Craftify AI Content Publisher Security & Risk Analysis

wordpress.org/plugins/craftify-ai-content-publisher

Publish blog posts directly from Craftify AI to your WordPress site.

0 active installs v1.0.2 PHP 7.4+ WP 5.0+ Updated Feb 5, 2026
aiautomationblogcontentpublishing
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Craftify AI Content Publisher Safe to Use in 2026?

Generally Safe

Score 100/100

Craftify AI Content Publisher has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The craftify-ai-content-publisher plugin version 1.0.2 demonstrates a generally good security posture based on the provided static analysis. The plugin has a small attack surface with no AJAX handlers or shortcodes, and its REST API routes are protected by permission callbacks. Furthermore, it utilizes prepared statements for all its SQL queries and has limited file operations. The absence of any recorded vulnerabilities in its history is a positive indicator.

However, there are areas for improvement that introduce some risk. A significant concern is the output escaping, where only 52% of outputs are properly escaped. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if untrusted data is displayed without adequate sanitization. The plugin also lacks nonce checks on its entry points, which, while currently protected by capability checks, could be a target for certain types of attacks if those checks were ever bypassed or misconfigured. The presence of external HTTP requests also warrants attention, as they can be a vector for various attacks if not handled securely. The fact that no taint analysis flows were found might indicate limited complexity or scope, but it doesn't entirely rule out potential issues with how data is handled internally, especially given the output escaping concerns.

In conclusion, while craftify-ai-content-publisher has a solid foundation with secure SQL handling and protected entry points, the incomplete output escaping and lack of nonce checks represent potential weaknesses. The absence of past vulnerabilities is encouraging, but these identified code signals suggest a need for more rigorous security practices, particularly in data output sanitization, to mitigate the risk of XSS and other client-side attacks.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks on entry points
Vulnerabilities
None known

Craftify AI Content Publisher Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Craftify AI Content Publisher Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
12 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

52% escaped23 total outputs
Attack Surface

Craftify AI Content Publisher Attack Surface

Entry Points2
Unprotected0

REST API Routes 2

POST/wp-json/craftify-ai/v1/publishcraftify-ai.php:339
GET/wp-json/craftify-ai/v1/verifycraftify-ai.php:407
WordPress Hooks 4
actionadmin_menucraftify-ai.php:59
actionadmin_initcraftify-ai.php:60
actionrest_api_initcraftify-ai.php:61
actionadmin_enqueue_scriptscraftify-ai.php:62
Maintenance & Trust

Craftify AI Content Publisher Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 5, 2026
PHP min version7.4
Downloads150

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Craftify AI Content Publisher Developer Profile

craftifyai

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Craftify AI Content Publisher

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/craftify-ai-content-publisher/assets/css/craftify-ai-admin.css/wp-content/plugins/craftify-ai-content-publisher/assets/js/craftify-ai-admin.js
Script Paths
/wp-content/plugins/craftify-ai-content-publisher/assets/js/craftify-ai-admin.js
Version Parameters
craftify-ai-content-publisher/assets/css/craftify-ai-admin.css?ver=craftify-ai-content-publisher/assets/js/craftify-ai-admin.js?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/craftify-ai/v1/sync
FAQ

Frequently Asked Questions about Craftify AI Content Publisher