
Superdraft Security & Risk Analysis
wordpress.org/plugins/superdraftA free WordPress plugin providing AI-powered writing assistance, image generation and editing, smart tagging, and autocomplete for better workflow.
Is Superdraft Safe to Use in 2026?
Generally Safe
Score 100/100Superdraft has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the 'superdraft' plugin version 1.1.4 exhibits a strong security posture. The code analysis reveals no dangerous functions, all SQL queries are properly prepared, and all output is correctly escaped, indicating good development practices. Furthermore, the complete absence of known CVEs and a clean vulnerability history suggest a commitment to security by the developers or a lack of past exploitable issues. The plugin also demonstrates robust security checks with a significant number of nonce and capability checks across its entry points.
While the plugin performs well in core security metrics, a notable area to consider is the presence of file operations and external HTTP requests. Although the analysis doesn't explicitly detail any vulnerabilities related to these, any implementation in these areas always carries inherent risks that require careful review. The taint analysis showing zero flows with unsanitized paths is a positive sign, but it's crucial to remember that static analysis is not exhaustive. The lack of any identified vulnerabilities or high-risk code signals is reassuring, and the plugin appears to be well-secured against common attack vectors.
Superdraft Security Vulnerabilities
Superdraft Code Analysis
SQL Query Safety
Output Escaping
Superdraft Attack Surface
AJAX Handlers 3
REST API Routes 7
WordPress Hooks 26
Maintenance & Trust
Superdraft Maintenance & Trust
Maintenance Signals
Community Trust
Superdraft Alternatives
AI Ghostwriter Lite
ai-ghostwriter
AI-powered content planning, generation, and publishing for WordPress using OpenAI GPT models.
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin
uncanny-automator
Uncanny Automator is the easiest and most powerful way to connect your WordPress plugins, sites and apps together with powerful automations.
Hyve Lite — Conversational AI Chatbot
hyve-lite
Hyve is an AI-powered chatbot that transforms your WordPress content into engaging conversations.
WordClever – AI Content Writer
wordclever-ai-content-writer
WordClever AI Content Writer generates SEO-friendly product descriptions, meta titles, and more for WooCommerce with just a few clicks.
AI Blog Automator
ai-blog-automator
Automatically generate and publish SEO-optimized blog posts using AI with customizable scheduling. Pro version includes custom prompt templates.
Superdraft Developer Profile
1 plugin · 20 total installs
How We Detect Superdraft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/superdraft/assets/admin/css/superdraft-admin.css/wp-content/plugins/superdraft/assets/admin/js/superdraft-admin.js/wp-content/plugins/superdraft/assets/admin/js/superdraft-admin.jssuperdraft/assets/admin/css/superdraft-admin.css?ver=superdraft/assets/admin/js/superdraft-admin.js?ver=HTML / DOM Fingerprints
superdraft-admin-pagesuperdraft-settings-sectionsuperdraft-api-logs-page<!-- Superdraft API Logs Table --><!-- End Superdraft API Logs Table -->data-superdraft-moduledata-superdraft-setting-keySuperdraftAdmin