
SPAI – Similar posts AI Plugin Security & Risk Analysis
wordpress.org/plugins/similar-posts-ai-spaiCreates an AI-based recommended articles widget. The fastest plugin, since all calculations take place on the developer's servers.
Is SPAI – Similar posts AI Plugin Safe to Use in 2026?
Generally Safe
Score 100/100SPAI – Similar posts AI Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "similar-posts-ai-spai" v1.8.1 plugin presents significant concerns, primarily due to its unprotected attack surface. With all 6 AJAX handlers lacking any authentication or capability checks, there's a high risk of unauthenticated users triggering potentially sensitive operations. The taint analysis, while limited in scope with only 2 flows, identified 2 flows with unsanitized paths, indicating a potential for vulnerabilities if these paths were to be exploited through the unprotected AJAX endpoints. The plugin demonstrates some good practices, such as a high percentage of SQL queries using prepared statements and a high rate of properly escaped output, which mitigates some risks. However, the absence of any nonce checks on AJAX handlers is a critical oversight. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign suggesting a generally well-maintained codebase. Despite the lack of past vulnerabilities and good practices in SQL and output handling, the substantial unprotected attack surface and the presence of unsanitized paths in taint flows create a considerable risk that outweighs these strengths.
Key Concerns
- AJAX handlers without authentication
- Flows with unsanitized paths
- Missing nonce checks on AJAX
- Capability checks missing on AJAX
SPAI – Similar posts AI Plugin Security Vulnerabilities
SPAI – Similar posts AI Plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SPAI – Similar posts AI Plugin Attack Surface
AJAX Handlers 6
WordPress Hooks 14
Maintenance & Trust
SPAI – Similar posts AI Plugin Maintenance & Trust
Maintenance Signals
Community Trust
SPAI – Similar posts AI Plugin Alternatives
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
YARPP – Yet Another Related Posts Plugin
yet-another-related-posts-plugin
The best WordPress plugin for displaying related posts. Simple and flexible, with a powerful proven algorithm and inbuilt caching.
Contextual Related Posts
contextual-related-posts
Keep visitors on your site longer with intelligent, fast-loading, contextually related posts. Block, shortcode, custom post type and widget ready.
Related Posts for WordPress
related-posts-for-wp
The best WordPress plugin for related posts. Simple, flexible, powerful algorithm, and built-in caching. Fully setup with only 1 click!
Awesome Related Posts – Display Contextual Similar Posts
awesome-related-posts
Displays related posts based on categories, tags, and custom taxonomies with customizable layouts.
SPAI – Similar posts AI Plugin Developer Profile
1 plugin · 10 total installs
How We Detect SPAI – Similar posts AI Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/similar-posts-ai-spai/public/css/spai-short_codes.css/wp-content/plugins/similar-posts-ai-spai/admin/css/spai-admin.css/wp-content/plugins/similar-posts-ai-spai/admin/libs/spectrum/spectrum.min.css/wp-content/plugins/similar-posts-ai-spai/public/css/spai-public.css/wp-content/plugins/similar-posts-ai-spai/admin/js/spai-admin.js/wp-content/plugins/similar-posts-ai-spai/admin/js/spai-admin-preview.js/wp-content/plugins/similar-posts-ai-spai/admin/js/spai-admin.js/wp-content/plugins/similar-posts-ai-spai/admin/js/spai-admin-preview.jssimilar-posts-ai-spai/public/css/spai-short_codes.css?ver=similar-posts-ai-spai/admin/css/spai-admin.css?ver=similar-posts-ai-spai/admin/libs/spectrum/spectrum.min.css?ver=similar-posts-ai-spai/public/css/spai-public.css?ver=similar-posts-ai-spai/admin/js/spai-admin.js?ver=similar-posts-ai-spai/admin/js/spai-admin-preview.js?ver=HTML / DOM Fingerprints
<!--
This file is part of the SPAI plugin.
-->
window.SPAI_VERSIONwindow.spai_admin_datawindow.spai_optionswindow.spai_admin_settings