Pimi Admin Agent Security & Risk Analysis

wordpress.org/plugins/pimi-admin-agent

Manage your WordPress site using simple commands. Create pages, posts, users, manage plugins, and more with commands.

0 active installs v2.0.1 PHP 7.4+ WP 6.7+ Updated Jan 14, 2026
admin-assistantadmin-toolsbulk-actionsproductivity
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pimi Admin Agent Safe to Use in 2026?

Generally Safe

Score 100/100

Pimi Admin Agent has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "pimi-admin-agent" v2.0.1 plugin exhibits a generally strong security posture, with several positive indicators. Notably, all identified AJAX handlers include authentication checks, there are no exposed REST API routes, shortcodes, or cron events, and a high percentage of SQL queries utilize prepared statements (82%) and output is properly escaped (98%). The presence of 30 nonce checks and 50 capability checks further reinforces this. The absence of any recorded CVEs or known vulnerabilities in its history is also a significant strength, suggesting a history of responsible development or a lack of past exploitable issues.

However, the taint analysis reveals a critical concern: 10 out of 16 analyzed flows have high severity unsanitized paths. This indicates potential for vulnerabilities where user-supplied input is not adequately validated or cleaned before being used in sensitive operations, particularly in file operations which are also present. While no critical severity taint flows were explicitly reported, the high number of 'high severity' unsanitized paths is a significant red flag. This suggests a potential for privilege escalation or other critical vulnerabilities if these flows are exploited, even if current exploit vectors aren't obvious or have not yet been discovered.

In conclusion, the plugin benefits from good practices in core areas like authentication and sanitization of SQL and output. The lack of historical vulnerabilities is positive. The primary weakness lies in the taint analysis, specifically the high number of unsanitized paths. This is the most significant area of concern and warrants immediate attention to ensure all inputs are thoroughly validated before use, mitigating potential risks that are not yet reflected in its CVE history.

Key Concerns

  • High severity unsanitized paths in taint analysis
  • Unsanitized paths present in taint analysis
  • File operations present
Vulnerabilities
None known

Pimi Admin Agent Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Pimi Admin Agent Code Analysis

Dangerous Functions
0
Raw SQL Queries
24
108 prepared
Unescaped Output
6
291 escaped
Nonce Checks
30
Capability Checks
50
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

82% prepared132 total queries

Output Escaping

98% escaped297 total outputs
Data Flows
11 unsanitized

Data Flow Analysis

16 flows11 with unsanitized paths
ajax_set_uninstall_preference (src\Admin.php:829)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Pimi Admin Agent Attack Surface

Entry Points25
Unprotected0

AJAX Handlers 25

authwp_ajax_pimi_set_uninstall_preferencesrc\Admin.php:34
authwp_ajax_pimi_save_templatesrc\Admin.php:38
authwp_ajax_pimi_execute_templatesrc\Admin.php:39
authwp_ajax_pimi_create_workflowsrc\Admin.php:40
authwp_ajax_pimi_execute_workflowsrc\Admin.php:41
authwp_ajax_pimi_get_workflow_detailssrc\Admin.php:42
authwp_ajax_pimi_submit_approvalsrc\Admin.php:43
authwp_ajax_pimi_approve_commandsrc\Admin.php:44
authwp_ajax_pimi_reject_commandsrc\Admin.php:45
authwp_ajax_pimi_create_bulk_jobsrc\Admin.php:46
authwp_ajax_pimi_execute_bulk_jobsrc\Admin.php:47
authwp_ajax_pimi_get_bulk_job_statussrc\Admin.php:48
authwp_ajax_pimi_get_all_bulk_jobssrc\Admin.php:49
authwp_ajax_pimi_resume_bulk_jobsrc\Admin.php:50
authwp_ajax_pimi_upload_csvsrc\Admin.php:51
authwp_ajax_pimi_set_csv_mappingsrc\Admin.php:52
authwp_ajax_pimi_execute_csv_importsrc\Admin.php:53
authwp_ajax_pimi_export_logssrc\Admin.php:54
authwp_ajax_pimi_get_dashboard_statssrc\Admin.php:55
authwp_ajax_pimi_delete_workflowsrc\Admin.php:56
authwp_ajax_pimi_delete_templatesrc\Admin.php:57
authwp_ajax_pimi_delete_bulk_jobsrc\Admin.php:58
authwp_ajax_pimi_process_promptsrc\Core.php:33
authwp_ajax_pimi_get_impact_previewsrc\Core.php:34
authwp_ajax_pimi_confirm_executionsrc\Core.php:35
WordPress Hooks 14
actionadmin_menusrc\Admin.php:28
actionadmin_enqueue_scriptssrc\Admin.php:29
actionadmin_initsrc\Admin.php:30
actionadmin_initsrc\Admin.php:31
actionadmin_initsrc\Admin.php:32
actionadmin_noticessrc\Admin.php:35
actionadmin_noticessrc\Admin.php:773
actionadmin_noticessrc\Admin.php:780
actionadmin_noticessrc\Admin.php:790
actionadmin_noticessrc\Admin.php:822
actioninitsrc\Security.php:33
actionadmin_initsrc\Security.php:35
filterpimi_response_datasrc\Security.php:37
actionpimi_suspicious_activitysrc\Security.php:39
Maintenance & Trust

Pimi Admin Agent Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 14, 2026
PHP min version7.4
Downloads92

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Pimi Admin Agent Developer Profile

Himanshu Bhuyan

2 plugins · 10 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pimi Admin Agent

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pimi-admin-agent/build/css/app.css/wp-content/plugins/pimi-admin-agent/build/js/app.js
Script Paths
/wp-content/plugins/pimi-admin-agent/build/js/app.js
Version Parameters
pimi-admin-agent/build/css/app.css?ver=pimi-admin-agent/build/js/app.js?ver=

HTML / DOM Fingerprints

CSS Classes
pimi-agent-containerpimi-agent-headerpimi-agent-sidebarpimi-agent-contentpimi-agent-command-inputpimi-agent-response-areapimi-agent-buttonpimi-agent-modal
Data Attributes
data-pimi-agent
JS Globals
PimiAgent
FAQ

Frequently Asked Questions about Pimi Admin Agent