Featured Image Creator AI Security & Risk Analysis

wordpress.org/plugins/featured-image-creator-ai

Auto-generate stunning AI-powered featured images using OpenAI (DALL-E 3), Google Gemini, or Stability AI. Supports bulk generation and more.

0 active installs v1.0.4 PHP 7.4+ WP 5.8+ Updated Feb 25, 2026
aidall-efeatured-imagegeministable-diffusion
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Featured Image Creator AI Safe to Use in 2026?

Generally Safe

Score 100/100

Featured Image Creator AI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "featured-image-creator-ai" plugin version 1.0.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage (93%) of properly escaped output. The absence of known vulnerabilities in its history is also a strong indicator of past security diligence. Furthermore, no critical or high severity taint flows were identified, suggesting that data processing within the plugin is generally handled with care. However, significant security concerns arise from its attack surface. The presence of 3 AJAX handlers, with 2 lacking any authentication checks, creates a substantial risk. This means that potentially sensitive functionalities could be triggered by unauthenticated users, opening the door for unauthorized actions. While file operations and external HTTP requests are present, the static analysis doesn't explicitly flag them as insecure, and the vulnerability history is clean, suggesting these may be handled appropriately or have not been targeted. The single nonce check on one AJAX handler, coupled with 8 capability checks, indicates some level of authorization is in place, but the two unprotected AJAX endpoints represent a clear and present danger.

Key Concerns

  • 2 unprotected AJAX handlers
  • Limited nonce checks on AJAX
Vulnerabilities
None known

Featured Image Creator AI Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Featured Image Creator AI Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
41 escaped
Nonce Checks
1
Capability Checks
8
File Operations
3
External Requests
6
Bundled Libraries
0

Output Escaping

93% escaped44 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
render_bulk_page (includes\class-bulk-generator.php:177)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Featured Image Creator AI Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 3

authwp_ajax_aifig_batch_generateincludes\class-bulk-generator.php:30
authwp_ajax_aifig_get_batch_idsincludes\class-bulk-generator.php:31
authwp_ajax_aifig_generate_singleincludes\class-post-meta-box.php:27
WordPress Hooks 12
actioninitfeatured-image-creator-ai.php:98
actionfuture_to_publishfeatured-image-creator-ai.php:133
actionadmin_enqueue_scriptsfeatured-image-creator-ai.php:183
filterplugin_row_metafeatured-image-creator-ai.php:222
actionadmin_noticesincludes\class-admin-notices.php:26
filterbulk_actions-edit-postincludes\class-bulk-generator.php:26
filterhandle_bulk_actions-edit-postincludes\class-bulk-generator.php:27
actionadmin_noticesincludes\class-bulk-generator.php:28
actionadmin_menuincludes\class-bulk-generator.php:29
actionadd_meta_boxesincludes\class-post-meta-box.php:26
actionadmin_menuincludes\class-settings.php:26
actionadmin_initincludes\class-settings.php:27
Maintenance & Trust

Featured Image Creator AI Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 25, 2026
PHP min version7.4
Downloads464

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Featured Image Creator AI Developer Profile

Gunjan Jaswal

6 plugins · 150 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Featured Image Creator AI

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/featured-image-creator-ai/assets/css/admin.css/wp-content/plugins/featured-image-creator-ai/assets/js/admin.js
Script Paths
/wp-content/plugins/featured-image-creator-ai/assets/js/admin.js
Version Parameters
featured-image-creator-ai/assets/css/admin.css?ver=featured-image-creator-ai/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
aifig-settings-pageaifig-bulk-generator-pageaifig-post-meta-box
HTML Comments
<!-- Generated by AI Featured Image Creator AI -->
Data Attributes
data-aifig-post-iddata-aifig-nonce
JS Globals
aifigData
FAQ

Frequently Asked Questions about Featured Image Creator AI