Magic Featured Image Generator (AI Generated) Security & Risk Analysis

wordpress.org/plugins/auto-featured-image-generator-wai

Generate a post featured image from the title and excerpt using Cloudflare Workers AI, directly from the editor sidebar.

0 active installs v1.1.0 PHP 7.4+ WP 6.0+ Updated Dec 3, 2025
aiai-imageauto-featured-imagefeatured-imageimage-generation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Magic Featured Image Generator (AI Generated) Safe to Use in 2026?

Generally Safe

Score 100/100

Magic Featured Image Generator (AI Generated) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The auto-featured-image-generator-wai plugin version 1.1.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, a complete reliance on prepared statements for SQL queries, and 100% properly escaped output are significant strengths. Furthermore, the plugin demonstrates good practice by implementing capability checks for its entry points. The vulnerability history is clean, with no known CVEs, which suggests a commitment to secure development or a lack of past exploitation.

However, the analysis does reveal a few areas for potential concern. The plugin has two REST API routes, and while the data indicates they have permission callbacks, the total entry points without explicit mention of thorough authorization for all potential interactions could be a minor weakness if not meticulously handled. The lack of nonce checks on AJAX handlers, though there are none listed, would be a critical oversight if any were present and unprotected. The single external HTTP request, without further context, carries a slight inherent risk, as it could be a vector for certain types of attacks if not handled with extreme caution and validation.

In conclusion, this plugin appears to be well-developed from a security perspective, with a commendable absence of common vulnerabilities. The minimal attack surface and robust handling of sensitive operations like SQL and output escaping are positive indicators. The primary areas for vigilance would be ensuring the authorization for the REST API routes is comprehensive and that any future additions, particularly AJAX endpoints, include proper nonce verification.

Key Concerns

  • REST API routes without explicit permission callback mention
  • External HTTP requests without context
Vulnerabilities
None known

Magic Featured Image Generator (AI Generated) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Magic Featured Image Generator (AI Generated) Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Magic Featured Image Generator (AI Generated) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
55 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped55 total outputs
Attack Surface

Magic Featured Image Generator (AI Generated) Attack Surface

Entry Points2
Unprotected0

REST API Routes 2

POST/wp-json/magifeimge/v1/generateauto-featured-image-generator-wai.php:315
POST/wp-json/magifeimge/v1/set-featuredauto-featured-image-generator-wai.php:344
WordPress Hooks 5
actionadmin_initauto-featured-image-generator-wai.php:27
actionadmin_menuauto-featured-image-generator-wai.php:28
actionrest_api_initauto-featured-image-generator-wai.php:29
actionenqueue_block_editor_assetsauto-featured-image-generator-wai.php:30
actionplugins_loadedauto-featured-image-generator-wai.php:408
Maintenance & Trust

Magic Featured Image Generator (AI Generated) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version7.4
Downloads147

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Magic Featured Image Generator (AI Generated) Developer Profile

yorksupport

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Magic Featured Image Generator (AI Generated)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-featured-image-generator-wai/build/index.css/wp-content/plugins/auto-featured-image-generator-wai/build/index.js
Version Parameters
/wp-content/plugins/auto-featured-image-generator-wai/build/index.css?ver=/wp-content/plugins/auto-featured-image-generator-wai/build/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
components-panel__bodymagifeimge-generate-button
Data Attributes
data-magifeimge-account-iddata-magifeimge-api-tokendata-magifeimge-modeldata-magifeimge-widthdata-magifeimge-heightdata-magifeimge-format+4 more
JS Globals
magifeimge_data
REST Endpoints
/wp-json/magifeimge/v1/generate
FAQ

Frequently Asked Questions about Magic Featured Image Generator (AI Generated)