AI Infographic Maker Security & Risk Analysis

wordpress.org/plugins/infographic-and-list-builder-ilist

AI Infographic maker with charts and graphs. Make Listicles, HTML infographics quickly with OpenAI ChatGPT.

700 active installs v5.1.5 PHP 5.6+ WP 4.6+ Updated Dec 17, 2025
aichartsinfographiclisticleopenai
95
A · Safe
CVEs total4
Unpatched0
Last CVEJan 30, 2025
Safety Verdict

Is AI Infographic Maker Safe to Use in 2026?

Generally Safe

Score 95/100

AI Infographic Maker has a strong security track record. Known vulnerabilities have been patched promptly.

4 known CVEsLast CVE: Jan 30, 2025Updated 3mo ago
Risk Assessment

The "infographic-and-list-builder-ilist" plugin, version 5.1.5, exhibits a mixed security posture. While it demonstrates good practices in several areas, such as using prepared statements for all SQL queries and implementing a substantial number of nonce and capability checks, significant concerns remain. The presence of one AJAX handler without authentication checks creates a notable attack vector. Furthermore, the plugin has a history of four known CVEs, including one critical vulnerability, indicating a recurring pattern of security weaknesses despite recent patching. The common vulnerability types suggest potential issues with input validation and authorization, which, combined with the static analysis findings, require careful attention.

Key Concerns

  • AJAX handler without authentication
  • History of 4 CVEs, including 1 critical
  • 73% of output escaped (concern)
  • Flow with unsanitized paths
Vulnerabilities
4

AI Infographic Maker Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
2 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Critical
1
Medium
3

4 total CVEs

CVE-2024-12415medium · 6.5Improper Control of Generation of Code ('Code Injection')

AI Infographic Maker <= 4.9.0 - Unauthenticated Arbitrary Shortcode Execution

Jan 30, 2025 Patched in 5.0.0 (1d)
CVE-2024-5858medium · 4.3Missing Authorization

Infographic Maker iList <= 4.7.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Title Update

Jun 14, 2024 Patched in 4.7.5 (1d)
CVE-2024-32696medium · 5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

AI Infographic Maker <= 4.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 19, 2024 Patched in 4.6.8 (6d)
CVE-2022-0747critical · 9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Infographic Maker – iList <= 4.3.7 - SQL Injection

Feb 28, 2022 Patched in 4.3.8 (694d)
Code Analysis
Analyzed Mar 16, 2026

AI Infographic Maker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
376
1028 escaped
Nonce Checks
14
Capability Checks
19
File Operations
3
External Requests
7
Bundled Libraries
2

Bundled Libraries

jQueryTinyMCE

SQL Query Safety

100% prepared4 total queries

Output Escaping

73% escaped1404 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

7 flows1 with unsanitized paths
goodbye_form_callback (class-plugin-deactivate-feedback.php:400)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

AI Infographic Maker Attack Surface

Entry Points23
Unprotected1

AJAX Handlers 21

authwp_ajax_goodbye_formclass-plugin-deactivate-feedback.php:62
authwp_ajax_cmb2_oembed_handlerinc\CMB2\includes\CMB2_Ajax.php:51
noprivwp_ajax_cmb2_oembed_handlerinc\CMB2\includes\CMB2_Ajax.php:52
authwp_ajax_qcld_ilist_floating_openai_keyword_suggestion_content_functioninc\inc\qcld_openai_floating_content.php:389
noprivwp_ajax_qcld_ilist_floating_openai_keyword_suggestion_content_functioninc\inc\qcld_openai_floating_content.php:390
authwp_ajax_qcld_ilist_floating_openai_save_draft_post_extrainc\inc\qcld_openai_floating_content.php:1558
noprivwp_ajax_qcld_ilist_floating_openai_save_draft_post_extrainc\inc\qcld_openai_floating_content.php:1559
authwp_ajax_qcld_ilist_floating_openai_keyword_rewrite_articleinc\inc\qcld_openai_floating_content.php:1650
noprivwp_ajax_qcld_ilist_floating_openai_keyword_rewrite_articleinc\inc\qcld_openai_floating_content.php:1651
authwp_ajax_qcld_ilist_floating_openai_qcld_ilist_content_generator_by_ajaxinc\inc\qcld_openai_floating_content.php:1764
noprivwp_ajax_qcld_ilist_floating_openai_qcld_ilist_content_generator_by_ajaxinc\inc\qcld_openai_floating_content.php:1765
authwp_ajax_qcld_upvote_actionqc-project-ilist-ajax.php:177
noprivwp_ajax_qcld_upvote_actionqc-project-ilist-ajax.php:178
authwp_ajax_show_ilist_templatesqc-project-ilist-ajax.php:351
noprivwp_ajax_show_ilist_templatesqc-project-ilist-ajax.php:352
authwp_ajax_show_shortcodesqc-project-ilist-ajax.php:433
authwp_ajax_qcld_openai_title_generate_descqc-project-ilist-ajax.php:606
authwp_ajax_ilist_embaded_list_url_infoqc-project-ilist-post-type.php:646
noprivwp_ajax_ilist_embaded_list_url_infoqc-project-ilist-post-type.php:647
authwp_ajax_qcilist_process_qc_promo_formqc-support-promo-page\class-qc-support-promo-page.php:116
authwp_ajax_qcld_recommend_support_function_ajaxqc-support-promo-page\qc-clr-recommendbot-support-plugin.php:8

