BlogWolf – AI Blog Post Generator & Auto-Pilot Content Writer Security & Risk Analysis

wordpress.org/plugins/blogwolf

Generate AI blog posts with images in one click. Auto-pilot mode writes and publishes SEO-optimized articles with WooCommerce support.

0 active installs v3.0.2 PHP 7.4+ WP 5.9+ Updated Unknown
ai-content-generatorai-writerauto-publishblog-post-generatorwoocommerce-blog
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BlogWolf – AI Blog Post Generator & Auto-Pilot Content Writer Safe to Use in 2026?

Generally Safe

Score 100/100

BlogWolf – AI Blog Post Generator & Auto-Pilot Content Writer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "blogwolf" v3.0.2 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the consistent use of prepared statements for SQL queries, and 100% proper output escaping are significant strengths. Furthermore, the plugin correctly implements nonce checks for all identified AJAX handlers and applies capability checks to a substantial number of its entry points. The vulnerability history also shows no known CVEs, suggesting a good track record of security.

However, a notable concern is the presence of one REST API route that lacks permission callbacks. This creates a potential entry point for unauthorized access or manipulation if not properly secured by other means. Additionally, the taint analysis revealed four flows with unsanitized paths, although they are not classified as critical or high severity. While this indicates a lack of direct critical risks from unsanitized paths in this version, it is an area that warrants attention for future updates to ensure robust security against path traversal or related vulnerabilities. The plugin's reliance on file operations and external HTTP requests, while not inherently insecure, could introduce risks if not handled with extreme care.

In conclusion, "blogwolf" v3.0.2 is in a strong security position with robust internal code practices. The primary area for improvement is addressing the unprotected REST API route. The unsanitized path flows, while not critical, should be reviewed to eliminate any potential for future exploitation. The plugin's lack of historical vulnerabilities is a positive indicator, but ongoing vigilance and security audits are always recommended.

Key Concerns

  • Unprotected REST API route
  • Flows with unsanitized paths (not critical)
Vulnerabilities
None known

BlogWolf – AI Blog Post Generator & Auto-Pilot Content Writer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

BlogWolf – AI Blog Post Generator & Auto-Pilot Content Writer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
124 escaped
Nonce Checks
5
Capability Checks
22
File Operations
1
External Requests
4
Bundled Libraries
0

Output Escaping

100% escaped124 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
blogwolf_ajax_api_proxy (blogwolf.php:739)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

BlogWolf – AI Blog Post Generator & Auto-Pilot Content Writer Attack Surface

Entry Points21
Unprotected1

AJAX Handlers 5

authwp_ajax_blogwolf_loginblogwolf.php:595
authwp_ajax_blogwolf_signupblogwolf.php:687
authwp_ajax_blogwolf_disconnectblogwolf.php:702
authwp_ajax_blogwolf_check_sessionblogwolf.php:737
authwp_ajax_blogwolf_api_proxyblogwolf.php:773

REST API Routes 16

GET/wp-json/blogwolf/v1/infoblogwolf.php:205
POST/wp-json/blogwolf/v1/yoast-meta/(?P<id>\d+)blogwolf.php:211
POST/wp-json/blogwolf/v1/postsblogwolf.php:224
GET/wp-json/blogwolf/v1/posts/(?P<id>\d+)blogwolf.php:230
POST/wp-json/blogwolf/v1/mediablogwolf.php:243
POST/wp-json/blogwolf/v1/media/(?P<id>\d+)blogwolf.php:249
GET/wp-json/blogwolf/v1/categoriesblogwolf.php:262
GET/wp-json/blogwolf/v1/templatesblogwolf.php:268
GET/wp-json/blogwolf/v1/postsblogwolf.php:274
GET/wp-json/blogwolf/v1/pagesblogwolf.php:280
GET/wp-json/blogwolf/v1/author-bioblogwolf.php:286
GET/wp-json/blogwolf/v1/productsblogwolf.php:292
GET/wp-json/blogwolf/v1/product-categoriesblogwolf.php:298
GET/wp-json/blogwolf/v1/product-tagsblogwolf.php:304
POST/wp-json/blogwolf/v1/revokeblogwolf.php:310
POST/wp-json/blogwolf/v1/publishblogwolf.php:316
WordPress Hooks 14
actionsave_postblogwolf.php:38
actiondelete_postblogwolf.php:39
actiontrashed_postblogwolf.php:40
actionuntrashed_postblogwolf.php:41
actioncreated_categoryblogwolf.php:48
actionedited_categoryblogwolf.php:49
actiondelete_categoryblogwolf.php:50
actionadmin_menublogwolf.php:126
actionadmin_enqueue_scriptsblogwolf.php:189
actionadmin_headblogwolf.php:198
actionrest_api_initblogwolf.php:324
actionadmin_noticesblogwolf.php:3317
filterrest_pre_serve_requestblogwolf.php:3338
actioninitblogwolf.php:3353
Maintenance & Trust

BlogWolf – AI Blog Post Generator & Auto-Pilot Content Writer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads310

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

BlogWolf – AI Blog Post Generator & Auto-Pilot Content Writer Developer Profile

BlogWolf

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BlogWolf – AI Blog Post Generator & Auto-Pilot Content Writer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/blogwolf/assets/css/blogwolf-admin.css/wp-content/plugins/blogwolf/assets/js/blogwolf-admin.js
Script Paths
assets/js/blogwolf-admin.js
Version Parameters
blogwolf-admin.css?ver=blogwolf-admin.js?ver=

HTML / DOM Fingerprints

JS Globals
blogwolfAdmin
REST Endpoints
/wp-json/blogwolf/v1/info/wp-json/blogwolf/v1/yoast-meta//wp-json/blogwolf/v1/posts/wp-json/blogwolf/v1/posts//wp-json/blogwolf/v1/media
FAQ

Frequently Asked Questions about BlogWolf – AI Blog Post Generator & Auto-Pilot Content Writer