Quickcreator – AI Blog Writer Security & Risk Analysis

wordpress.org/plugins/quickcreator

Integrate QuickCreator's Content Editor with WordPress for AI-driven SEO content creation and seamless publishing.

600 active installs v0.2.2 PHP 7.4+ WP 6.0+ Updated Jan 14, 2026
contentcontent-writingkeywordsquickcreatorseo
97
A · Safe
CVEs total1
Unpatched0
Last CVEOct 23, 2025
Safety Verdict

Is Quickcreator – AI Blog Writer Safe to Use in 2026?

Generally Safe

Score 97/100

Quickcreator – AI Blog Writer has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 23, 2025Updated 2mo ago
Risk Assessment

The quickcreator plugin v0.2.2 exhibits a mixed security posture. On the positive side, it demonstrates strong practices in its handling of SQL queries, utilizing prepared statements for all 100% of its queries, and a high percentage (93%) of its output is properly escaped. The absence of dangerous functions and no identified critical or high severity taint flows are also encouraging signs.

However, several significant concerns are raised by the static analysis. The plugin has a notable attack surface with 30 total entry points, and a critical weakness exists with 3 unprotected AJAX handlers. While capability checks and nonce checks are present, their limited count (2 each) on a larger attack surface might not be sufficient. The plugin also has a history of vulnerabilities, with one known CVE, albeit currently unpatched. The common vulnerability type of "Insertion of Sensitive Information into Log File" suggests potential data leakage issues that require careful attention.

In conclusion, while quickcreator v0.2.2 has some good security foundations, the presence of unprotected AJAX endpoints and a past vulnerability related to sensitive information logging represent substantial risks that need immediate remediation. The attack surface, coupled with the specific vulnerabilities identified, warrants caution.

Key Concerns

  • Unprotected AJAX handlers
  • One known CVE (though unpatched status unknown)
  • Limited nonce checks
  • Limited capability checks
  • Minor unescaped output
Vulnerabilities
1

Quickcreator – AI Blog Writer Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-11504high · 7.5Insertion of Sensitive Information into Log File

Quickcreator – AI Blog Writer 0.0.9 - 0.1.17 - Unauthenticated API Key Exposure

Oct 23, 2025 Patched in 0.1.18 (11d)
Code Analysis
Analyzed Mar 16, 2026

Quickcreator – AI Blog Writer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
88 escaped
Nonce Checks
2
Capability Checks
2
File Operations
4
External Requests
1
Bundled Libraries
0

Output Escaping

93% escaped95 total outputs
Attack Surface
3 unprotected

Quickcreator – AI Blog Writer Attack Surface

Entry Points30
Unprotected3

AJAX Handlers 3

authwp_ajax_generate_quickcreator_connection_urlincludes\quickcreator\class-quickcreator.php:106
authwp_ajax_disconnect_quickcreatorincludes\quickcreator\class-quickcreator.php:107
authwp_ajax_check_quickcreator_connection_statusincludes\quickcreator\class-quickcreator.php:108