Shortcodes 2

[qcld-chart] qc-project-ilist-chart.php:130
[qcld-ilist] qc-project-ilist-shortcode.php:13
WordPress Hooks 98
actionadmin_footer-plugins.phpclass-plugin-deactivate-feedback.php:61
filterwp_mail_content_typeclass-plugin-deactivate-feedback.php:97
actionadmin_headclass-qc-free-plugin-upgrade-notice.php:34
actionplugin_row_metaclass-qc-free-plugin-upgrade-notice.php:128
actionadmin_menuclass-qc-free-plugin-upgrade-notice.php:170
actionwp_enqueue_scriptsembed\embedder.php:5
actionwp_enqueue_scriptsembed\embedder.php:53
filtertemplate_includeembed\embedder.php:60
actioninitembed\embedder.php:65
actionqcsl_after_add_btnembed\embedder.php:108
actioninitembed\embedder.php:112
actionenqueue_block_assetsgutenberg\ilist-block\src\init.php:33
actionenqueue_block_editor_assetsgutenberg\ilist-block\src\init.php:64
actionadmin_initinc\CMB2\cmb2-conditionals.php:52
actionadmin_footerinc\CMB2\cmb2-conditionals.php:53
actionplugins_loadedinc\CMB2\cmb2-conditionals.php:217
actioncmb2_admin_initinc\CMB2\example-functions.php:105
actioncmb2_admin_initinc\CMB2\example-functions.php:447
actioncmb2_admin_initinc\CMB2\example-functions.php:478
actioncmb2_admin_initinc\CMB2\example-functions.php:542
actioncmb2_admin_initinc\CMB2\example-functions.php:612
actioncmb2_admin_initinc\CMB2\example-functions.php:654
actioncmb2_initinc\CMB2\example-functions.php:756
filterwp_prepare_attachment_for_jsinc\CMB2\includes\CMB2.php:1440
actionadmin_enqueue_scriptsinc\CMB2\includes\CMB2.php:1458
actioncmb2_save_options-page_fieldsinc\CMB2\includes\CMB2_Ajax.php:54
filterget_post_metadatainc\CMB2\includes\CMB2_Ajax.php:147
filterupdate_post_metadatainc\CMB2\includes\CMB2_Ajax.php:150
filtercmb2_show_oninc\CMB2\includes\CMB2_hookup.php:79
actionedit_form_topinc\CMB2\includes\CMB2_hookup.php:115
actionedit_form_before_permalinkinc\CMB2\includes\CMB2_hookup.php:119
actionedit_form_after_titleinc\CMB2\includes\CMB2_hookup.php:123
actionedit_form_after_editorinc\CMB2\includes\CMB2_hookup.php:127
actionadd_meta_boxesinc\CMB2\includes\CMB2_hookup.php:131
actionadd_attachmentinc\CMB2\includes\CMB2_hookup.php:134
actionedit_attachmentinc\CMB2\includes\CMB2_hookup.php:135
actionsave_postinc\CMB2\includes\CMB2_hookup.php:136
actionadd_meta_boxes_commentinc\CMB2\includes\CMB2_hookup.php:149
actionedit_commentinc\CMB2\includes\CMB2_hookup.php:150
filtermanage_edit-comments_columnsinc\CMB2\includes\CMB2_hookup.php:153
actionmanage_comments_custom_columninc\CMB2\includes\CMB2_hookup.php:154
actionshow_user_profileinc\CMB2\includes\CMB2_hookup.php:163
actionedit_user_profileinc\CMB2\includes\CMB2_hookup.php:164
actionuser_new_forminc\CMB2\includes\CMB2_hookup.php:165
actionpersonal_options_updateinc\CMB2\includes\CMB2_hookup.php:167
actionedit_user_profile_updateinc\CMB2\includes\CMB2_hookup.php:168
actionuser_registerinc\CMB2\includes\CMB2_hookup.php:169
filtermanage_users_columnsinc\CMB2\includes\CMB2_hookup.php:172
filtermanage_users_custom_columninc\CMB2\includes\CMB2_hookup.php:173
actioncreated_terminc\CMB2\includes\CMB2_hookup.php:221
actionedited_termsinc\CMB2\includes\CMB2_hookup.php:222
actiondelete_terminc\CMB2\includes\CMB2_hookup.php:223
actioncmb2_do_oembedinc\CMB2\includes\helper-functions.php:127
filteris_protected_metainc\CMB2\includes\rest-api\CMB2_REST.php:144
actioninitinc\CMB2\init.php:74
actionadmin_initinc\grid-master\Cmb2GridPlugin.php:3
actionadmin_headinc\grid-master\Cmb2GridPluginLoad.php:20
actionadmin_enqueue_scriptsinc\grid-master\Cmb2GridPluginLoad.php:21
actionplugins_loadedinc\grid-master\Cmb2GridPluginLoad.php:135
actioncmb2_admin_initinc\grid-master\Test\Test.php:19
actioncmb2_admin_initinc\grid-master\Test\Test.php:20
actionadmin_enqueue_scriptsinc\inc\qcld_openai_floating_content.php:6
actionadmin_footerinc\inc\qcld_openai_floating_content.php:27
filterqcld_ilist_openai_text_imgqc-project-ilist-ajax.php:610
filterqcld_ilist_openai_data_functionqc-project-ilist-ajax.php:739
actionwp_enqueue_scriptsqc-project-ilist-asset.php:25
actionthe_postsqc-project-ilist-asset.php:33
actionadmin_enqueue_scriptsqc-project-ilist-asset.php:106
actionadmin_footerqc-project-ilist-chart.php:128
actionadmin_footerqc-project-ilist-fa.php:60
actionadmin_initqc-project-ilist-frameworks.php:19
actionadmin_menuqc-project-ilist-frameworks.php:22
actioninitqc-project-ilist-main.php:56
filtercustom_menu_orderqc-project-ilist-main.php:117
actionadmin_menuqc-project-ilist-main.php:121
actionadmin_noticesqc-project-ilist-main.php:194
actionadd_meta_boxesqc-project-ilist-main.php:197
actionplugins_loadedqc-project-ilist-main.php:224
actionactivated_pluginqc-project-ilist-main.php:273
actioninitqc-project-ilist-main.php:279
actioninitqc-project-ilist-post-type.php:68
actioncmb2_admin_initqc-project-ilist-post-type.php:88
actioncmb2_admin_initqc-project-ilist-post-type.php:138
filtermanage_ilist_posts_columnsqc-project-ilist-post-type.php:402
actionmanage_ilist_posts_custom_columnqc-project-ilist-post-type.php:403
filtermce_external_pluginsqc-project-ilist-post-type.php:410
filtermce_buttonsqc-project-ilist-post-type.php:411
actioninitqc-project-ilist-post-type.php:429
actionadmin_footerqc-project-ilist-post-type.php:437
actionadd_meta_boxesqc-project-ilist-post-type.php:456
actionadd_meta_boxesqc-project-ilist-post-type.php:490
actionadd_meta_boxesqc-project-ilist-post-type.php:517
actionadd_meta_boxesqc-project-ilist-post-type.php:560
actionadmin_head-post.phpqc-project-ilist-post-type.php:617
actionadmin_head-post-new.phpqc-project-ilist-post-type.php:618
actionsave_postqc-project-ilist-post-type.php:620
actionadmin_menuqc-support-promo-page\class-qc-support-promo-page.php:32
actionadmin_enqueue_scriptsqc-support-promo-page\class-qc-support-promo-page.php:62
Maintenance & Trust

