Block Diffusion – Generate images from text prompts Security & Risk Analysis

wordpress.org/plugins/stable-diffusion

Generate unique images from text prompts using machine learning, all in the cloud.

80 active installs v0.7.1 PHP 7.0+ WP 5.8+ Updated Mar 30, 2023
aiartificial-intelligenceblockpromptstable-diffusion
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Block Diffusion – Generate images from text prompts Safe to Use in 2026?

Generally Safe

Score 85/100

Block Diffusion – Generate images from text prompts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The static analysis of the 'stable-diffusion' v0.7.1 plugin reveals a generally strong security posture. The plugin exhibits no identified dangerous functions, all SQL queries use prepared statements, and all identified outputs are properly escaped. Furthermore, there are no file operations or known vulnerabilities, suggesting a diligent approach to secure coding practices. The absence of any taint analysis findings, critical or high severity, further reinforces this positive assessment. The plugin also has a limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, which is a significant security advantage.

However, several areas warrant attention. The plugin makes six external HTTP requests, which, while not inherently a vulnerability, represent a potential attack vector if not handled securely. More importantly, the complete lack of nonce checks and capability checks across all entry points is a significant concern. While the attack surface is currently zero, any future addition of entry points without these fundamental security measures would leave the plugin highly vulnerable to Cross-Site Request Forgery (CSRF) and privilege escalation attacks. The absence of vulnerability history is a positive indicator but doesn't guarantee future immunity.

In conclusion, the 'stable-diffusion' plugin demonstrates good secure coding practices in its current version, particularly regarding data handling and output sanitization. The lack of known vulnerabilities is a notable strength. The primary weakness lies in the absence of essential security checks like nonces and capability checks on its (currently non-existent) entry points, which creates a future risk if the attack surface expands. The external HTTP requests also present a minor, though not critical, area for review.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • External HTTP requests
Vulnerabilities
None known

Block Diffusion – Generate images from text prompts Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Block Diffusion – Generate images from text prompts Release Timeline

v0.7.1Current
v0.7.0
v0.6.0
v0.5.0
v0.4.0
v0.3.0
v0.2.0
v0.1.8
v0.1.7
v0.1.6
v0.1.5
v0.1.4
v0.1.3
v0.1.2
v0.1.1
v0.1.0
Code Analysis
Analyzed Mar 16, 2026

Block Diffusion – Generate images from text prompts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
6
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Block Diffusion – Generate images from text prompts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionrest_api_initphp\routes.php:5
actionadmin_initphp\settings.php:5
actionrest_api_initphp\settings.php:6
actioninitstable-diffusion.php:16
Maintenance & Trust

Block Diffusion – Generate images from text prompts Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMar 30, 2023
PHP min version7.0
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs80
Developer Profile

Block Diffusion – Generate images from text prompts Developer Profile

Kevin Batdorf

11 plugins · 12K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Block Diffusion – Generate images from text prompts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/stable-diffusion/build/index.js/wp-content/plugins/stable-diffusion/build/index.css
Script Paths
/wp-content/plugins/stable-diffusion/build/index.js
Version Parameters
stable-diffusion/build/index.js?ver=stable-diffusion/build/index.css?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/kevinbatdorf/stable-diffusion/
FAQ

Frequently Asked Questions about Block Diffusion – Generate images from text prompts