Easy MCP AI Security & Risk Analysis

wordpress.org/plugins/easy-mcp-ai

Connect Claude, ChatGPT & any MCP-compatible AI to WordPress — create, edit & manage content without the admin panel. 100+ built-in tools. 100% free.

300 active installs v1.3.1 PHP 7.4+ WP 6.0+ Updated Apr 13, 2026
aiapiautomationmcprest-api
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy MCP AI Safe to Use in 2026?

Generally Safe

Score 100/100

Easy MCP AI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'easy-mcp-ai' v1.3.1 plugin exhibits a generally positive security posture based on the static analysis. A notable strength is the complete absence of SQL injection vulnerabilities, with all queries utilizing prepared statements. Furthermore, output escaping is consistently applied, and there are no external HTTP requests or dangerous functions detected. The plugin also avoids bundling potentially vulnerable third-party libraries. However, the presence of three taint flows with unsanitized paths is a significant concern. While the static analysis did not classify them as critical or high severity, these flows represent potential pathways for attackers to inject malicious data. The complete lack of CVEs in its history is encouraging, suggesting a history of responsible development, but it doesn't negate the risks identified in the current code analysis.

Despite the lack of historical vulnerabilities and good practices in SQL and output handling, the identified taint flows with unsanitized paths present a tangible risk. The absence of nonce checks and capability checks on potential entry points (though none are explicitly found in the attack surface breakdown) could also be a weakness if the plugin's functionality were to expand. The conclusion is that while the plugin demonstrates good security hygiene in many areas, the identified taint flows warrant further investigation and remediation to ensure a robust security profile. The limited attack surface is a positive, but the unaddressed taint flows are the primary area of concern.

Key Concerns

  • Taint flows with unsanitized paths found
  • No nonce checks detected
  • No capability checks on some entry points
Vulnerabilities
None known

Easy MCP AI Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Easy MCP AI Release Timeline

v1.3.1Current
v1.3.0
v1.2.0
v1.1.1
Code Analysis
Analyzed Apr 16, 2026

Easy MCP AI Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
41 prepared
Unescaped Output
0
840 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared41 total queries

Output Escaping

100% escaped840 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
render_tokens_page (includes/admin/class-admin-page.php:404)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Easy MCP AI Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Easy MCP AI Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 13, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

Easy MCP AI Developer Profile

EasyMCPAI

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy MCP AI

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-mcp-ai/assets/css/admin.css/wp-content/plugins/easy-mcp-ai/assets/js/admin.js
Script Paths
/wp-content/plugins/easy-mcp-ai/assets/js/admin.js
Version Parameters
easy-mcp-ai/assets/css/admin.css?ver=easy-mcp-ai/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
easy-mcp-ai-token-form
Data Attributes
data-easy-mcp-ai-nonce
REST Endpoints
/wp-json/easy-mcp-ai/
FAQ

Frequently Asked Questions about Easy MCP AI