AI Infographic Maker Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 17, 2025
PHP min version5.6
Downloads107K

Community Trust

Rating88/100
Number of ratings17
Active installs700
Developer Profile

AI Infographic Maker Developer Profile

QuantumCloud

29 plugins · 26K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
255 days
View full developer profile
Detection Fingerprints

How We Detect AI Infographic Maker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/infographic-and-list-builder-ilist/assets/css/bootstrap.min.css/wp-content/plugins/infographic-and-list-builder-ilist/assets/css/ilist-style.css/wp-content/plugins/infographic-and-list-builder-ilist/assets/css/main.css/wp-content/plugins/infographic-and-list-builder-ilist/assets/css/responsive.css/wp-content/plugins/infographic-and-list-builder-ilist/assets/css/slick-theme.css/wp-content/plugins/infographic-and-list-builder-ilist/assets/css/slick.css/wp-content/plugins/infographic-and-list-builder-ilist/assets/js/bootstrap.min.js/wp-content/plugins/infographic-and-list-builder-ilist/assets/js/chart.min.js+3 more
Version Parameters
/wp-content/plugins/infographic-and-list-builder-ilist/assets/css/bootstrap.min.css?ver=/wp-content/plugins/infographic-and-list-builder-ilist/assets/css/ilist-style.css?ver=/wp-content/plugins/infographic-and-list-builder-ilist/assets/css/main.css?ver=/wp-content/plugins/infographic-and-list-builder-ilist/assets/css/responsive.css?ver=/wp-content/plugins/infographic-and-list-builder-ilist/assets/css/slick-theme.css?ver=/wp-content/plugins/infographic-and-list-builder-ilist/assets/css/slick.css?ver=/wp-content/plugins/infographic-and-list-builder-ilist/assets/js/bootstrap.min.js?ver=/wp-content/plugins/infographic-and-list-builder-ilist/assets/js/chart.min.js?ver=/wp-content/plugins/infographic-and-list-builder-ilist/assets/js/ilist-main.js?ver=/wp-content/plugins/infographic-and-list-builder-ilist/assets/js/main.js?ver=/wp-content/plugins/infographic-and-list-builder-ilist/assets/js/slick.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
ilist-noticeilist_info_carouselilist_info_itemilist-main-wrapper
Data Attributes
data-ilist-id
JS Globals
iList
FAQ

Frequently Asked Questions about AI Infographic Maker