Auto-Install Free SSL – Generate & Install Free SSL Certificates Security & Risk Analysis

wordpress.org/plugins/auto-install-free-ssl

Generate & install Free SSL Certificates for WordPress, HTTPS redirect, get PADLOCK in the browser, get automatic Renewal Reminders from plugin.

9K active installs v4.6.1 PHP 5.6+ WP 4.1+ Updated Dec 24, 2025
free-sslfree-ssl-certificatehttps-redirectssl-certificatessl-security
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Auto-Install Free SSL – Generate & Install Free SSL Certificates Safe to Use in 2026?

Generally Safe

Score 100/100

Auto-Install Free SSL – Generate & Install Free SSL Certificates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The auto-install-free-ssl plugin version 4.6.1 exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query handling and a lack of recorded critical vulnerabilities, significant concerns arise from its attack surface and output escaping. The presence of an unprotected AJAX handler presents a clear entry point for potential unauthorized actions or information disclosure if not properly secured by the application logic. Furthermore, the extremely low percentage of properly escaped output is a major red flag, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities that could be exploited by attackers to inject malicious code into user interfaces. The taint analysis showing a high number of flows with unsanitized paths, although not reaching critical or high severity, further reinforces the concern around input sanitization. The plugin's history of zero CVEs is positive, suggesting a generally stable codebase, but this must be weighed against the immediate risks identified in the static analysis.

Key Concerns

  • Unprotected AJAX handler found
  • Low percentage of properly escaped output
  • High number of unsanitized paths in taint analysis
  • Bundled library (Freemius) potentially outdated
Vulnerabilities
None known

Auto-Install Free SSL – Generate & Install Free SSL Certificates Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Auto-Install Free SSL – Generate & Install Free SSL Certificates Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
196
9 escaped
Nonce Checks
17
Capability Checks
2
File Operations
31
External Requests
9
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

4% escaped205 total outputs
Data Flows
13 unsanitized

Data Flow Analysis

18 flows13 with unsanitized paths
aifs_download_file_handler (auto-install-free-ssl.php:725)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Auto-Install Free SSL – Generate & Install Free SSL Certificates Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_aifs_update_optionauto-install-free-ssl.php:721
WordPress Hooks 31
actionaifs_display_review_initauto-install-free-ssl.php:624
actionaifs_display_announcement_initauto-install-free-ssl.php:634
actionaifs_display_discount_offer_initauto-install-free-ssl.php:644
actionadmin_noticesauto-install-free-ssl.php:670
actionaifs_do_this_dailyauto-install-free-ssl.php:718
filteris_submenu_visibleauto-install-free-ssl.php:885
filteruninstall_reasonsauto-install-free-ssl.php:917
actionafter_uninstallauto-install-free-ssl.php:990
actionadmin_initauto-install-free-ssl.php:995
actionadmin_menuauto-install-free-ssl.php:997
actioninitauto-install-free-ssl.php:999
actionadmin_enqueue_scriptsauto-install-free-ssl.php:1007
actionadmin_enqueue_scriptsauto-install-free-ssl.php:1008
actionadmin_initauto-install-free-ssl.php:1009
filtercheckout/parametersauto-install-free-ssl.php:1020
actionadmin_noticesFreeSSLAuto\src\Admin\AdminNotice.php:102
actionadmin_initFreeSSLAuto\src\Admin\AdminNotice.php:106
actionadmin_menuFreeSSLAuto\src\Admin\ForceHttpsPage.php:52
actionadmin_initFreeSSLAuto\src\Admin\ForceSSL.php:64
actionwpFreeSSLAuto\src\Admin\ForceSSL.php:67
actionwp_loadedFreeSSLAuto\src\Admin\ForceSSL.php:69
actionadmin_initFreeSSLAuto\src\Admin\ForceSSL.php:72
actioninitFreeSSLAuto\src\Admin\ForceSSL.php:74
actionshutdownFreeSSLAuto\src\Admin\ForceSSL.php:76
actionwp_print_scriptsFreeSSLAuto\src\Admin\ForceSSL.php:126
actionwpFreeSSLAuto\src\Admin\ForceSSL.php:129
actionadmin_menuFreeSSLAuto\src\Admin\GenerateSSLmanually.php:80
actionadmin_initFreeSSLAuto\src\Admin\GenerateSSLmanually.php:81
actionadmin_initFreeSSLAuto\src\Admin\GenerateSSLmanually.php:82
actionadmin_enqueue_scriptsFreeSSLAuto\src\Admin\HomeOptions.php:53
actionadmin_menuFreeSSLAuto\src\Admin\Log.php:54

Scheduled Events 4

aifs_do_this_daily
aifs_display_review_init
aifs_display_announcement_init
aifs_display_discount_offer_init
Maintenance & Trust

Auto-Install Free SSL – Generate & Install Free SSL Certificates Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 24, 2025
PHP min version5.6
Downloads501K

Community Trust

Rating98/100
Number of ratings397
Active installs9K
Developer Profile

Auto-Install Free SSL – Generate & Install Free SSL Certificates Developer Profile

Anindya Sundar Mandal

1 plugin · 9K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Auto-Install Free SSL – Generate & Install Free SSL Certificates

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/auto-install-free-ssl/css/aifs-admin-notice.css/wp-content/plugins/auto-install-free-ssl/css/aifs-style.css/wp-content/plugins/auto-install-free-ssl/js/aifs-admin-script.js/wp-content/plugins/auto-install-free-ssl/js/aifs-frontend-script.js
Script Paths
/wp-content/plugins/auto-install-free-ssl/js/aifs-admin-script.js/wp-content/plugins/auto-install-free-ssl/js/aifs-frontend-script.js
Version Parameters
auto-install-free-ssl/css/aifs-admin-notice.css?ver=auto-install-free-ssl/css/aifs-style.css?ver=auto-install-free-ssl/js/aifs-admin-script.js?ver=auto-install-free-ssl/js/aifs-frontend-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
aifs-admin-noticeaifs-styleauto-install-free-ssl
HTML Comments
<!-- START Freemius--><!-- END Freemius--><!--START Freemius--><!--END Freemius-->
Data Attributes
data-aifs-plugin-version
JS Globals
aifs_admin_paramsaifs_frontend_params
REST Endpoints
/wp-json/auto-install-free-ssl/
FAQ

Frequently Asked Questions about Auto-Install Free SSL – Generate & Install Free SSL Certificates