Asimov Security & Risk Analysis

wordpress.org/plugins/asimov

Asimov is an AI enhanced platform that can help you write trending content with the best embedded SEO characteristics of the moment in order to maximi …

10 active installs v1.1.0 PHP 7.0+ WP 5.0+ Updated Mar 11, 2021
adviceaiautomationwriting
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Asimov Safe to Use in 2026?

Generally Safe

Score 85/100

Asimov has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "asimov" plugin v1.1.0 exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, raw SQL queries, and file operations, significant concerns arise from its unprotected entry points. All 5 identified REST API routes lack permission callbacks, creating a substantial attack surface that could be exploited by unauthorized users. Furthermore, only 13% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities within these unprotected routes.

The lack of known CVEs and vulnerability history suggests a degree of past security diligence, but this should not overshadow the current findings. The taint analysis showing zero flows with unsanitized paths is a positive sign, but it is undermined by the large number of unprotected REST API endpoints and the poor output escaping, which together present a clear and present danger.

In conclusion, the "asimov" plugin has a critical weakness in its exposed REST API endpoints and insufficient output escaping. While the absence of direct SQL injection or file manipulation vulnerabilities is commendable, the potential for XSS and unauthorized access via the REST API is severe. The plugin's security is significantly compromised by these identified weaknesses, despite its clean vulnerability history.

Key Concerns

  • REST API routes without permission callbacks
  • Low percentage of properly escaped output
  • Unprotected entry points (5)
Vulnerabilities
None known

Asimov Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Asimov Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
40
6 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
10
Bundled Libraries
0

Output Escaping

13% escaped46 total outputs
Attack Surface
5 unprotected

Asimov Attack Surface

Entry Points5
Unprotected5

REST API Routes 5

POST/wp-json/asimov-plugin/v1/save_infoadmin\class-asimov-admin.php:155
POST/wp-json/asimov-plugin/v1/get_infoadmin\class-asimov-admin.php:160
POST/wp-json/asimov-plugin/v1/submit_articleadmin\class-asimov-admin.php:165
POST/wp-json/asimov-plugin/v1/export_articlesadmin\class-asimov-admin.php:170
POST/wp-json/asimov-plugin/v1/post_ga_infoadmin\class-asimov-admin.php:175
WordPress Hooks 15
actionadmin_menuadmin\class-asimov-admin.php:61
actionadmin_initadmin\class-asimov-admin.php:62
filterplugin_localeasimov-plugin.php:46
actionplugins_loadedincludes\class-asimov.php:152
actionadmin_enqueue_scriptsincludes\class-asimov.php:169
actionadmin_enqueue_scriptsincludes\class-asimov.php:170
actionrest_api_initincludes\class-asimov.php:171
actionadd_meta_boxesincludes\class-asimov.php:172
filtercron_schedulesincludes\class-asimov.php:175
filterplugin_localeincludes\class-asimov.php:176
actionasimov_daily_cronincludes\class-asimov.php:183
actionasimov_hourly_cronincludes\class-asimov.php:184
actionexport_articlesincludes\class-asimov.php:187
actionwp_enqueue_scriptsincludes\class-asimov.php:201
actionwp_enqueue_scriptsincludes\class-asimov.php:202

Scheduled Events 2

asimov_hourly_cron
asimov_daily_cron
Maintenance & Trust

Asimov Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedMar 11, 2021
PHP min version7.0
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Asimov Developer Profile

asc27luigi

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Asimov

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/asimov-plugin/admin/css/includes/bootstrap/v4.6.0/bootstrap.min.css/wp-content/plugins/asimov-plugin/admin/fonts/font-awesome/v5.12.2/css/all.css/wp-content/plugins/asimov-plugin/admin/fonts/font-awesome/v5.12.2/css/fontawesome.min.css/wp-content/plugins/asimov-plugin/admin/fonts/font-awesome/v4.7.0/css/font-awesome.min.css/wp-content/plugins/asimov-plugin/admin/css/asimov-plugin.css/wp-content/plugins/asimov-plugin/admin/css/bootstrap-social.css/wp-content/plugins/asimov-plugin/admin/js/asimov-plugin-wizard.js/wp-content/plugins/asimov-plugin/admin/js/includes/bootstrap/v4.6.0/bootstrap.bundle.min.js+2 more
Script Paths
/wp-content/plugins/asimov-plugin/admin/js/asimov-plugin-wizard.js/wp-content/plugins/asimov-plugin/admin/js/includes/bootstrap/v4.6.0/bootstrap.bundle.min.js/wp-content/plugins/asimov-plugin/admin/js/metabox/jquery.circliful.js/wp-content/plugins/asimov-plugin/admin/js/metabox/logic.js
Version Parameters
asimov-plugin/css/asimov-plugin.css?ver=asimov-plugin/css/bootstrap-social.css?ver=asimov-plugin/js/asimov-plugin-wizard.js?ver=asimov-plugin/js/metabox/jquery.circliful.js?ver=asimov-plugin/js/metabox/logic.js?ver=

HTML / DOM Fingerprints

CSS Classes
asimov-plugin-wizardasimov-plugin
Data Attributes
data-noncedata-rest-urldata-remote-urldata-origin-urldata-plugin-url
JS Globals
LOCALIZED_VARS
REST Endpoints
/wp-json/asimov-plugin
FAQ

Frequently Asked Questions about Asimov