AI Try-On Assistant Security & Risk Analysis

wordpress.org/plugins/ai-try-on-assistant

A WooCommerce AI try-on assistant that allows customers to try on clothes, hairstyles, and makeup using Google Gemini AI.

10 active installs v1.0.5 PHP 8.0+ WP 6.8+ Updated Sep 7, 2025
aie-commercegeminivirtual-try-onwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AI Try-On Assistant Safe to Use in 2026?

Generally Safe

Score 100/100

AI Try-On Assistant has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "ai-try-on-assistant" plugin v1.0.5 demonstrates a strong security posture based on the provided static analysis. The complete absence of unprotected entry points, including AJAX handlers and REST API routes, is a significant strength. The plugin also utilizes prepared statements for all its SQL queries, mitigating the risk of SQL injection vulnerabilities. Furthermore, the presence of nonce checks and capability checks on its AJAX handlers suggests a deliberate effort to implement basic security measures.

Key Concerns

  • Unescaped output detected
  • File operation detected
  • External HTTP requests detected
Vulnerabilities
None known

AI Try-On Assistant Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AI Try-On Assistant Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
60 escaped
Nonce Checks
9
Capability Checks
2
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

78% escaped77 total outputs
Attack Surface

AI Try-On Assistant Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 8

authwp_ajax_aitoa_upload_photoincludes\class-aitoa-ajax.php:14
authwp_ajax_aitoa_delete_photoincludes\class-aitoa-ajax.php:15
authwp_ajax_aitoa_try_onincludes\class-aitoa-ajax.php:16
authwp_ajax_aitoa_load_try_on_interfaceincludes\class-aitoa-ajax.php:17
authwp_ajax_aitoa_get_image_dataincludes\class-aitoa-ajax.php:18
authwp_ajax_aitoa_get_user_photoincludes\class-aitoa-ajax.php:19
authwp_ajax_aitoa_validate_imageincludes\class-aitoa-ajax.php:20
authwp_ajax_aitoa_quick_save_try_on_settingsincludes\class-aitoa-ajax.php:21
WordPress Hooks 15
actionbefore_woocommerce_initai-try-on-assistant.php:24
actionadmin_noticesai-try-on-assistant.php:41
actionplugins_loadedai-try-on-assistant.php:58
actionadmin_menuincludes\class-aitoa-admin.php:14
actionadmin_initincludes\class-aitoa-admin.php:15
actionadd_meta_boxesincludes\class-aitoa-admin.php:16
actionsave_postincludes\class-aitoa-admin.php:17
actionwp_footerincludes\class-aitoa-frontend.php:17
actionwoocommerce_edit_account_form_startincludes\class-aitoa-frontend.php:20
actionwoocommerce_edit_account_formincludes\class-aitoa-frontend.php:21
actionwoocommerce_save_account_detailsincludes\class-aitoa-frontend.php:22
actionwp_footerincludes\class-aitoa-frontend.php:25
actionwp_enqueue_scriptsincludes\class-aitoa-main.php:30
actionadmin_enqueue_scriptsincludes\class-aitoa-main.php:31
actionadmin_noticesvirtual-try-on-assistant.php:15
Maintenance & Trust

AI Try-On Assistant Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 7, 2025
PHP min version8.0
Downloads343

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

AI Try-On Assistant Developer Profile

Eric Wu

3 plugins · 10 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AI Try-On Assistant

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ai-try-on-assistant/admin/css/admin-style.css/wp-content/plugins/ai-try-on-assistant/admin/js/admin-script.js/wp-content/plugins/ai-try-on-assistant/public/css/frontend-style.css/wp-content/plugins/ai-try-on-assistant/public/js/frontend-script.js
Script Paths
/wp-content/plugins/ai-try-on-assistant/admin/js/admin-script.js/wp-content/plugins/ai-try-on-assistant/public/js/frontend-script.js
Version Parameters
ai-try-on-assistant/admin/css/admin-style.css?ver=ai-try-on-assistant/admin/js/admin-script.js?ver=ai-try-on-assistant/public/css/frontend-style.css?ver=ai-try-on-assistant/public/js/frontend-script.js?ver=

HTML / DOM Fingerprints

Data Attributes
enctype="multipart/form-data"
JS Globals
aitoa_ajaxaitoa_admin_ajax
FAQ

Frequently Asked Questions about AI Try-On Assistant