SG AI Studio Security & Risk Analysis

wordpress.org/plugins/sg-ai-studio

Manage your WordPress site with AI - create content, install plugins, and perform site management tasks effortlessly.

1K active installs v1.1.3 PHP 7.4+ WP 5.0+ Updated Apr 14, 2026
aicontentmanagementsitegroundstudio
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SG AI Studio Safe to Use in 2026?

Generally Safe

Score 100/100

SG AI Studio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The sg-ai-studio v1.1.3 plugin exhibits a generally strong security posture based on the static analysis. All identified SQL queries utilize prepared statements, a critical best practice that mitigates SQL injection risks. Furthermore, all output is properly escaped, which is essential for preventing Cross-Site Scripting (XSS) vulnerabilities. The plugin also demonstrates good use of nonces and capability checks for its entry points, and no critical or high-severity taint flows were detected. The absence of known CVEs and past vulnerabilities reinforces this positive outlook.

Despite these strengths, there are a few areas that warrant consideration. The presence of two cron events, while not inherently insecure, represents potential points of execution that, if not meticulously secured, could become vectors for attack. The plugin also makes 10 external HTTP requests, which, depending on the target of these requests and the data transmitted, could introduce risks related to data leakage or man-in-the-middle attacks if not handled with secure protocols and proper validation. The inclusion of the Guzzle library, while common, requires attention to ensure it's updated to the latest secure version.

Overall, sg-ai-studio v1.1.3 appears to be a well-developed plugin from a security perspective, adhering to many core security principles. The limited attack surface and secure handling of data are commendable. However, ongoing vigilance regarding the security of its scheduled tasks and external communication, along with maintaining up-to-date bundled libraries, will be key to preserving its secure state.

Key Concerns

  • Bundled library (Guzzle) may be outdated
  • Potential risks from external HTTP requests
  • Two cron events present potential execution points
Vulnerabilities
None known

SG AI Studio Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SG AI Studio Release Timeline

v1.1.3Current
Code Analysis
Analyzed Apr 16, 2026

SG AI Studio Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
31 prepared
Unescaped Output
0
117 escaped
Nonce Checks
4
Capability Checks
13
File Operations
2
External Requests
10
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared31 total queries

Output Escaping

100% escaped117 total outputs
Attack Surface

SG AI Studio Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionnetwork_admin_menucore/Loader/Loader.php:93
actionadmin_menucore/Loader/Loader.php:94
actionadmin_enqueue_scriptscore/Loader/Loader.php:96
actionadmin_enqueue_scriptscore/Loader/Loader.php:98
actionadmin_print_stylescore/Loader/Loader.php:100
actionadmin_initcore/Loader/Loader.php:102
actionadmin_print_footer_scriptscore/Loader/Loader.php:104
actionrest_api_initcore/Loader/Loader.php:106
actionwp_insert_sitecore/Loader/Loader.php:112
actioninitcore/Loader/Loader.php:116
actionadmin_initcore/Loader/Loader.php:120
actionsg_ai_studio_clear_logs_croncore/Loader/Loader.php:122
actioninitcore/Loader/Loader.php:134
actionrest_api_initcore/Loader/Loader.php:145
actionenqueue_block_editor_assetscore/Loader/Loader.php:156
filtercron_schedulescore/Loader/Loader.php:178
actioninitcore/Loader/Loader.php:187
actionsg_ai_studio_key_refresh_croncore/Loader/Loader.php:190
filterwp_die_handlercore/Rest/Themes.php:1236

Scheduled Events 2

sg_ai_studio_clear_logs_cron
sg_ai_studio_key_refresh_cron
Maintenance & Trust

SG AI Studio Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 14, 2026
PHP min version7.4
Downloads17K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

SG AI Studio Developer Profile

SiteGround

5 plugins · 2.1M total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
483 days
View full developer profile
Detection Fingerprints

How We Detect SG AI Studio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sg-ai-studio/assets/css/settings.css/wp-content/plugins/sg-ai-studio/assets/js/settings.js/wp-content/plugins/sg-ai-studio/assets/js/chat.js
Script Paths
/wp-content/plugins/sg-ai-studio/assets/js/settings.js/wp-content/plugins/sg-ai-studio/assets/js/chat.js
Version Parameters
sg-ai-studio/assets/css/settings.css?ver=sg-ai-studio/assets/js/settings.js?ver=sg-ai-studio/assets/js/chat.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-ai-studio-settings-containersiteground-ai-studio
Data Attributes
data-dom-element-id="wp-ai-studio-settings-container"data-page="settings"
JS Globals
WPAIStudioSettingsConfigWPAIStudioConfig
REST Endpoints
/wp-json/sg-ai-studio
FAQ

Frequently Asked Questions about SG AI Studio