Qalam Arabic AI Writing Assistant Plugin | Qalam Security & Risk Analysis

wordpress.org/plugins/qalam

Qalam plugin for WordPress adds AI based grammar, spell check, and Tashkeel "Diacritization" capabilities to your website content in Arabic Language.

30 active installs v1.0.4 PHP 7.2+ WP 5.2+ Updated Aug 13, 2024
grammarproofreadingspell-checkspellingtashkeel-diacritization
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Qalam Arabic AI Writing Assistant Plugin | Qalam Safe to Use in 2026?

Generally Safe

Score 92/100

Qalam Arabic AI Writing Assistant Plugin | Qalam has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The qalam plugin v1.0.4 demonstrates a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface entry points like AJAX handlers, REST API routes, or shortcodes, combined with a complete lack of dangerous functions, suggests a well-contained and defensively coded plugin. The analysis also indicates excellent practices in SQL query handling and output escaping, with 100% of SQL queries utilizing prepared statements and all outputs being properly escaped. Furthermore, the plugin has no recorded vulnerabilities, CVEs, or historical security issues, which is a significant indicator of diligent development and testing. The lack of file operations and external HTTP requests further minimizes its potential attack surface.

However, the complete absence of nonce checks and capability checks across all identified code signals is a notable concern. While the current analysis shows zero entry points, if any functionality were to be added or exposed in the future without these security measures, it could create vulnerabilities. The fact that there are no identified taint flows or vulnerabilities in this version does not guarantee future safety if development practices evolve without incorporating robust authentication and authorization mechanisms.

In conclusion, the qalam v1.0.4 plugin is currently very secure, with excellent adherence to safe coding practices for SQL and output handling, and a clean vulnerability history. The primary weakness lies in the complete omission of nonce and capability checks, which is a foundational security principle in WordPress development and a potential risk for future expansion. This presents a trade-off between its current minimal risk and its potential future risk if not addressed.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Qalam Arabic AI Writing Assistant Plugin | Qalam Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Qalam Arabic AI Writing Assistant Plugin | Qalam Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped11 total outputs
Attack Surface

Qalam Arabic AI Writing Assistant Plugin | Qalam Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuqalam.php:89
actionadmin_initqalam.php:90
actionadmin_enqueue_scriptsqalam.php:97
Maintenance & Trust

Qalam Arabic AI Writing Assistant Plugin | Qalam Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 13, 2024
PHP min version7.2
Downloads3K

Community Trust

Rating80/100
Number of ratings4
Active installs30
Developer Profile

Qalam Arabic AI Writing Assistant Plugin | Qalam Developer Profile

Qalam.ai

1 plugin · 30 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Qalam Arabic AI Writing Assistant Plugin | Qalam

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/qalam/assets/js/main.js/wp-content/plugins/qalam/assets/js/script.js
Script Paths
assets/js/main.js?v1.1.0assets/js/script.js
Version Parameters
qalam/assets/js/main.js?v1.1.0qalam/assets/js/script.js

HTML / DOM Fingerprints

HTML Comments
Qalam is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or any later version. Qalam is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with Qalam. If not, see https://www.gnu.org/licenses/gpl-2.0.html.
Data Attributes
id="qalam_section"
JS Globals
settings
FAQ

Frequently Asked Questions about Qalam Arabic AI Writing Assistant Plugin | Qalam