AI-Only Pages Security & Risk Analysis

wordpress.org/plugins/ai-only-pages

Mark any page as AI-only. Hidden from search engines, optimized for AI crawlers, listed in /llms-index.txt. Includes Token Diet and global settings.

0 active installs v1.3.3 PHP 7.4+ WP 5.5+ Updated Mar 12, 2026
aillmnoindexrobotsseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AI-Only Pages Safe to Use in 2026?

Generally Safe

Score 100/100

AI-Only Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 22d ago
Risk Assessment

The "ai-only-pages" plugin version 1.3.3 demonstrates a generally strong security posture based on the provided static analysis. The absence of any entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code exhibits good practices by properly escaping a high percentage of its outputs (96%) and utilizing prepared statements for the majority of its SQL queries (83%). The presence of nonce and capability checks, although limited in number, further bolsters its defenses.

The taint analysis revealed no unsanitized paths, indicating a low risk of common injection vulnerabilities. The plugin also has no recorded vulnerability history, which is a very positive sign. However, the extremely small attack surface and limited code signals might suggest a plugin with very basic functionality, or that the analysis might not have uncovered all potential interactions if the plugin relies heavily on external integrations or user-provided data that isn't directly processed by these analysis points.

In conclusion, based on the data, "ai-only-pages" v1.3.3 appears to be a secure plugin. The lack of identified vulnerabilities, combined with good coding practices in output escaping and SQL query handling, suggests a low risk for most WordPress installations. The primary limitation of this assessment is the apparent minimal complexity or interaction points within the plugin, which could potentially mask other risks if more complex functionality exists.

Vulnerabilities
None known

AI-Only Pages Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AI-Only Pages Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
5 prepared
Unescaped Output
2
45 escaped
Nonce Checks
1
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

83% prepared6 total queries

Output Escaping

96% escaped47 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<class-plugin> (includes\class-plugin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AI-Only Pages Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 31
actionadmin_noticesai-only-pages.php:43
actionadmin_noticesai-only-pages.php:58
actioninitincludes\class-plugin.php:197
actioninitincludes\class-plugin.php:198
filterquery_varsincludes\class-plugin.php:199
actionadd_meta_boxesincludes\class-plugin.php:201
actionsave_postincludes\class-plugin.php:202
actionadmin_enqueue_scriptsincludes\class-plugin.php:206
actionwp_headincludes\class-plugin.php:210
actionwpincludes\class-plugin.php:215
actiontemplate_redirectincludes\class-plugin.php:217
actiontemplate_redirectincludes\class-plugin.php:218
actionadmin_noticesincludes\class-plugin.php:220
actionbefore_delete_postincludes\class-plugin.php:227
actiontransition_post_statusincludes\class-plugin.php:228
filterwpseo_robotsincludes\class-plugin.php:239
filterwp_robotsincludes\class-plugin.php:240
filterrank_math/frontend/robotsincludes\class-plugin.php:241
filterwpseo_exclude_from_sitemap_by_post_idsincludes\class-plugin.php:244
filterwp_sitemaps_posts_query_argsincludes\class-plugin.php:245
filterwp_sitemaps_posts_entryincludes\class-plugin.php:246
actionshutdownincludes\class-plugin.php:882
actionplugins_loadedincludes\class-plugin.php:1388
actionadmin_menuincludes\class-settings.php:83
actionadmin_initincludes\class-settings.php:84
actionadmin_enqueue_scriptsincludes\class-settings.php:85
filteraionly_should_clean_outputincludes\class-settings.php:89
filteraionly_strip_token_bloat_tagsincludes\class-settings.php:90
filteraionly_strip_selectorsincludes\class-settings.php:91
actiontemplate_redirectincludes\class-settings.php:95
actionplugins_loadedincludes\class-settings.php:980
Maintenance & Trust

AI-Only Pages Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 12, 2026
PHP min version7.4
Downloads146

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AI-Only Pages Developer Profile

tommyoz12

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AI-Only Pages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ai-only-pages/assets/css/admin.css/wp-content/plugins/ai-only-pages/assets/js/admin.js/wp-content/plugins/ai-only-pages/assets/js/frontend.js
Version Parameters
ai-only-pages/assets/css/admin.css?ver=ai-only-pages/assets/js/admin.js?ver=ai-only-pages/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
aionly-admin-meta-box
Data Attributes
data-aionly-noncedata-aionly-action
JS Globals
window.aionly_admin_params
FAQ

Frequently Asked Questions about AI-Only Pages