
AI Services Security & Risk Analysis
wordpress.org/plugins/ai-servicesMakes AI centrally available in WordPress, whether via PHP, REST API, JavaScript, or WP-CLI - for any provider.
Is AI Services Safe to Use in 2026?
Generally Safe
Score 100/100AI Services has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ai-services" plugin v0.7.4 demonstrates a generally strong security posture based on the provided static analysis. The absence of any identified vulnerabilities in its history and the complete avoidance of dangerous functions, raw SQL queries, and external HTTP requests are commendable. The high percentage of properly escaped output further reinforces this positive impression, indicating that the developers have taken care to prevent common cross-site scripting (XSS) vulnerabilities. The plugin also has a zero attack surface, meaning no direct entry points that could be exploited.
However, there are significant concerns that temper this otherwise positive assessment. The complete lack of nonce checks and capability checks across all entry points (even though there are none currently) is a major red flag. If any entry points were to be introduced in future versions without proper authentication and authorization mechanisms, this could lead to severe security vulnerabilities. The presence of the Guzzle library, a bundled dependency, also presents a potential risk if it is outdated or contains known vulnerabilities, though this is not explicitly stated in the provided data. The absence of taint analysis results is also notable; while it could mean no issues were found, it could also indicate that the analysis was incomplete or not performed.
In conclusion, while "ai-services" v0.7.4 has a clean vulnerability history and good coding practices in terms of output escaping and SQL prepared statements, the fundamental lack of authentication and authorization checks on potential entry points is a critical weakness. The plugin's current security is heavily reliant on its minimal attack surface, which is not a sustainable long-term security strategy. Developers should prioritize implementing robust authentication and authorization for any future additions or modifications to the plugin.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Bundled library (Guzzle)
AI Services Security Vulnerabilities
AI Services Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
AI Services Attack Surface
WordPress Hooks 23
Maintenance & Trust
AI Services Maintenance & Trust
Maintenance Signals
Community Trust
AI Services Alternatives
Genie Image – Image Generation with its AI Magic
genie-image-ai
Ai Image Generator, Open AI DALL-E 2, Image Generator Plugin, Blog post Image generator, AI Image Creation, WordPress Image Generator, Openai photo ge …
AI Auto Post & Image Generator
ai-auto-post-image-generator
Automate your WordPress content creation with AI-powered text and image generation. Support for OpenAI, Google Gemini, Pollinations, and Leonardo.AI.
ClipCloud – Image Generation
clipcloud-image-generation
Create images for your posts and articles with ClipCloud AI — automatically, conveniently, and fast. Always a free plan.
AI Entries
ai-entries
This plugin uses Google artificial intelligence (GEMINI), Stability AI, and News API to automate the creation of WordPress posts based on configurable …
AI Generator
ai-generator
A powerful WordPress AI content generation plugin that helps you create better content with AI.
AI Services Developer Profile
12 plugins · 18K total installs
How We Detect AI Services
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ai-services/build/chatbot/index.js/wp-content/plugins/ai-services/build/chatbot/style-index.css/wp-content/plugins/ai-services/build/chatbot/index.jsai-services/style.css?ver=ai-services/script.js?ver=HTML / DOM Fingerprints
chatbot-rootdata-block=""data-block-type=""data-block-content=""/wp-json/ai-services/v1/chatbot<div id="ai-services-chatbot-root" class="chatbot-root"></div>