Planet ⑨ (Beta) Security & Risk Analysis

wordpress.org/plugins/planet-9

AI-powered writing and translation directly inside WordPress, via a smart, context-aware floating toolbar.

20 active installs v2.15.3 PHP 7.4+ WP 5.0+ Updated Dec 11, 2025
aicontent-creationcopywritingopenaitranslation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Planet ⑨ (Beta) Safe to Use in 2026?

Generally Safe

Score 100/100

Planet ⑨ (Beta) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "planet-9" plugin v2.15.3 demonstrates a strong security posture based on the provided static analysis. The complete absence of critical or high severity taint flows, along with 100% usage of prepared statements for SQL queries and proper output escaping, are significant strengths. The plugin also exhibits good security practices by implementing nonce checks and avoiding dangerous functions. Furthermore, the lack of any known CVEs in its vulnerability history suggests a history of secure development and maintenance. The plugin's attack surface is minimal, with only one AJAX handler identified, and importantly, this handler appears to be protected, contributing to its low risk profile. The external HTTP request is noted, but without further context on its purpose, it's difficult to assess as a direct risk. However, the absence of capability checks on the AJAX handler, while not an immediate critical issue given the limited attack surface, represents a potential area for future improvement to further harden the plugin against unauthorized access if the functionality is sensitive.

Key Concerns

  • Missing capability checks on AJAX handler
Vulnerabilities
None known

Planet ⑨ (Beta) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Planet ⑨ (Beta) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
50 escaped
Nonce Checks
6
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped50 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<tab_settings> (templates\includes\tab_settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Planet ⑨ (Beta) Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_rewrite_with_aiincludes\ai.php:209
WordPress Hooks 7
actionadmin_footerincludes\ai.php:37
actionadmin_enqueue_scriptsplanet-9.php:56
actionadmin_enqueue_scriptsplanet-9.php:75
actionadmin_menuplanet-9.php:91
filteruse_block_editor_for_postplanet-9.php:108
filteruse_block_editor_for_post_typeplanet-9.php:109
actioninitplanet-9.php:112
Maintenance & Trust

Planet ⑨ (Beta) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version7.4
Downloads840

Community Trust

Rating100/100
Number of ratings3
Active installs20
Developer Profile

Planet ⑨ (Beta) Developer Profile

Planet 9

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Planet ⑨ (Beta)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/planet-9/assets/css/style.css/wp-content/plugins/planet-9/assets/js/scripts.js
Script Paths
/wp-content/plugins/planet-9/assets/js/scripts.js
Version Parameters
planet-9/style.css?ver=planet-9/scripts.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Planet ⑨ (Beta)