Sajjetti – AI Audit Security & Risk Analysis

wordpress.org/plugins/sajjetti-audit

AI-assisted theme and plugin scanner for security, performance, and best practices. Provides clear, actionable insights.

0 active installs v1.0.0 PHP 8.0+ WP 6.6+ Updated Oct 9, 2025
auditcode-analysisperformancescannersecurity
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sajjetti – AI Audit Safe to Use in 2026?

Generally Safe

Score 100/100

Sajjetti – AI Audit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The sajjetti-audit v1.0.0 plugin presents a mixed security picture. On the positive side, the plugin boasts a remarkably small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the static analysis shows no critical or high severity taint flows, a clean history of known CVEs, and a strong adherence to using prepared statements for SQL queries. This indicates a generally well-developed plugin with good awareness of common web vulnerabilities.

However, significant concerns arise from the lack of proper output escaping, with only 4% of outputs being properly escaped. This creates a high risk of cross-site scripting (XSS) vulnerabilities, where malicious code could be injected into the website. Additionally, the absence of any nonce or capability checks across all entry points, combined with a complete lack of direct security checks (nonce/capability checks), is a critical oversight. This means that even if the attack surface were larger, any potential entry points would be entirely unprotected against unauthorized actions.

In conclusion, while the plugin excels in minimizing its attack surface and handling SQL securely, the severe deficiency in output escaping and the complete lack of authorization checks are major security weaknesses. These issues, if exploited, could lead to significant compromise. The absence of historical vulnerabilities is positive but cannot negate the current, evident risks.

Key Concerns

  • Output escaping is severely lacking
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Sajjetti – AI Audit Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Sajjetti – AI Audit Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
76 prepared
Unescaped Output
135
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

97% prepared78 total queries

Output Escaping

4% escaped140 total outputs
Attack Surface

Sajjetti – AI Audit Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Sajjetti – AI Audit Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 9, 2025
PHP min version8.0
Downloads170

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Sajjetti – AI Audit Developer Profile

Sajjetti

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sajjetti – AI Audit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sajjetti-audit/assets/css/admin-global.css/wp-content/plugins/sajjetti-audit/assets/css/admin-onboard.css/wp-content/plugins/sajjetti-audit/assets/css/admin-page-min.css/wp-content/plugins/sajjetti-audit/assets/css/admin-page.css
Version Parameters
sajjetti-audit/assets/css/admin-onboard.css?ver=sajjetti-audit/assets/css/admin-global.css?ver=sajjetti-audit/assets/css/admin-page-min.css?ver=sajjetti-audit/assets/css/admin-page.css?ver=

HTML / DOM Fingerprints

CSS Classes
sajjetti-admin-noticesajjetti-audit-notice-error
FAQ

Frequently Asked Questions about Sajjetti – AI Audit