with Post Purchase Follow-Up Emails.
AI News Developer Profile
1 plugin · 0 total installs
How We Detect AI News
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ai-news/assets/css/admin.css/wp-content/plugins/ai-news/assets/js/admin.js/wp-content/plugins/ai-news/assets/js/admin.jsai-news/assets/css/admin.css?ver=ai-news/assets/js/admin.js?ver=HTML / DOM Fingerprints
ainews-admin-cssainews_ajaxainews_ajax