Locomote by Diffusal – AI Content Automation Security & Risk Analysis

wordpress.org/plugins/locomote

AI-powered tool that automates content creation, scheduling, and publishing directly inside your website.

0 active installs v1.0.1 PHP 8.0+ WP 6.0+ Updated Dec 5, 2025
aiautomationblogcontent-creationscheduling
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Locomote by Diffusal – AI Content Automation Safe to Use in 2026?

Generally Safe

Score 100/100

Locomote by Diffusal – AI Content Automation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The locomote v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. All identified entry points (AJAX handlers) are protected by capability checks, and there are no known vulnerabilities (CVEs) associated with this plugin. The code demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output, indicating a commitment to preventing common web vulnerabilities like SQL injection and cross-site scripting (XSS).

However, a notable concern is the absence of nonce checks on the AJAX handlers. While capability checks provide a baseline level of authorization, nonces are crucial for preventing Cross-Site Request Forgery (CSRF) attacks. Without them, an attacker could trick a logged-in user into performing unintended actions through these AJAX endpoints.

In conclusion, locomote v1.0.1 is generally well-secured with a clean vulnerability history and solid coding practices regarding SQL and output handling. The primary area for improvement lies in implementing nonce checks for its AJAX endpoints to further harden it against potential CSRF exploits. Despite this, the overall risk is currently low due to the lack of known vulnerabilities and comprehensive authorization on its entry points.

Key Concerns

  • Missing nonce checks on AJAX handlers
Vulnerabilities
None known

Locomote by Diffusal – AI Content Automation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Locomote by Diffusal – AI Content Automation Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Locomote by Diffusal – AI Content Automation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Locomote by Diffusal – AI Content Automation Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_locomote_generate_app_passworddiffusal-locomote.php:180
authwp_ajax_locomote_generate_app_passwordtrunk\diffusal-locomote.php:180
WordPress Hooks 6
actionadmin_menudiffusal-locomote.php:46
actionadmin_enqueue_scriptsdiffusal-locomote.php:110
actioninitdiffusal-locomote.php:154
actionadmin_menutrunk\diffusal-locomote.php:46
actionadmin_enqueue_scriptstrunk\diffusal-locomote.php:110
actioninittrunk\diffusal-locomote.php:154
Maintenance & Trust

Locomote by Diffusal – AI Content Automation Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 5, 2025
PHP min version8.0
Downloads157

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Locomote by Diffusal – AI Content Automation Developer Profile

dimitarchetelev

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Locomote by Diffusal – AI Content Automation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/locomote/public/bundle.js/wp-content/plugins/locomote/dist/public/bundle.js
Script Paths
/wp-content/plugins/locomote/public/bundle.js/wp-content/plugins/locomote/dist/public/bundle.js
Version Parameters
locomote/public/bundle.js?ver=locomote/dist/public/bundle.js?ver=

HTML / DOM Fingerprints

JS Globals
wpPluginReactConfig
Shortcode Output
<div id="main"></div>
FAQ

Frequently Asked Questions about Locomote by Diffusal – AI Content Automation