ContentZavod – AI Content Generator & SEO Autopublisher Security & Risk Analysis

wordpress.org/plugins/contentzavod

AI-powered content generator that automatically publishes SEO-optimized articles to your WordPress site daily. Monitors 80+ news sources in 10 languag …

0 active installs v2.5.0 PHP 7.4+ WP 5.0+ Updated Mar 13, 2026
aiautomationcontentpublishingseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ContentZavod – AI Content Generator & SEO Autopublisher Safe to Use in 2026?

Generally Safe

Score 100/100

ContentZavod – AI Content Generator & SEO Autopublisher has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 22d ago
Risk Assessment

The "contentzavod" v2.5.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by not exposing any AJAX handlers, REST API routes, shortcodes, or cron events without authentication, and all identified SQL queries utilize prepared statements. There's also evidence of capability checks and an absence of bundled libraries, reducing potential attack vectors from outdated dependencies.

However, significant concerns arise from the output escaping. With only 48% of outputs properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce checks on entry points, despite a seemingly small attack surface, is also a concern as it leaves potential avenues for cross-site request forgery (CSRF) if any hidden entry points exist or are introduced in future versions. The presence of external HTTP requests, while not inherently a vulnerability, warrants careful monitoring for potential SSRF or data exfiltration if the target URLs are not strictly controlled.

The plugin's vulnerability history is a significant strength, with no recorded CVEs. This, combined with the limited attack surface and secure SQL handling, suggests a developer who is potentially security-conscious. However, the absence of vulnerabilities could also be due to a lack of extensive security testing or a relatively small user base. The current analysis highlights a plugin that has made some good security choices but has a critical weakness in output sanitization that needs immediate attention.

Key Concerns

  • Low output escaping rate
  • Missing nonce checks
Vulnerabilities
None known

ContentZavod – AI Content Generator & SEO Autopublisher Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ContentZavod – AI Content Generator & SEO Autopublisher Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
67
61 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

48% escaped128 total outputs
Attack Surface

ContentZavod – AI Content Generator & SEO Autopublisher Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actioninitcontentzavod.php:82
actiontemplate_redirectcontentzavod.php:85
actionparse_requestcontentzavod.php:88
filterquery_varscontentzavod.php:90
filterrobots_txtcontentzavod.php:93
actionadmin_menucontentzavod.php:96
actionadmin_initcontentzavod.php:97
actionadmin_enqueue_scriptscontentzavod.php:100
actionadmin_noticescontentzavod.php:106
actionplugins_loadedcontentzavod.php:1401
Maintenance & Trust

ContentZavod – AI Content Generator & SEO Autopublisher Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version7.4
Downloads412

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ContentZavod – AI Content Generator & SEO Autopublisher Developer Profile

fittinru

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ContentZavod – AI Content Generator & SEO Autopublisher

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/contentzavod/css/admin.css/wp-content/plugins/contentzavod/js/admin.js

HTML / DOM Fingerprints

CSS Classes
contentzavod-admin-settings
HTML Comments
<!-- ContentZavod Admin Settings --><!-- IndexNow Key Verification --><!-- ContentZavod Sitemap -->
Data Attributes
data-cz-pathdata-cz-tag-slug
JS Globals
contentzavod_ajax_object
FAQ

Frequently Asked Questions about ContentZavod – AI Content Generator & SEO Autopublisher