Quickcreator Agent Security & Risk Analysis

wordpress.org/plugins/quickcreator-agent

Integrate QuickCreator Agent with WordPress for AI-driven SEO content creation and seamless publishing.

30 active installs v0.2.2 PHP 7.4+ WP 6.0+ Updated Feb 5, 2026
aicontentcontent-writingquickcreator-agentseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Quickcreator Agent Safe to Use in 2026?

Generally Safe

Score 100/100

Quickcreator Agent has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'quickcreator-agent' v0.2.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, using prepared statements exclusively, and a high percentage of properly escaped output. The absence of known CVEs and any recorded vulnerability history is also a significant strength, suggesting a generally well-maintained codebase. However, there are notable concerns arising from the static analysis.

The plugin exposes 3 AJAX handlers without authentication checks, representing a direct and potentially exploitable attack surface. While the taint analysis found no unsanitized paths, the lack of authentication on these AJAX endpoints is a critical oversight that could allow unauthorized actions if these endpoints perform sensitive operations. The presence of file operations and external HTTP requests, though not inherently malicious, warrant careful review in conjunction with the unprotected AJAX endpoints.

Overall, the plugin benefits from good SQL and output sanitization practices and a clean vulnerability history. The primary risk lies in the unprotected AJAX handlers. Addressing these immediately is crucial to significantly improve the plugin's security. Without this, the plugin's potential for exploitation, especially if those AJAX handlers interact with sensitive data or functionality, remains a concern.

Key Concerns

  • AJAX handlers without auth checks
  • AJAX handlers without auth checks
  • AJAX handlers without auth checks
Vulnerabilities
None known

Quickcreator Agent Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Quickcreator Agent Release Timeline

v0.2.2Current
Code Analysis
Analyzed Apr 16, 2026

Quickcreator Agent Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
115 escaped
Nonce Checks
2
Capability Checks
2
File Operations
4
External Requests
1
Bundled Libraries
0

Output Escaping

94% escaped122 total outputs
Attack Surface
3 unprotected

Quickcreator Agent Attack Surface

Entry Points15
Unprotected3

AJAX Handlers 3

authwp_ajax_quickcreator_agent_get_connection_urlincludes/quickcreator/class-quickcreator.php:64
authwp_ajax_quickcreator_agent_disconnectincludes/quickcreator/class-quickcreator.php:65
authwp_ajax_quickcreator_agent_check_connection_statusincludes/quickcreator/class-quickcreator.php:66

REST API Routes 12

POST/wp-json/quickcreator-agent/v1/connect/includes/quickcreator/class-quickcreator.php:145
DELETE/wp-json/quickcreator-agent/v1/disconnect/includes/quickcreator/class-quickcreator.php:158
POST/wp-json/quickcreator-agent/v1/import_post/includes/quickcreator/class-quickcreator.php:171
POST/wp-json/quickcreator-agent/v1/change_post_status/includes/quickcreator/class-quickcreator.php:183
GET/wp-json/quickcreator-agent/v1/version/includes/quickcreator/class-quickcreator.php:196
GET/wp-json/quickcreator-agent/v1/categories/includes/quickcreator/class-quickcreator.php:209
GET/wp-json/quickcreator-agent/v1/tags/includes/quickcreator/class-quickcreator.php:222
GET/wp-json/quickcreator-agent/v1/users/includes/quickcreator/class-quickcreator.php:235
GET/wp-json/quickcreator-agent/v1/post_types/includes/quickcreator/class-quickcreator.php:248
POST/wp-json/quickcreator-agent/v1/disconnect_draft/includes/quickcreator/class-quickcreator.php:261
POST/wp-json/quickcreator-agent/v1/get_posts/includes/quickcreator/class-quickcreator.php:274
POST/wp-json/quickcreator-agent/v1/import_tag/includes/quickcreator/class-quickcreator.php:288
WordPress Hooks 12
actionadmin_menuincludes/admin/class-quickcreator-admin.php:28
actionadmin_initincludes/admin/class-quickcreator-admin.php:30
actionadmin_enqueue_scriptsincludes/admin/class-quickcreator-admin.php:32
actioninitincludes/class-quickcreator-agent.php:110
filtersafe_style_cssincludes/class-quickcreator-agent.php:112
filteruagb_post_query_args_gridincludes/class-quickcreator-agent.php:114
filteruagb_post_query_args_carouselincludes/class-quickcreator-agent.php:116
actionupgrader_process_completeincludes/class-quickcreator-agent.php:265
actionadmin_enqueue_scriptsincludes/class-quickcreator-agent.php:324
actionwp_enqueue_scriptsincludes/class-quickcreator-agent.php:345
actionrest_api_initincludes/quickcreator/class-quickcreator.php:62
filterrest_request_after_callbacksincludes/quickcreator/class-quickcreator.php:67
Maintenance & Trust

Quickcreator Agent Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 5, 2026
PHP min version7.4
Downloads265

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Quickcreator Agent Developer Profile

Quickcreator

2 plugins · 630 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
11 days
View full developer profile
Detection Fingerprints

How We Detect Quickcreator Agent

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quickcreator-agent/assets/css/quickcreator-connector.css/wp-content/plugins/quickcreator-agent/assets/js/quickcreator-connector.js
Script Paths
/wp-content/plugins/quickcreator-agent/assets/js/quickcreator-connector.js
Version Parameters
quickcreator-agent/assets/js/quickcreator-connector.js?ver=quickcreator-agent/assets/css/quickcreator-connector.css?ver=

HTML / DOM Fingerprints

CSS Classes
quickcreator-connector-popupquickcreator-connector-popup-wrapper
Data Attributes
data-quickcreator-agent-nonce
JS Globals
quickcreator_agent_connection_lang
REST Endpoints
/wp-json/quickcreator-agent/v1/connection
FAQ

Frequently Asked Questions about Quickcreator Agent