Comet AI Says: Product Descriptions Security & Risk Analysis

wordpress.org/plugins/comet-ai-says

Generate contextual AI product descriptions on-the-fly and store them in custom fields without messing with your existing descriptions.

0 active installs v1.1.7 PHP 7.4+ WP 5.8+ Updated Dec 25, 2025
aicustom-fieldsgptproduct-descriptionswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Comet AI Says: Product Descriptions Safe to Use in 2026?

Generally Safe

Score 100/100

Comet AI Says: Product Descriptions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "comet-ai-says" v1.1.7 plugin demonstrates a generally good security posture with a notable strength in its handling of SQL queries, with 100% using prepared statements. The plugin also exhibits strong output escaping practices, with 94% of outputs properly escaped, and a good number of nonce and capability checks are implemented. However, a significant concern arises from the presence of one unprotected AJAX handler, which represents a direct attack vector into the plugin's functionality. While there is no recorded vulnerability history or critical taint analysis findings, the unprotected AJAX handler warrants attention as it could potentially be exploited by an attacker.

Key Concerns

  • Unprotected AJAX handler found
Vulnerabilities
None known

Comet AI Says: Product Descriptions Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Comet AI Says: Product Descriptions Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
113 escaped
Nonce Checks
9
Capability Checks
4
File Operations
3
External Requests
5
Bundled Libraries
0

Output Escaping

94% escaped120 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
extra_tablenav (includes\class-ai-products-table.php:276)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Comet AI Says: Product Descriptions Attack Surface

Entry Points7
Unprotected1

AJAX Handlers 6

authwp_ajax_wpcmt_aisays_check_existing_descriptionincludes\class-admin-interface.php:44
authwp_ajax_wpcmt_aisays_generate_single_ai_descriptionincludes\class-admin-interface.php:45
authwp_ajax_wpcmt_aisays_generate_ai_descriptionincludes\class-ai-generator.php:20
authwp_ajax_wpcmt_aisays_save_ai_descriptionincludes\class-ai-generator.php:21
authwp_ajax_wpcmt_aisays_get_ai_descriptionincludes\class-ai-generator.php:22
authwp_ajax_wpcmt_aisays_delete_ai_descriptionincludes\class-ai-generator.php:23

Shortcodes 1

[comet-ai-says-product-description] includes\class-frontend-display.php:15
WordPress Hooks 15
actioninitcomet-ai-says.php:60
actionadmin_initcomet-ai-says.php:61
actiontemplate_redirectcomet-ai-says.php:62
actionadmin_menuincludes\class-admin-interface.php:36
actionadmin_initincludes\class-admin-interface.php:37
actionadd_meta_boxesincludes\class-admin-interface.php:38
actionadmin_noticesincludes\class-admin-interface.php:39
actionadmin_enqueue_scriptsincludes\class-admin-interface.php:41
actionadmin_post_generate_bulk_ai_descriptionsincludes\class-admin-interface.php:42
actionadmin_initincludes\class-admin-interface.php:43
actionsave_post_productincludes\class-admin-interface.php:46
actionwoocommerce_single_product_summaryincludes\class-frontend-display.php:25
actionwoocommerce_after_single_product_summaryincludes\class-frontend-display.php:29
actionwoocommerce_after_single_product_summaryincludes\class-frontend-display.php:33
actionwoocommerce_after_single_productincludes\class-frontend-display.php:37
Maintenance & Trust

Comet AI Says: Product Descriptions Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 25, 2025
PHP min version7.4
Downloads249

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Comet AI Says: Product Descriptions Developer Profile

wpComet

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Comet AI Says: Product Descriptions

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/comet-ai-says/assets/css/wpcmt-aisays-style.css/wp-content/plugins/comet-ai-says/assets/js/wpcmt-aisays-script.js
Script Paths
/wp-content/plugins/comet-ai-says/assets/js/wpcmt-aisays-script.js
Version Parameters
v=1.1.7

HTML / DOM Fingerprints

CSS Classes
wpcmt-aisays-settingswpcmt-aisays-inputwpcmt-aisays-button
Data Attributes
data-wpcmt-aisays-providerdata-wpcmt-aisays-gemini-modeldata-wpcmt-aisays-openai-modeldata-wpcmt-aisays-display-modedata-wpcmt-aisays-display-position
JS Globals
wpcmt_aisays_script_vars
Shortcode Output
[comet-ai-says-product-description]
FAQ

Frequently Asked Questions about Comet AI Says: Product Descriptions