
AI Provider for Google Security & Risk Analysis
wordpress.org/plugins/ai-provider-for-googleGoogle AI (Gemini) provider for the PHP AI Client SDK.
Is AI Provider for Google Safe to Use in 2026?
Generally Safe
Score 100/100AI Provider for Google has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'ai-provider-for-google' v1.0.3 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped outputs, file operations, or external HTTP requests is highly commendable. Crucially, the complete lack of any identified taint flows, especially those with unsanitized paths or critical/high severity, indicates robust input handling and sanitization practices. The plugin also demonstrates adherence to WordPress security best practices by not exposing a significant attack surface, with zero AJAX handlers, REST API routes, shortcodes, or cron events directly accessible. Furthermore, the absence of any recorded vulnerabilities or CVEs in its history suggests a well-maintained and secure development lifecycle.
While the static analysis reveals no immediate security weaknesses, the complete absence of nonce and capability checks is a notable concern. Although the current attack surface is zero, this lack of checks implies that if new entry points were to be introduced in future updates, they might be inherently unprotected. This could become a significant liability if the plugin's functionality evolves.
In conclusion, 'ai-provider-for-google' v1.0.3 appears to be a very secure plugin, with excellent adherence to secure coding principles. The primary weakness lies in the complete absence of any authorization checks (nonce and capability), which, while not an issue with the current minimal attack surface, represents a potential risk for future development. The plugin's strong performance in static analysis and its clean vulnerability history are significant strengths.
Key Concerns
- Missing nonce checks
- Missing capability checks
AI Provider for Google Security Vulnerabilities
AI Provider for Google Code Analysis
AI Provider for Google Attack Surface
WordPress Hooks 1
Maintenance & Trust
AI Provider for Google Maintenance & Trust
Maintenance Signals
Community Trust
AI Provider for Google Alternatives
AI Featured Image
ai-featured-image-generator
One-click AI Featured Image Generator using OpenAI model - Free users can bulk-generate up to 5 posts per batch. Pro adds Google Gemini support, unlim …
AI Provider for Anthropic
ai-provider-for-anthropic
Anthropic (Claude) provider for the PHP AI Client SDK.
AI Provider for OpenAI
ai-provider-for-openai
AI Provider for OpenAI for the PHP AI Client SDK.
SummarAIze – Automatically create TL;DRs for your posts
summaraize
AI-powered post summaries using OpenAI or Google Gemini. Instantly boost engagement, SEO, and readability with smart key takeaways.
WebPlanetSoft AI Content Gen – Google Gemini AI Writer, SEO Blog Post & Content Generator
webplanet-ai-content-gen
Create high-quality SEO content with AI. The ultimate AI writer for manual blog posts, smart previews, and auto-categories using Google Gemini.
AI Provider for Google Developer Profile
34 plugins · 14.9M total installs
How We Detect AI Provider for Google
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.