
PageTest.ai – AI-Powered A/B and Multivariate Testing for WordPress Security & Risk Analysis
wordpress.org/plugins/pagetest-aiRun AI-powered A/B and multivariate tests on your WordPress site—no coding needed. Optimize conversions by finding your best content.
Is PageTest.ai – AI-Powered A/B and Multivariate Testing for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100PageTest.ai – AI-Powered A/B and Multivariate Testing for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The pagetest-ai v1.0.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong coding practices by utilizing prepared statements for all SQL queries and properly escaping all output, indicating a good defense against common injection vulnerabilities. The absence of dangerous functions, file operations, and any known historical vulnerabilities (CVEs) further contributes to a generally positive security outlook. However, a significant concern arises from its attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks. This creates a direct and unprotected entry point into the plugin's functionality, potentially allowing any unauthenticated user to trigger these actions. While taint analysis did not reveal any explicit unsanitized flows, the lack of authorization on these AJAX handlers is a critical oversight that could be exploited if the actions they perform are sensitive or could lead to undesirable side effects when triggered by unauthorized users.
Key Concerns
- AJAX handlers without authentication
- Lack of capability checks on entry points
PageTest.ai – AI-Powered A/B and Multivariate Testing for WordPress Security Vulnerabilities
PageTest.ai – AI-Powered A/B and Multivariate Testing for WordPress Code Analysis
Output Escaping
PageTest.ai – AI-Powered A/B and Multivariate Testing for WordPress Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
PageTest.ai – AI-Powered A/B and Multivariate Testing for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
PageTest.ai – AI-Powered A/B and Multivariate Testing for WordPress Alternatives
Unbounce Landing Pages
unbounce
Unbounce is the most powerful standalone landing page builder available.
Convert Experiences
convert-experiments
Convert Experiences provides advanced A/B and MVT Testing functionality for your website or blog.
Sigmize: A/B Testing, Session Recordings, Heatmaps & Revenue Tracking for WooCommerce, SureCart & EDD
sigmize
Powerful A/B testing for WordPress with heatmaps, session replays, and e-commerce tracking for WooCommerce, SureCart, and EDD.
abtestkit – AB testing for WooCommerce
abtestkit
Split testing for WooCommerce, compatible with all themes, page builders & caching plugins.
Landing Lion Landing Pages
landing-lion-landing-pages
Landing Lion is the easiest and fastest landing page builder to create landing pages for your brand.
PageTest.ai – AI-Powered A/B and Multivariate Testing for WordPress Developer Profile
1 plugin · 20 total installs
How We Detect PageTest.ai – AI-Powered A/B and Multivariate Testing for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pagetest-ai/assets/admin-style.css/wp-content/plugins/pagetest-ai/assets/login.css/wp-content/plugins/pagetest-ai/assets/logo-style.css/wp-content/plugins/pagetest-ai/inc/admin.js/wp-content/plugins/pagetest-ai/inc/admin.jspagetest-admin-style?ver=1.0.1pagetest-login-style?ver=1.0.0pagetest-logo-style?ver=1.0.0HTML / DOM Fingerprints
login-containerpagetest-login-logoform-grouplogin-buttonforgot-passwordregisterid="pagetest-login-form"id="pagetest_email"id="pagetest_password"pagetest_ajax/wp-json/pagetest/v1/endpoint