RenewAI Post Creator Security & Risk Analysis

wordpress.org/plugins/renewai-post-creator-free

Generate high-quality blog post content using AI models from OpenAI, with premium features for Anthropic, Google Gemini and Perplexity.

10 active installs v1.4 PHP + WP 5.0+ Updated Nov 13, 2025
ai-content-generationanthropicgeminiopenaiperplexity
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is RenewAI Post Creator Safe to Use in 2026?

Generally Safe

Score 100/100

RenewAI Post Creator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The renewai-post-creator-free plugin, version 1.4, exhibits a generally good security posture. The static analysis reveals no directly exploitable vulnerabilities like unescaped output, dangerous functions, or raw SQL queries. The plugin also implements a healthy number of nonce and capability checks, suggesting a proactive approach to securing its entry points. The absence of known CVEs further strengthens this positive outlook, indicating a history of responsible development and patching if issues did arise.

However, a minor concern arises from the taint analysis, which identified one flow with an unsanitized path. While this did not result in a critical or high severity finding, it warrants attention as it could potentially lead to unexpected behavior or information disclosure if exploited under specific circumstances. The presence of an external HTTP request, while common, also represents a potential vector for supply chain attacks if the external service is compromised. The bundled Freemius library, while not flagged as outdated in the provided data, is an area to monitor for potential future vulnerabilities if it falls behind on updates.

Overall, the plugin appears secure for general use. The strengths lie in its adherence to best practices regarding SQL, output escaping, and authorization checks. The primary weakness is the single unsanitized path identified in the taint analysis, which, although minor in this instance, highlights the need for continuous vigilance in code sanitization. The lack of historical vulnerabilities is a significant positive indicator of the developer's commitment to security.

Key Concerns

  • Flow with unsanitized path
  • External HTTP request present
  • Bundled Freemius v1.0 library
Vulnerabilities
None known

RenewAI Post Creator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

RenewAI Post Creator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
37 escaped
Nonce Checks
3
Capability Checks
9
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

90% escaped41 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
<api-keys> (pages\api-keys.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

RenewAI Post Creator Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_generate_post_contentrenewai-post-creator.php:63
authwp_ajax_delete_renewai_log_filerenewai-post-creator.php:64
WordPress Hooks 4
actionadmin_menurenewai-post-creator.php:60
actionadd_meta_boxesrenewai-post-creator.php:61
actionadmin_enqueue_scriptsrenewai-post-creator.php:62
actionadmin_initrenewai-post-creator.php:65
Maintenance & Trust

RenewAI Post Creator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 13, 2025
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

RenewAI Post Creator Developer Profile

Derek Jubach

3 plugins · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RenewAI Post Creator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/renewai-post-creator-free/assets/css/renewai-styles.css/wp-content/plugins/renewai-post-creator-free/assets/js/app.js
Script Paths
/wp-content/plugins/renewai-post-creator-free/assets/js/app.js
Version Parameters
renewai-post-creator-free/assets/css/renewai-styles.css?ver=1.0renewai-post-creator-free/assets/js/app.js?ver=1.0

HTML / DOM Fingerprints

CSS Classes
renewai-settingsrenewai-content-generatorrenewai-prompt-editorrenewai-provider-settingsrenewai-api-key-formrenewai-log-viewer
HTML Comments
<!-- DO NOT REMOVE THIS IF, IT IS ESSENTIAL FOR THE `function_exists` CALL ABOVE TO PROPERLY WORK. --><!-- Include Freemius SDK. --><!-- Init Freemius. --><!-- Signal that SDK was initiated. -->+10 more
Data Attributes
data-renewai-providerdata-renewai-action
JS Globals
renewai_ajax_objectrenewai_vars
REST Endpoints
/wp-json/renewai-post-creator/v1/generate/wp-json/renewai-post-creator/v1/log/delete
FAQ

Frequently Asked Questions about RenewAI Post Creator