
All-Images.ai – IA Image Bank and Custom Image creation Security & Risk Analysis
wordpress.org/plugins/all-images-aiIA Image Bank and Custom Image creation IA
Is All-Images.ai – IA Image Bank and Custom Image creation Safe to Use in 2026?
Generally Safe
Score 90/100All-Images.ai – IA Image Bank and Custom Image creation has a strong security track record. Known vulnerabilities have been patched promptly.
The 'all-images-ai' plugin v1.0.5 presents a mixed security posture. While it demonstrates good practices in SQL query preparation and output escaping, with 80% and 90% respectively, it suffers from a significant concern regarding its attack surface. All eight identified AJAX handlers lack authentication checks, making them vulnerable to unauthorized access and potential exploitation by unauthenticated users. This wide-open entry point is a major security weakness.
The vulnerability history indicates a past high-severity vulnerability related to unrestricted file uploads of dangerous types. Although this vulnerability is currently patched, its recurrence is a potential risk. The taint analysis shows one flow with unsanitized paths, which, while not classified as critical or high, still represents a potential entry point for manipulation if not properly handled. The absence of critical or high-severity taint flows and the fact that the past high-severity vulnerability is patched are positive signs, but the unprotected AJAX handlers and past vulnerability type demand attention.
In conclusion, the plugin has strengths in its code hygiene for SQL and output, but the significant number of unprotected AJAX endpoints and the history of a dangerous file upload vulnerability are critical concerns. Users should be cautious and ensure strict access controls are in place for any site using this plugin, as the potential for unauthenticated actions is high.
Key Concerns
- Unprotected AJAX handlers
- Past high severity vulnerability
- Flow with unsanitized paths
All-Images.ai – IA Image Bank and Custom Image creation Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
All-Images.ai – IA Image Bank and Custom Image creation <= 1.0.4 - Authenticated (Subscriber+) Arbitrary File Upload
All-Images.ai – IA Image Bank and Custom Image creation Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
All-Images.ai – IA Image Bank and Custom Image creation Attack Surface
AJAX Handlers 8
WordPress Hooks 22
Maintenance & Trust
All-Images.ai – IA Image Bank and Custom Image creation Maintenance & Trust
Maintenance Signals
Community Trust
All-Images.ai – IA Image Bank and Custom Image creation Alternatives
Quick Featured Images
quick-featured-images
The time-saving solution for managing tons of featured images within minutes: Set, replace and delete in bulk and set default images for future posts.
Easy Add Thumbnail
easy-add-thumbnail
Automatically sets the featured image to the first image uploaded into the post (any post type with thumbnail support). So easy like that...
Auto Featured Image from Title
auto-featured-image-from-title
Automatically generates an image from the post title of a new or updated post and sets it as the featured image.
Instant Image Generator (AI Image by Gemini, Dall-E and One Click Image from Unsplash, Openverse, Pixabay, Pexels, Giphy)
ai-image
Search millions of stock photos, generate AI images with OpenAI & Gemini, browse GIFs, and import directly to your Media Library.
SNY Auto Featured Image
wp-auto-featured-image
Automatically set a default featured image for posts, pages, or custom post types when none is assigned.
All-Images.ai – IA Image Bank and Custom Image creation Developer Profile
1 plugin · 400 total installs
How We Detect All-Images.ai – IA Image Bank and Custom Image creation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-images-ai/admin/css/all-images-ai-admin.css/wp-content/plugins/all-images-ai/admin/js/all-images-ai-admin.js/wp-content/plugins/all-images-ai/public/css/all-images-ai-public.css/wp-content/plugins/all-images-ai/public/js/all-images-ai-public.jsAll-Images.ai v1.0.5/wp-content/plugins/all-images-ai/admin/js/all-images-ai-admin.js/wp-content/plugins/all-images-ai/public/js/all-images-ai-public.jsall-images-ai-admin-css?ver=all-images-ai-admin-js?ver=all-images-ai-public-css?ver=all-images-ai-public-js?ver=HTML / DOM Fingerprints
all-images-ai-wrapall-images-ai-sectionall-images-ai-search-wrapall-images-ai-result-item<!-- Start All-Images.ai --><!-- End All-Images.ai --><!-- All-Images.ai --><!-- START WRAPPER --><!-- All-Images.ai --><!-- END WRAPPER -->data-api-keydata-noncedata-tabdata-typeall_images_ai_admin_paramsall_images_ai_public_params/wp-json/all-images-ai/v1/generate/wp-json/all-images-ai/v1/search[all_images_ai_search][all_images_ai_gallery]