
Assistant – Every Day Productivity Apps Security & Risk Analysis
wordpress.org/plugins/assistantAssistant is a plugin that allows you to work more efficiently. It provides you shortcuts to common admin tasks on the front-end of your website.
Is Assistant – Every Day Productivity Apps Safe to Use in 2026?
Generally Safe
Score 95/100Assistant – Every Day Productivity Apps has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "assistant" plugin v1.5.4 exhibits a mixed security posture. On one hand, the static analysis reveals a commendably small attack surface with zero identified entry points that lack authentication or permission checks. This indicates a conscious effort to limit direct exposure. Furthermore, the plugin demonstrates good practices in its handling of SQL queries, with a high percentage utilizing prepared statements, and a significant portion of output is properly escaped, which mitigates certain classes of vulnerabilities.
However, several red flags warrant attention. The vulnerability history is concerning, with a total of four known CVEs, including one high-severity vulnerability. The presence of past vulnerabilities in categories like Cross-site Scripting, Deserialization, Information Exposure, and SSRF suggests recurring security weaknesses within the plugin's development. The taint analysis also flagged one flow with unsanitized paths, which, while not classified as critical or high severity in this analysis, represents a potential vector for attack if exploited in conjunction with other weaknesses. The complete lack of nonce checks on any entry points, despite a substantial number of capability checks, is a significant omission that could be leveraged by attackers.
In conclusion, while the plugin has strengths in its limited attack surface and proper SQL handling, the historical vulnerability patterns and the identified unsanitized path in the taint analysis, coupled with the absence of nonce checks, present notable risks. The fact that there are currently no unpatched vulnerabilities is positive, but the past incidents and the taint analysis result suggest that ongoing vigilance and potential code improvements are necessary to ensure robust security.
Key Concerns
- One taint flow with unsanitized paths
- 0 Nonce checks on entry points
- 1 High severity historical vulnerability
- 3 Medium severity historical vulnerabilities
- 28% of SQL queries not using prepared statements
- 28% of output not properly escaped
Assistant – Every Day Productivity Apps Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
WordPress Assistant <= 1.5.2 - Reflected Cross-Site Scripting
Assistant <= 1.5.1 - Authenticated (Editor+) PHP Object Injection
Assistant – Every Day Productivity Apps <= 1.4.9.1 - Unauthenticated Sensitive Information Exposure
Assistant <= 1.4.3 - Authenticated (Editor+) Server Side Request Forgery
Assistant – Every Day Productivity Apps Release Timeline
Assistant – Every Day Productivity Apps Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Assistant – Every Day Productivity Apps Attack Surface
WordPress Hooks 38
Maintenance & Trust
Assistant – Every Day Productivity Apps Maintenance & Trust
Maintenance Signals
Community Trust
Assistant – Every Day Productivity Apps Alternatives
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor
kadence-blocks
20+ AI-powered Gutenberg Blocks with endless options, enabling top-notch efficiency for high-performance dynamic website creation.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
Page Builder Gutenberg Blocks – CoBlocks
coblocks
CoBlocks is a suite of page builder WordPress blocks for Gutenberg, with 10+ new blocks and a true page builder experience with rows and columns.
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
otter-blocks
Quickly create WordPress pages with 20+ blocks, 100+ ready-to-import designs, and advanced editor extensions. It’s website building, Lego-style!
GenerateBlocks
generateblocks
A small collection of lightweight WordPress blocks that can accomplish nearly anything.
Assistant – Every Day Productivity Apps Developer Profile
3 plugins · 204K total installs
How We Detect Assistant – Every Day Productivity Apps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/assistant/backend/dist/assistant.css/wp-content/plugins/assistant/backend/dist/assistant.js/wp-content/plugins/assistant/backend/dist/assistant.jsassistant/backend/dist/assistant.js?ver=assistant/backend/dist/assistant.css?ver=HTML / DOM Fingerprints
fl-assistantdata-fl-assistant-uiFL_ASSISTANT_DATA/wp-json/fl-assistant/v1