
Tish WordPress Theme AI Customizer Security & Risk Analysis
wordpress.org/plugins/tish-theme-ai-customizer-liteCustomize any WordPress theme with GPT-5 — describe it, preview it, approve it.
Is Tish WordPress Theme AI Customizer Safe to Use in 2026?
Generally Safe
Score 100/100Tish WordPress Theme AI Customizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The tish-theme-ai-customizer-lite plugin v1.0.0 exhibits a generally good security posture with some areas for improvement. The plugin demonstrates strong adherence to secure coding practices, with a high percentage of SQL queries using prepared statements and a majority of output being properly escaped. The absence of any known CVEs or past vulnerabilities is a positive indicator of the developers' attention to security. Furthermore, the plugin does not bundle any external libraries, reducing the risk associated with outdated or vulnerable dependencies.
However, the presence of three AJAX handlers without authentication checks presents a notable attack surface. While the static analysis did not reveal any critical or high-severity taint flows, these unprotected AJAX endpoints could potentially be exploited if they process user-supplied data in an insecure manner, especially if combined with other vulnerabilities or logic flaws. The absence of shortcodes, cron events, and REST API routes, along with the presence of nonce and capability checks in other areas, mitigates some of the overall risk, but the unprotected AJAX handlers remain the primary concern in this assessment.
Key Concerns
- 3 AJAX handlers without auth checks
Tish WordPress Theme AI Customizer Security Vulnerabilities
Tish WordPress Theme AI Customizer Code Analysis
SQL Query Safety
Output Escaping
Tish WordPress Theme AI Customizer Attack Surface
AJAX Handlers 5
WordPress Hooks 9
Maintenance & Trust
Tish WordPress Theme AI Customizer Maintenance & Trust
Maintenance Signals
Community Trust
Tish WordPress Theme AI Customizer Alternatives
TJ Custom CSS
theme-junkie-custom-css
Easily to add any Custom CSS code to your WordPress website.
Color Scheme every Theme
color-scheme-every-theme
This plugin lets you change the entire color scheme of the current theme via the
SPM Show Colors for Elementor
spm-show-colors-for-elementor
Copies Elementor global or custom HEX color value to clipboard.
Simple Custom CSS and JS
custom-css-js
Easily add Custom CSS or JS to your website with an awesome editor.
Kirki Customizer Framework
kirki
The Ultimate Customizer Framework for WordPress Theme Developers
Tish WordPress Theme AI Customizer Developer Profile
54 plugins · 3K total installs
How We Detect Tish WordPress Theme AI Customizer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tish-theme-ai-customizer-lite/assets/css/admin.css/wp-content/plugins/tish-theme-ai-customizer-lite/assets/js/admin.js/wp-content/plugins/tish-theme-ai-customizer-lite/assets/js/selector.jsassets/js/admin.jsassets/js/selector.jstish-ai-admintish-ai-selectorHTML / DOM Fingerprints
<!-- Tish AI Preview CSS --><!-- Tish AI Approved CSS -->id='tish-ai-preview-css'id='tish-ai-approved-css'id='tish-ai-selector-hide-adminbar'TISH_AI/wp-json/tish-ai/v1/test-openai-key/wp-json/tish-ai/v1/generate-css/wp-json/tish-ai/v1/approve-css