
Swell AI Image Block Security & Risk Analysis
wordpress.org/plugins/swell-ai-image-blockAI-powered Gutenberg block that automatically selects contextually relevant stock images — and finds your featured image too.
Is Swell AI Image Block Safe to Use in 2026?
Generally Safe
Score 100/100Swell AI Image Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The swell-ai-image-block plugin v1.1.1 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The plugin shows excellent practices regarding SQL queries, with all using prepared statements, and all identified outputs are properly escaped. There are no critical or high severity taint flows, and the vulnerability history is clean, with no known CVEs. The plugin also avoids bundling libraries, which can sometimes introduce vulnerabilities if not kept up-to-date.
However, several areas raise concerns that prevent a perfect score. The complete absence of nonce checks is a significant weakness, especially given the presence of file operations and external HTTP requests. Without nonces, these actions could be vulnerable to Cross-Site Request Forgery (CSRF) attacks if triggered by a malicious actor. While there are capability checks, their effectiveness is limited without accompanying nonce validation. The plugin also makes nine external HTTP requests, which, while not inherently insecure, represent potential attack vectors if the external services are compromised or if the requests are not handled with sufficient validation and sanitization.
In conclusion, swell-ai-image-block v1.1.1 is built on a foundation of good security practices, particularly in data handling and output sanitization. The lack of a vulnerability history is a positive indicator. The primary areas for improvement are the implementation of nonce checks for all sensitive operations, particularly those involving file handling and external requests, to mitigate CSRF risks. The number of external HTTP requests warrants careful review to ensure they are handled securely.
Key Concerns
- Missing nonce checks for critical operations
- File operations without nonce checks
- External HTTP requests without nonce checks
Swell AI Image Block Security Vulnerabilities
Swell AI Image Block Code Analysis
SQL Query Safety
Output Escaping
Swell AI Image Block Attack Surface
WordPress Hooks 5
Maintenance & Trust
Swell AI Image Block Maintenance & Trust
Maintenance Signals
Community Trust
Swell AI Image Block Alternatives
Instant Image Generator (AI Image by Gemini, Dall-E and One Click Image from Unsplash, Openverse, Pixabay, Pexels, Giphy)
ai-image
Search millions of stock photos, generate AI images with OpenAI & Gemini, browse GIFs, and import directly to your Media Library.
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
ZI Hide Featured Image
zi-hide-featured-image
This WP plugin hides the featured image on a single post or page.
All-Images.ai – IA Image Bank and Custom Image creation
all-images-ai
IA Image Bank and Custom Image creation IA
Imajinn – Magical AI Image Generation
imajinn-ai
Generate the perfect royalty-free images for your blog in seconds with cutting-edge AI for a fraction of the cost of stock photo sites.
Swell AI Image Block Developer Profile
2 plugins · 0 total installs
How We Detect Swell AI Image Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/swell-ai-image-block/build/index.js/wp-content/plugins/swell-ai-image-block/build/style-index.css/wp-content/plugins/swell-ai-image-block/build/index.jsswell-ai-image-block/build/index.js?ver=swell-ai-image-block/build/style-index.css?ver=HTML / DOM Fingerprints
swell-ai-image-block-editor-wrapperdata-swell-ai-image-block-editor-wrapperwindow.SwellAIImageBlock/wp-json/swell-ai-image-block/v1/analyze/wp-json/swell-ai-image-block/v1/search/wp-json/swell-ai-image-block/v1/track-download/wp-json/swell-ai-image-block/v1/usage/wp-json/swell-ai-image-block/v1/sideload-image