Contentra AI Security & Risk Analysis

wordpress.org/plugins/contentra-ai

Generate SEO-optimized content with Google Gemini AI for posts, pages, and products directly in WordPress.

0 active installs v1.2.3 PHP 7.4+ WP 5.8+ Updated Feb 20, 2026
aiblog-writercontent-generatorgeminiseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contentra AI Safe to Use in 2026?

Generally Safe

Score 100/100

Contentra AI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The contentra-ai plugin v1.2.3 demonstrates a generally good security posture with strong adherence to best practices. The static analysis reveals a significant effort to secure its entry points, with 98% of outputs being properly escaped and 89% of SQL queries utilizing prepared statements. The absence of dangerous functions, file operations, and critical/high severity taint flows further bolsters its security. Furthermore, the plugin has no recorded vulnerability history, which indicates a stable and well-maintained codebase. The plugin's strengths lie in its robust output escaping, prepared statement usage, and lack of historical vulnerabilities.

However, a minor concern arises from the presence of one unprotected REST API route. While the attack surface is relatively small with only 11 total entry points, this single unprotected route represents a potential avenue for unauthorized access or manipulation. The plugin also makes 11 external HTTP requests, which could pose a risk if any of these external services are compromised or if the requests are not handled securely. Despite these minor concerns, the overall security of contentra-ai v1.2.3 appears strong, with the developers showing a commitment to secure coding practices.

Key Concerns

  • Unprotected REST API route
Vulnerabilities
None known

Contentra AI Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Contentra AI Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
16 prepared
Unescaped Output
3
150 escaped
Nonce Checks
8
Capability Checks
11
File Operations
0
External Requests
11
Bundled Libraries
0

SQL Query Safety

89% prepared18 total queries

Output Escaping

98% escaped153 total outputs
Attack Surface
1 unprotected

Contentra AI Attack Surface

Entry Points11
Unprotected1

AJAX Handlers 8

authwp_ajax_contentra_generate_contentadmin\class-admin.php:69
authwp_ajax_contentra_save_settingsadmin\class-admin.php:70
authwp_ajax_contentra_proxy_connectadmin\class-admin.php:71
authwp_ajax_contentra_proxy_testadmin\class-admin.php:72
authwp_ajax_contentra_update_post_statusadmin\class-admin.php:73
authwp_ajax_contentra_proxy_statusadmin\class-admin.php:74
authwp_ajax_contentra_ai_test_connectionincludes\class-activation-api.php:15
authwp_ajax_contentra_ai_generate_activation_tokenincludes\class-activation-handler.php:8

REST API Routes 3

POST/wp-json/contentra-ai/v1/activateincludes\class-activation-api.php:28
GET/wp-json/contentra-ai/v1/test-connectionincludes\class-activation-api.php:34
GET/wp-json/contentra/v1/verifyincludes\class-domain-verification.php:29
WordPress Hooks 10
actionadmin_menuadmin\class-admin.php:60
actionadmin_enqueue_scriptsadmin\class-admin.php:63
actionadmin_enqueue_scriptsadmin\class-admin.php:66
actionplugins_loadedcontentra-ai.php:58
actionadmin_initcontentra-ai.php:59
actionrest_api_initincludes\class-activation-api.php:14
actionplugins_loadedincludes\class-activation-api.php:441
actionadmin_initincludes\class-activation-handler.php:65
actionrest_api_initincludes\class-domain-verification.php:24
actionplugins_loadedincludes\class-upgrade.php:31
Maintenance & Trust

Contentra AI Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version7.4
Downloads196

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Contentra AI Developer Profile

Yudiz Solutions Pvt. Ltd.

14 plugins · 6K total installs

85
trust score
Avg Security Score
96/100
Avg Patch Time
59 days
View full developer profile
Detection Fingerprints

How We Detect Contentra AI

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/contentra-ai/admin/css/contentra-ai-admin.css/wp-content/plugins/contentra-ai/admin/js/contentra-ai-admin.js
Script Paths
/wp-content/plugins/contentra-ai/admin/js/contentra-ai-admin.js
Version Parameters
contentra-ai/admin/css/contentra-ai-admin.css?ver=contentra-ai/admin/js/contentra-ai-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
contentra-ai-settings-pagecontentra-ai-input-groupcontentra-ai-api-key-sectioncontentra-ai-dashboard-widget
HTML Comments
<!-- Contentra AI Settings Page --><!-- Contentra AI API Key Input --><!-- Contentra AI Dashboard Widget Start --><!-- Contentra AI Dashboard Widget End -->
Data Attributes
data-contentra-ai-actiondata-contentra-ai-nonce
JS Globals
contentraAiAdmincontentraAiAjaxcontentraAiSettings
REST Endpoints
/wp-json/contentra-ai/v1/settings/wp-json/contentra-ai/v1/generate/wp-json/contentra-ai/v1/verify-domain
FAQ

Frequently Asked Questions about Contentra AI