AI Agent by SiteGround Security & Risk Analysis

wordpress.org/plugins/sg-ai-studio

Manage your WordPress site with AI - create content, install plugins, and perform site management tasks effortlessly.

1.0M active installs v1.2.6 PHP 7.4+ WP 5.0+ Updated Jul 8, 2026
agentaichatbotconnectorsiteground
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AI Agent by SiteGround Safe to Use in 2026?

Generally Safe

Score 100/100

AI Agent by SiteGround has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The sg-ai-studio v1.1.3 plugin exhibits a generally strong security posture based on the static analysis. All identified SQL queries utilize prepared statements, a critical best practice that mitigates SQL injection risks. Furthermore, all output is properly escaped, which is essential for preventing Cross-Site Scripting (XSS) vulnerabilities. The plugin also demonstrates good use of nonces and capability checks for its entry points, and no critical or high-severity taint flows were detected. The absence of known CVEs and past vulnerabilities reinforces this positive outlook.

Despite these strengths, there are a few areas that warrant consideration. The presence of two cron events, while not inherently insecure, represents potential points of execution that, if not meticulously secured, could become vectors for attack. The plugin also makes 10 external HTTP requests, which, depending on the target of these requests and the data transmitted, could introduce risks related to data leakage or man-in-the-middle attacks if not handled with secure protocols and proper validation. The inclusion of the Guzzle library, while common, requires attention to ensure it's updated to the latest secure version.

Overall, sg-ai-studio v1.1.3 appears to be a well-developed plugin from a security perspective, adhering to many core security principles. The limited attack surface and secure handling of data are commendable. However, ongoing vigilance regarding the security of its scheduled tasks and external communication, along with maintaining up-to-date bundled libraries, will be key to preserving its secure state.

Key Concerns

  • Bundled library (Guzzle) may be outdated
  • Potential risks from external HTTP requests
  • Two cron events present potential execution points
Vulnerabilities
None known

AI Agent by SiteGround Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

AI Agent by SiteGround Release Timeline

v1.2.6Current
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.1.9
v1.1.8
v1.1.7
v1.1.6
v1.1.5
v1.1.4
v1.1.3
Code Analysis
Analyzed Apr 16, 2026

AI Agent by SiteGround Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
31 prepared
Unescaped Output
0
117 escaped
Nonce Checks
4
Capability Checks
13
File Operations
2
External Requests
10
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared31 total queries

Output Escaping

100% escaped117 total outputs
Attack Surface

AI Agent by SiteGround Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionnetwork_admin_menucore/Loader/Loader.php:93
actionadmin_menucore/Loader/Loader.php:94
actionadmin_enqueue_scriptscore/Loader/Loader.php:96
actionadmin_enqueue_scriptscore/Loader/Loader.php:98
actionadmin_print_stylescore/Loader/Loader.php:100
actionadmin_initcore/Loader/Loader.php:102
actionadmin_print_footer_scriptscore/Loader/Loader.php:104
actionrest_api_initcore/Loader/Loader.php:106
actionwp_insert_sitecore/Loader/Loader.php:112
actioninitcore/Loader/Loader.php:116
actionadmin_initcore/Loader/Loader.php:120
actionsg_ai_studio_clear_logs_croncore/Loader/Loader.php:122
actioninitcore/Loader/Loader.php:134
actionrest_api_initcore/Loader/Loader.php:145
actionenqueue_block_editor_assetscore/Loader/Loader.php:156
filtercron_schedulescore/Loader/Loader.php:178
actioninitcore/Loader/Loader.php:187
actionsg_ai_studio_key_refresh_croncore/Loader/Loader.php:190
filterwp_die_handlercore/Rest/Themes.php:1236

Scheduled Events 2

sg_ai_studio_clear_logs_cron
sg_ai_studio_key_refresh_cron
Maintenance & Trust

AI Agent by SiteGround Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJul 8, 2026
PHP min version7.4
Downloads7.5M

Community Trust

Rating28/100
Number of ratings80
Active installs1.0M
Developer Profile

AI Agent by SiteGround Developer Profile

SiteGround

5 plugins · 3.1M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
387 days
View full developer profile
Detection Fingerprints

How We Detect AI Agent by SiteGround

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sg-ai-studio/assets/css/settings.css/wp-content/plugins/sg-ai-studio/assets/js/settings.js/wp-content/plugins/sg-ai-studio/assets/js/chat.js
Script Paths
/wp-content/plugins/sg-ai-studio/assets/js/settings.js/wp-content/plugins/sg-ai-studio/assets/js/chat.js
Version Parameters
sg-ai-studio/assets/css/settings.css?ver=sg-ai-studio/assets/js/settings.js?ver=sg-ai-studio/assets/js/chat.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-ai-studio-settings-containersiteground-ai-studio
Data Attributes
data-dom-element-id="wp-ai-studio-settings-container"data-page="settings"
JS Globals
WPAIStudioSettingsConfigWPAIStudioConfig
REST Endpoints
/wp-json/sg-ai-studio
FAQ

Frequently Asked Questions about AI Agent by SiteGround