AI Provider for Google Security & Risk Analysis

wordpress.org/plugins/ai-provider-for-google

Google AI (Gemini) provider for the PHP AI Client SDK.

100 active installs v1.0.2 PHP 7.4+ WP 6.9+ Updated Mar 4, 2026
aiartificial-intelligenceconnectorgeminigoogle
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AI Provider for Google Safe to Use in 2026?

Generally Safe

Score 100/100

AI Provider for Google has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin 'ai-provider-for-google' v1.0.3 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped outputs, file operations, or external HTTP requests is highly commendable. Crucially, the complete lack of any identified taint flows, especially those with unsanitized paths or critical/high severity, indicates robust input handling and sanitization practices. The plugin also demonstrates adherence to WordPress security best practices by not exposing a significant attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events directly accessible. Furthermore, the absence of any recorded vulnerabilities or CVEs in its history suggests a well-maintained and secure development lifecycle.

While the static analysis reveals no immediate security weaknesses, the complete absence of nonce and capability checks is a notable concern. Although the current attack surface is zero, this lack of checks implies that if new entry points were to be introduced in future updates, they might be inherently unprotected. This could become a significant liability if the plugin's functionality evolves.

In conclusion, 'ai-provider-for-google' v1.0.3 appears to be a very secure plugin, with excellent adherence to secure coding principles. The primary weakness lies in the complete absence of any authorization checks (nonce and capability), which, while not an issue with the current minimal attack surface, represents a potential risk for future development. The plugin's strong performance in static analysis and its clean vulnerability history are significant strengths.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

AI Provider for Google Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AI Provider for Google Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

AI Provider for Google Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitplugin.php:54
Maintenance & Trust

AI Provider for Google Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 4, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

AI Provider for Google Developer Profile

WordPress.org

34 plugins · 14.9M total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
1718 days
View full developer profile
Detection Fingerprints

How We Detect AI Provider for Google

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about AI Provider for Google