TicLabs AI Content Hub Security & Risk Analysis

wordpress.org/plugins/ticlabs-ai-content-hub

Flexible AI content generation plugin. Generate content, images & optimize SEO with OpenAI, Google AI, Anthropic, Stability AI & more.

0 active installs v1.0.0 PHP 8.0+ WP 6.0+ Updated Jan 8, 2026
aiartificial-intelligencecontent-generationimage-generation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TicLabs AI Content Hub Safe to Use in 2026?

Generally Safe

Score 100/100

TicLabs AI Content Hub has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'ticlabs-ai-content-hub' plugin exhibits several concerning security practices, despite some positive indicators. The most significant risk stems from its substantial attack surface, with 8 out of 18 AJAX handlers lacking authentication checks. This presents a clear pathway for unauthenticated users to interact with potentially sensitive plugin functionalities, increasing the likelihood of exploitation if vulnerabilities exist within these handlers. While the plugin demonstrates good practices in SQL query preparation and output escaping, the taint analysis revealing flows with unsanitized paths is a red flag, even without critical or high severity designations. These unsanitized paths could lead to directory traversal or other file-based attacks, particularly when combined with the single file operation detected.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths
  • File operations detected
Vulnerabilities
None known

TicLabs AI Content Hub Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TicLabs AI Content Hub Release Timeline

v1.0
Code Analysis
Analyzed Apr 16, 2026

TicLabs AI Content Hub Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
216 escaped
Nonce Checks
5
Capability Checks
5
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped216 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
ticlabsaich_ajax_save_image_data_to_media_library (includes/class-plugin.php:351)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

TicLabs AI Content Hub Attack Surface

Entry Points18
Unprotected8

AJAX Handlers 18

noprivwp_ajax_ticlabsaich_generate_contentincludes/class-plugin.php:41
authwp_ajax_ticlabsaich_generate_contentincludes/class-plugin.php:42
noprivwp_ajax_ticlabsaich_save_api_keyincludes/class-plugin.php:43
authwp_ajax_ticlabsaich_save_api_keyincludes/class-plugin.php:44
noprivwp_ajax_ticlabsaich_get_text_api_configincludes/class-plugin.php:45
authwp_ajax_ticlabsaich_get_text_api_configincludes/class-plugin.php:46
noprivwp_ajax_ticlabsaich_get_image_api_configincludes/class-plugin.php:47
authwp_ajax_ticlabsaich_get_image_api_configincludes/class-plugin.php:48
noprivwp_ajax_ticlabsaich_save_license_keyincludes/class-plugin.php:49
authwp_ajax_ticlabsaich_save_license_keyincludes/class-plugin.php:50
noprivwp_ajax_ticlabsaich_save_image_to_media_libraryincludes/class-plugin.php:51
authwp_ajax_ticlabsaich_save_image_to_media_libraryincludes/class-plugin.php:52
noprivwp_ajax_ticlabsaich_save_image_data_to_media_libraryincludes/class-plugin.php:53
authwp_ajax_ticlabsaich_save_image_data_to_media_libraryincludes/class-plugin.php:54
authwp_ajax_ticlabsaich_async_generate_imageincludes/class-plugin.php:56
noprivwp_ajax_ticlabsaich_async_generate_imageincludes/class-plugin.php:57
authwp_ajax_ticlabsaich_async_check_statusincludes/class-plugin.php:59
noprivwp_ajax_ticlabsaich_async_check_statusincludes/class-plugin.php:60
WordPress Hooks 5
actionadmin_menuincludes/class-admin.php:11
actionadmin_enqueue_scriptsincludes/class-admin.php:12
actioninitincludes/class-plugin.php:32
actionadmin_initincludes/class-plugin.php:33
actionplugins_loadedticlabs-ai-content-hub.php:37
Maintenance & Trust

TicLabs AI Content Hub Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 8, 2026
PHP min version8.0
Downloads144

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

TicLabs AI Content Hub Developer Profile

tomich78

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TicLabs AI Content Hub

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ticlabs-ai-content-hub/admin/css/admin.css/wp-content/plugins/ticlabs-ai-content-hub/admin/js/admin.js
Script Paths
/wp-content/plugins/ticlabs-ai-content-hub/admin/js/admin.js
Version Parameters
ticlabs-ai-content-hub/admin/css/admin.css?ver=ticlabs-ai-content-hub/admin/js/admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-route
JS Globals
ticlabsaich_dataticlabsaich_PROVIDERS
FAQ

Frequently Asked Questions about TicLabs AI Content Hub