Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images Security & Risk Analysis

wordpress.org/plugins/alt-text-generator

Automatically generate alt text for images using AI technology to improve WordPress website accessibility and SEO.

20 active installs v1.8.6 PHP 5.6+ WP 5.7+ Updated Feb 23, 2026
ai-alt-textai-alt-text-generatoralt-textalt-text-aiimage-alt-text
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 11, 2025
Download
Safety Verdict

Is Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images Safe to Use in 2026?

Generally Safe

Score 99/100

Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Nov 11, 2025Updated 2mo ago
Risk Assessment

The "alt-text-generator" plugin v1.8.6 demonstrates strong adherence to several core WordPress security best practices. The static analysis reveals an absence of dangerous functions, all SQL queries are properly prepared, and all output is correctly escaped, indicating a low risk of common injection and XSS vulnerabilities. Furthermore, all 12 AJAX handlers have nonce checks, and 14 capability checks are implemented, suggesting good protection against unauthorized actions and privilege escalation. The lack of shortcodes, cron events, and REST API routes also limits the overall attack surface considerably. However, the plugin makes 9 external HTTP requests, which, while not a direct vulnerability, represent potential points of failure or compromise if the external services are not secure or become unavailable.

The vulnerability history shows a single past CVE, which is now patched. The fact that it was a "Missing Authorization" vulnerability, coupled with the current implementation of nonce and capability checks on all AJAX handlers, suggests that this past issue may have been addressed. The absence of critical or high severity taint flows further supports the current low risk profile derived from code analysis. Despite these strengths, the presence of any past vulnerability warrants a degree of caution. The plugin appears to be actively maintained and is currently in a good security state with no unpatched vulnerabilities.

In conclusion, "alt-text-generator" v1.8.6 has a generally strong security posture with significant focus on input validation and output escaping. The developer has addressed past security concerns effectively. The main area for potential improvement lies in managing or securing the external HTTP requests to further harden the plugin. The limited attack surface and robust use of WordPress security APIs contribute to a favorable risk assessment for this version.

Key Concerns

  • External HTTP requests observed
Vulnerabilities
1 published

Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-12113medium · 4.3Missing Authorization

Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images <= 1.8.3 - Missing Authorization to Authenticated (Subscriber+) API Key Deletion

Nov 11, 2025 Patched in 1.8.4 (1d)
Version History

Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images Release Timeline

v1.8.6Current
v1.8.5
v1.8.4
v1.8.31 CVE
v1.8.21 CVE
v1.8.11 CVE
v1.8.01 CVE
v1.7.21 CVE
Code Analysis
Analyzed Mar 17, 2026

Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
59 escaped
Nonce Checks
12
Capability Checks
14
File Operations
0
External Requests
9
Bundled Libraries
0

Output Escaping

100% escaped59 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

3 flows
atgai_set_api_key (index.php:357)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images Attack Surface

Entry Points12
Unprotected0

AJAX Handlers 12

authwp_ajax_alt_text_generator_submit_uninstall_reasonincludes\class-uninstall-feedback.php:17
authwp_ajax_atgai_fetch_imagesindex.php:182
authwp_ajax_atgai_get_images_countindex.php:283
authwp_ajax_atgai_set_api_keyindex.php:351
authwp_ajax_atgai_get_api_keyindex.php:352
authwp_ajax_atgai_delete_api_keyindex.php:353
authwp_ajax_atgai_get_settingsindex.php:519
authwp_ajax_atgai_upsert_settingsindex.php:578
authwp_ajax_atgai_update_image_alt_textindex.php:582
authwp_ajax_atgai_get_site_domainindex.php:790
authwp_ajax_atgai_get_userindex.php:818
authwp_ajax_atgai_generate_alt_textindex.php:877
WordPress Hooks 6
actionadmin_footerincludes\class-uninstall-feedback.php:16
actionadmin_enqueue_scriptsindex.php:90
actionadmin_footer-upload.phpindex.php:147
actionadmin_menuindex.php:162
actionadd_attachmentindex.php:687
actionadmin_print_scriptsindex.php:1052
Maintenance & Trust

Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 23, 2026
PHP min version5.6
Downloads3K

Community Trust

Rating60/100
Number of ratings2
Active installs20
Developer Profile

Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images Developer Profile

WebToffee

18 plugins · 377K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
152 days
View full developer profile
Detection Fingerprints

How We Detect Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/alt-text-generator/build/index.js/wp-content/plugins/alt-text-generator/build/index.css/wp-content/plugins/alt-text-generator/build/media-button.js
Script Paths
/wp-content/plugins/alt-text-generator/build/index.js/wp-content/plugins/alt-text-generator/build/media-button.js
Version Parameters
alt-text-generator/build/index.js?v=alt-text-generator/build/index.cssalt-text-generator/build/media-button.js

HTML / DOM Fingerprints

CSS Classes
atgai-app
Data Attributes
data-nonce
JS Globals
atgaiWpApiSettings
REST Endpoints
/wp-json/wp/v2/media
FAQ

Frequently Asked Questions about Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images