
Qalam Arabic AI Writing Assistant Plugin | Qalam Security & Risk Analysis
wordpress.org/plugins/qalamQalam plugin for WordPress adds AI based grammar, spell check, and Tashkeel "Diacritization" capabilities to your website content in Arabic Language.
Is Qalam Arabic AI Writing Assistant Plugin | Qalam Safe to Use in 2026?
Generally Safe
Score 92/100Qalam Arabic AI Writing Assistant Plugin | Qalam has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The qalam plugin v1.0.4 demonstrates a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface entry points like AJAX handlers, REST API routes, or shortcodes, combined with a complete lack of dangerous functions, suggests a well-contained and defensively coded plugin. The analysis also indicates excellent practices in SQL query handling and output escaping, with 100% of SQL queries utilizing prepared statements and all outputs being properly escaped. Furthermore, the plugin has no recorded vulnerabilities, CVEs, or historical security issues, which is a significant indicator of diligent development and testing. The lack of file operations and external HTTP requests further minimizes its potential attack surface.
However, the complete absence of nonce checks and capability checks across all identified code signals is a notable concern. While the current analysis shows zero entry points, if any functionality were to be added or exposed in the future without these security measures, it could create vulnerabilities. The fact that there are no identified taint flows or vulnerabilities in this version does not guarantee future safety if development practices evolve without incorporating robust authentication and authorization mechanisms.
In conclusion, the qalam v1.0.4 plugin is currently very secure, with excellent adherence to safe coding practices for SQL and output handling, and a clean vulnerability history. The primary weakness lies in the complete omission of nonce and capability checks, which is a foundational security principle in WordPress development and a potential risk for future expansion. This presents a trade-off between its current minimal risk and its potential future risk if not addressed.
Key Concerns
- Missing nonce checks
- Missing capability checks
Qalam Arabic AI Writing Assistant Plugin | Qalam Security Vulnerabilities
Qalam Arabic AI Writing Assistant Plugin | Qalam Code Analysis
Output Escaping
Qalam Arabic AI Writing Assistant Plugin | Qalam Attack Surface
WordPress Hooks 3
Maintenance & Trust
Qalam Arabic AI Writing Assistant Plugin | Qalam Maintenance & Trust
Maintenance Signals
Community Trust
Qalam Arabic AI Writing Assistant Plugin | Qalam Alternatives
Perfect Tense – Spelling and Grammar Checker
perfect-tense
Perfect Tense is an AI-powered, spelling and grammar corrector. Perfect Tense will automatically detect and fix mistakes, proofread entire blog posts, …
WProofreader spell & grammar check plugin for WordPress
webspellchecker
WProofreader checks spelling, grammar, and style in real-time while editing in WordPress.
WP Spell Check
wp-spell-check
Proofread & Audit your WordPress website with One Click! Find & fix the errors and build a professional image for your business.
Webmaster Spelling Notifications
gourl-spelling-notifications
Plugin allows site visitors to send reports to the webmaster/owner about any spelling or grammatical errors. Spelling checker on your website.
Spotfix – proofreading, spelling and grammar reviews by visitors
spotfix-content-review
Collect visitors’ questions and suggestions directly on your website pages. Make proofreading, spell checking, and grammar reviews easy.
Qalam Arabic AI Writing Assistant Plugin | Qalam Developer Profile
1 plugin · 30 total installs
How We Detect Qalam Arabic AI Writing Assistant Plugin | Qalam
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/qalam/assets/js/main.js/wp-content/plugins/qalam/assets/js/script.jsassets/js/main.js?v1.1.0assets/js/script.jsqalam/assets/js/main.js?v1.1.0qalam/assets/js/script.jsHTML / DOM Fingerprints
Qalam is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 2 of the License, or
any later version.
Qalam is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with Qalam. If not, see https://www.gnu.org/licenses/gpl-2.0.html.id="qalam_section"settings