REST API Routes 27

POST/wp-json/quickcreatorblog/v1/connect/includes\quickcreator\class-quickcreator.php:187
DELETE/wp-json/quickcreatorblog/v1/disconnect/includes\quickcreator\class-quickcreator.php:200
POST/wp-json/quickcreatorblog/v1/import_post/includes\quickcreator\class-quickcreator.php:213
POST/wp-json/quickcreatorblog/v1/change_post_status/includes\quickcreator\class-quickcreator.php:225
GET/wp-json/quickcreatorblog/v1/version/includes\quickcreator\class-quickcreator.php:238
GET/wp-json/quickcreatorblog/v1/categories/includes\quickcreator\class-quickcreator.php:251
GET/wp-json/quickcreatorblog/v1/tags/includes\quickcreator\class-quickcreator.php:264
GET/wp-json/quickcreatorblog/v1/users/includes\quickcreator\class-quickcreator.php:277
GET/wp-json/quickcreatorblog/v1/post_types/includes\quickcreator\class-quickcreator.php:290
POST/wp-json/quickcreatorblog/v1/disconnect_draft/includes\quickcreator\class-quickcreator.php:303
POST/wp-json/quickcreatorblog/v1/get_posts/includes\quickcreator\class-quickcreator.php:316
POST/wp-json/quickcreatorblog/v1/upload_img_to_media_library/includes\quickcreator\class-quickcreator.php:329
POST/wp-json/quickcreatorblog/v1/site_builder_add_level_menu/includes\quickcreator\class-quickcreator.php:342
POST/wp-json/quickcreatorblog/v1/site_builder_site_init/includes\quickcreator\class-quickcreator.php:355
POST/wp-json/quickcreatorblog/v1/site_builder_copy_post/includes\quickcreator\class-quickcreator.php:368
POST/wp-json/quickcreatorblog/v1/site_builder_get_post_meta_by_key/includes\quickcreator\class-quickcreator.php:382
POST/wp-json/quickcreatorblog/v1/site_builder_get_attachment_metadata/includes\quickcreator\class-quickcreator.php:396
POST/wp-json/quickcreatorblog/v1/site_builder_add_term/includes\quickcreator\class-quickcreator.php:410
POST/wp-json/quickcreatorblog/v1/site_builder_taxonomy_as_level_menu/includes\quickcreator\class-quickcreator.php:423
POST/wp-json/quickcreatorblog/v1/site_builder_bind_post_taxonomy_term/includes\quickcreator\class-quickcreator.php:436
POST/wp-json/quickcreatorblog/v1/site_builder_get_template_data/includes\quickcreator\class-quickcreator.php:449
POST/wp-json/quickcreatorblog/v1/site_builder_get_library_data/includes\quickcreator\class-quickcreator.php:463
POST/wp-json/quickcreatorblog/v1/site_builder_install_plugin/includes\quickcreator\class-quickcreator.php:477
POST/wp-json/quickcreatorblog/v1/site_builder_install_plugin_upload/includes\quickcreator\class-quickcreator.php:491
POST/wp-json/quickcreatorblog/v1/site_builder_theme_builder_save_conditions/includes\quickcreator\class-quickcreator.php:505
POST/wp-json/quickcreatorblog/v1/site_builder_install_theme/includes\quickcreator\class-quickcreator.php:519
POST/wp-json/quickcreatorblog/v1/import_tag/includes\quickcreator\class-quickcreator.php:533
WordPress Hooks 12
actionadmin_menuincludes\admin\class-quickcreator-admin.php:24
actionadmin_initincludes\admin\class-quickcreator-admin.php:26
actionadmin_enqueue_scriptsincludes\admin\class-quickcreator-admin.php:28
actioninitincludes\class-quickcreatorblog.php:106
filtersafe_style_cssincludes\class-quickcreatorblog.php:108
filteruagb_post_query_args_gridincludes\class-quickcreatorblog.php:110
filteruagb_post_query_args_carouselincludes\class-quickcreatorblog.php:112
actionupgrader_process_completeincludes\class-quickcreatorblog.php:261
actionadmin_enqueue_scriptsincludes\class-quickcreatorblog.php:330
actionwp_enqueue_scriptsincludes\class-quickcreatorblog.php:351
actionrest_api_initincludes\quickcreator\class-quickcreator.php:104
filterrest_request_after_callbacksincludes\quickcreator\class-quickcreator.php:109
Maintenance & Trust

Quickcreator – AI Blog Writer Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 14, 2026
PHP min version7.4
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs600
Developer Profile

Quickcreator – AI Blog Writer Developer Profile

Quickcreator

1 plugin · 600 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect Quickcreator – AI Blog Writer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quickcreator/assets/css/quickcreator-admin.css/wp-content/plugins/quickcreator/assets/js/quickcreator-connector.js/wp-content/plugins/quickcreator/assets/js/quickcreator-content-importer.js
Script Paths
/wp-content/plugins/quickcreator/assets/js/quickcreator-connector.js/wp-content/plugins/quickcreator/assets/js/quickcreator-content-importer.js
Version Parameters
quickcreator/assets/css/quickcreator-admin.css?ver=quickcreator/assets/js/quickcreator-connector.js?ver=quickcreator/assets/js/quickcreator-content-importer.js?ver=

HTML / DOM Fingerprints

CSS Classes
quickcreator-admin-wrapquickcreator-settings-form
Data Attributes
data-quickcreator-settings
JS Globals
quickcreator_connection_langquickcreator_content_importer_langquickcreator_obj
FAQ

Frequently Asked Questions about Quickcreator – AI Blog Writer