NexiPilot Content AI – AI-Powered FAQ, Summary & Internal Link Generator Security & Risk Analysis

wordpress.org/plugins/nexipilot-content-ai

AI-powered WordPress plugin that generates FAQs, content summaries, and smart internal links for your posts using OpenAI, Claude, Gemini, or Grok.

0 active installs v1.0.0 PHP 7.4+ WP 5.8+ Updated Unknown
ai-summarizationcontent-generationfaqinternal-links
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NexiPilot Content AI – AI-Powered FAQ, Summary & Internal Link Generator Safe to Use in 2026?

Generally Safe

Score 100/100

NexiPilot Content AI – AI-Powered FAQ, Summary & Internal Link Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The nexipilot-content-ai plugin v1.0.0 demonstrates a generally strong security posture based on the provided static analysis. It effectively utilizes prepared statements for all SQL queries and maintains a high percentage of properly escaped output, mitigating common injection and XSS risks. The presence of nonce and capability checks on all identified entry points is commendable, indicating an effort to secure interactions with the plugin. The absence of any recorded vulnerabilities in its history further supports this positive assessment, suggesting a commitment to secure development practices.

However, the presence of two flows with unsanitized paths in the taint analysis is a point of concern. While these flows were not classified as critical or high severity, they represent potential avenues for attackers to exploit if they can influence the path components. The plugin also makes five external HTTP requests, which, while not inherently insecure, can introduce risks if not handled with proper validation and sanitization of incoming data before being used in these requests.

In conclusion, nexipilot-content-ai v1.0.0 is built on a solid foundation of secure coding practices, particularly in its handling of database interactions and output. The main area for improvement lies in a thorough review and sanitization of the identified unsanitized paths to eliminate any potential vulnerabilities. The plugin's lack of past vulnerabilities is a positive indicator, but vigilance regarding the identified taint flows is warranted.

Key Concerns

  • Flows with unsanitized paths found
  • External HTTP requests made
Vulnerabilities
None known

NexiPilot Content AI – AI-Powered FAQ, Summary & Internal Link Generator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

NexiPilot Content AI – AI-Powered FAQ, Summary & Internal Link Generator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
128 escaped
Nonce Checks
5
Capability Checks
6
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

97% escaped132 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
ajax_generate_faq (Admin\MetaBox\FAQMetaBox.php:348)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

NexiPilot Content AI – AI-Powered FAQ, Summary & Internal Link Generator Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_nexipilot_save_settingAdmin\AdminManager.php:96
authwp_ajax_nexipilot_generate_faqAdmin\MetaBox\FAQMetaBox.php:59
authwp_ajax_nexipilot_generate_demo_faqAdmin\MetaBox\FAQMetaBox.php:60
authwp_ajax_nexipilot_check_api_statusAdmin\MetaBox\FAQMetaBox.php:61
WordPress Hooks 16
filterplugin_row_metaAdmin\AdminManager.php:98
actionadmin_enqueue_scriptsAdmin\Assets\Assets.php:34
actionadmin_enqueue_scriptsAdmin\Assets\Assets.php:35
actionwp_enqueue_scriptsAdmin\Assets\Assets.php:36
actionadd_meta_boxesAdmin\MetaBox\FAQMetaBox.php:57
actionsave_postAdmin\MetaBox\FAQMetaBox.php:58
actionadmin_menuAdmin\Settings.php:37
actionadmin_initAdmin\Settings.php:38
actionupdate_option_nexipilot_openai_api_keyAdmin\Settings.php:41
actionupdate_option_nexipilot_claude_api_keyAdmin\Settings.php:42
actionupdate_option_nexipilot_gemini_api_keyAdmin\Settings.php:43
actionupdate_option_nexipilot_grok_api_keyAdmin\Settings.php:44
actionwp_enqueue_scriptsFrontend\Assets\Assets.php:34
filterthe_contentFrontend\ContentInjector.php:56
actionsave_postFrontend\ContentInjector.php:57
actionplugins_loadednexipilot-content-ai.php:103
Maintenance & Trust

NexiPilot Content AI – AI-Powered FAQ, Summary & Internal Link Generator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads126

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

NexiPilot Content AI – AI-Powered FAQ, Summary & Internal Link Generator Developer Profile

Nexiby LLC

7 plugins · 80 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NexiPilot Content AI – AI-Powered FAQ, Summary & Internal Link Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nexipilot-content-ai/Admin/Assets/css/admin.css/wp-content/plugins/nexipilot-content-ai/Admin/Assets/js/sweetalert2.js/wp-content/plugins/nexipilot-content-ai/Admin/Assets/js/settings.js/wp-content/plugins/nexipilot-content-ai/Admin/Assets/js/faq-metabox.js
Script Paths
/wp-content/plugins/nexipilot-content-ai/Admin/Assets/js/sweetalert2.js/wp-content/plugins/nexipilot-content-ai/Admin/Assets/js/settings.js/wp-content/plugins/nexipilot-content-ai/Admin/Assets/js/faq-metabox.js
Version Parameters
nexipilot-admin-style?ver=nexipilot-settings-script?ver=nexipilot-faq-metabox-script?ver=

HTML / DOM Fingerprints

CSS Classes
nexipilot-faq-item
HTML Comments
<!-- NexiPilot FAQ Item Start --><!-- NexiPilot FAQ Item End --><!-- NexiPilot Content AI Meta Box --><!-- NexiPilot Content AI Meta Box End -->+2 more
Data Attributes
data-nexipilot-faq-iddata-nexipilot-nonce-fielddata-nexipilot-remove-nonce
JS Globals
nexipilotAdminNEXIPILOT_VERSIONNEXIPILOT_URLNEXIPILOT_ADMIN_ASSETS
Shortcode Output
[nexipilot_generate_faq][nexipilot_content_summary][nexipilot_internal_links]
FAQ

Frequently Asked Questions about NexiPilot Content AI – AI-Powered FAQ, Summary & Internal Link Generator