
Mandat AEO Assistant Security & Risk Analysis
wordpress.org/plugins/mandat-aeo-assistantAI-powered content generation plugin using Google Gemini API to create long-form SEO articles with images, internal linking, and Polylang integration.
Is Mandat AEO Assistant Safe to Use in 2026?
Generally Safe
Score 100/100Mandat AEO Assistant has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mandat-aeo-assistant" plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices in output escaping, using prepared statements for most SQL queries, and incorporates nonce and capability checks. The absence of recorded vulnerabilities and dangerous functions is also a good sign.
However, significant concerns arise from the attack surface and taint analysis. A substantial portion of the plugin's entry points, specifically all 5 AJAX handlers, lack authentication checks, exposing them to unauthorized access. Furthermore, the taint analysis reveals 3 flows with unsanitized paths classified as high severity. This indicates potential for malicious input to reach sensitive operations without proper sanitization, which could lead to various security issues depending on the context of these flows.
While the plugin has no recorded vulnerability history, the presence of high-severity taint flows without corresponding known CVEs suggests that vulnerabilities might exist but haven't been publicly disclosed or exploited yet. The plugin's strengths lie in its internal code hygiene for SQL and output, but its external exposure points and unsanitized data flows are critical weaknesses that need immediate attention.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows with unsanitized paths
Mandat AEO Assistant Security Vulnerabilities
Mandat AEO Assistant Release Timeline
Mandat AEO Assistant Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Mandat AEO Assistant Attack Surface
AJAX Handlers 5
REST API Routes 1
WordPress Hooks 14
Maintenance & Trust
Mandat AEO Assistant Maintenance & Trust
Maintenance Signals
Community Trust
Mandat AEO Assistant Alternatives
TextBulker (IA Redaction)
textbulker
Official plugin for TextBulker.com – inject SEO metadata via REST API when publishing AI-generated content.
Spawnster: AI Blog Writer and Instant Site Generator for Publishing Articles on a Schedule
spawnster-ai-content-generator
The Best AI Blog Writer for Automatically Generating SEO-Friendly Blog Articles on a Schedule
AnswerSEO – AEO & LLM Optimization for Generative AI Search
answer-engine-optimization-aeo-audit
Audit and optimize your website for Answer Engine Optimization (AEO). Manage FAQs, JSON-LD, LLMs Speakable markup etc.. for AI Optimization (AIO).
Markdown Mirror – llms.txt and .md always up to date
markdown-mirror
Generate an llms.txt map and dynamic Markdown (.md) versions of every page of your site to improve your AI SEO and facilitate LLMs indexing.
WriteText.ai
writetext-ai
WooCommerce AI for SEO, AEO & GEO. Automate product content creation with smart templates, bulk generation, and full-site optimization.
Mandat AEO Assistant Developer Profile
9 plugins · 10K total installs
How We Detect Mandat AEO Assistant
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mandat-aeo-assistant/assets/css/admin-style.css/wp-content/plugins/mandat-aeo-assistant/assets/js/admin-script.js/wp-content/plugins/mandat-aeo-assistant/assets/js/admin-script.jsmandat-aeo-assistant/assets/css/admin-style.css?ver=mandat-aeo-assistant/assets/js/admin-script.js?ver=HTML / DOM Fingerprints
cost-breakdowntotal-cost-cellgrand-total-celltranslation-badgedata-nonce-generate_textdata-nonce-generate_imagesdata-nonce-update_contentdata-nonce-update_categoriesdata-nonce-translatemaao_i18n/wp-json/mandat-aeo-assistant/v1/posts