Api.co.id GhostWriter Security & Risk Analysis

wordpress.org/plugins/apicoid-ghostwriter

AI-powered content generation plugin that connects to Api.co.id to automatically create and rewrite articles with SEO optimization.

40 active installs v1.4.6 PHP 7.4+ WP 6.2+ Updated Mar 4, 2026
aiarticle-generatorautomationcontent-generationseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Api.co.id GhostWriter Safe to Use in 2026?

Generally Safe

Score 100/100

Api.co.id GhostWriter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The apicoid-ghostwriter plugin v1.4.6 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices, with a high percentage of SQL queries using prepared statements and a significant proportion of outputs being properly escaped. Crucially, all identified entry points, including AJAX handlers, appear to be protected by authentication checks. The absence of file operations and external HTTP requests within the analyzed flows also reduces the attack surface in those areas. Furthermore, the plugin has no recorded vulnerability history, which is a very positive indicator of its stability and secure development over time.

However, there is one identified taint flow with an unsanitized path, which warrants attention. While labeled as non-critical, this type of flow can sometimes lead to path traversal vulnerabilities if not handled carefully. The presence of external HTTP requests, though not inherently a vulnerability, is an area that typically requires careful scrutiny for potential information disclosure or dependency on external services that could be compromised.

In conclusion, apicoid-ghostwriter v1.4.6 is well-secured with robust protections in place for its entry points and data handling. The lack of historical vulnerabilities is a testament to its maintainers' diligence. The single taint flow with an unsanitized path represents a minor area for improvement, but overall, the plugin appears to be a safe option.

Key Concerns

  • Taint flow with unsanitized path
Vulnerabilities
None known

Api.co.id GhostWriter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Api.co.id GhostWriter Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
22 prepared
Unescaped Output
11
170 escaped
Nonce Checks
19
Capability Checks
26
File Operations
0
External Requests
9
Bundled Libraries
0

SQL Query Safety

92% prepared24 total queries

Output Escaping

94% escaped181 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

6 flows1 with unsanitized paths
ajax_validate_api_key (apicoid-ghostwriter.php:885)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Api.co.id GhostWriter Attack Surface

Entry Points18
Unprotected0

AJAX Handlers 18

authwp_ajax_apicoid_gw_save_presetapicoid-ghostwriter.php:82
authwp_ajax_apicoid_gw_delete_presetapicoid-ghostwriter.php:83
authwp_ajax_apicoid_gw_validate_api_keyapicoid-ghostwriter.php:95
authwp_ajax_apicoid_gw_check_api_key_statusapicoid-ghostwriter.php:98
authwp_ajax_apicoid_gw_generate_articleapicoid-ghostwriter.php:101
authwp_ajax_apicoid_gw_rewrite_articleapicoid-ghostwriter.php:104
authwp_ajax_apicoid_gw_delete_articleapicoid-ghostwriter.php:107
authwp_ajax_apicoid_gw_get_article_suggestionsapicoid-ghostwriter.php:110
authwp_ajax_apicoid_gw_generate_featured_imageapicoid-ghostwriter.php:113
authwp_ajax_apicoid_gw_generate_image_from_promptapicoid-ghostwriter.php:116
authwp_ajax_apicoid_gw_generate_article_by_categoryapicoid-ghostwriter.php:118
authwp_ajax_apicoid_gw_save_google_index_settingsapicoid-ghostwriter.php:121
authwp_ajax_apicoid_gw_test_google_indexapicoid-ghostwriter.php:124
authwp_ajax_apicoid_gw_get_google_index_logsapicoid-ghostwriter.php:127
authwp_ajax_apicoid_gw_clear_google_index_logsapicoid-ghostwriter.php:130
authwp_ajax_apicoid_gw_save_auto_schedule_settingsapicoid-ghostwriter.php:133
authwp_ajax_apicoid_gw_auto_schedule_postapicoid-ghostwriter.php:134
authwp_ajax_apicoid_gw_rearrange_schedule_queueapicoid-ghostwriter.php:135
WordPress Hooks 10
actionplugins_loadedapicoid-ghostwriter.php:70
actioninitapicoid-ghostwriter.php:73
actionadmin_initapicoid-ghostwriter.php:76
actionadmin_initapicoid-ghostwriter.php:79
actionadmin_initapicoid-ghostwriter.php:86
actionadmin_menuapicoid-ghostwriter.php:89
actiontransition_post_statusapicoid-ghostwriter.php:138
actionadmin_enqueue_scriptsapicoid-ghostwriter.php:141
actionadmin_noticesapicoid-ghostwriter.php:144
actionadmin_post_apicoid_gw_create_tableapicoid-ghostwriter.php:147
Maintenance & Trust

Api.co.id GhostWriter Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.4
Downloads641

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Api.co.id GhostWriter Developer Profile

Api.co.id

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Api.co.id GhostWriter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/apicoid-ghostwriter/assets/css/backend.css/wp-content/plugins/apicoid-ghostwriter/assets/js/backend.js/wp-content/plugins/apicoid-ghostwriter/assets/js/frontend.js/wp-content/plugins/apicoid-ghostwriter/assets/css/frontend.css/wp-content/plugins/apicoid-ghostwriter/assets/css/components.css
Generator Patterns
Api.co.id GhostWriter 1.4.6
Script Paths
/wp-content/plugins/apicoid-ghostwriter/assets/js/backend.js/wp-content/plugins/apicoid-ghostwriter/assets/js/frontend.js
Version Parameters
apicoid-ghostwriter/assets/css/backend.css?ver=apicoid-ghostwriter/assets/js/backend.js?ver=apicoid-ghostwriter/assets/js/frontend.js?ver=apicoid-ghostwriter/assets/css/frontend.css?ver=apicoid-ghostwriter/assets/css/components.css?ver=

HTML / DOM Fingerprints

CSS Classes
apicoid-gw-preset-item
HTML Comments
<!-- Api.co.id GhostWriter by Api.co.id -->
Data Attributes
data-noncedata-actiondata-preset-id
JS Globals
apicoid_gw_params
REST Endpoints
/wp-json/apicoid-gw/v1/presets/wp-json/apicoid-gw/v1/settings
Shortcode Output
[apicoid_gw_generator][apicoid_gw_rewriter]
FAQ

Frequently Asked Questions about Api.co.id GhostWriter