WBAI BlogsAi Security & Risk Analysis

wordpress.org/plugins/wbai-blogsai

Generate blog post ideas, full articles, and featured images using artificial intelligence directly inside WordPress.

20 active installs v1.0.1 PHP 7.3+ WP 6.0+ Updated Feb 26, 2026
aiautomationbloggingcontentseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WBAI BlogsAi Safe to Use in 2026?

Generally Safe

Score 100/100

WBAI BlogsAi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The wbai-blogsai plugin version 1.0.1 exhibits a generally strong security posture based on the static analysis. It demonstrates good practices by implementing robust authentication and authorization checks for all identified AJAX entry points. The absence of dangerous functions and the exclusive use of prepared statements for SQL queries are significant strengths. Furthermore, the plugin has a clean vulnerability history with no known CVEs, indicating a commitment to security or simply a lack of past discoveries.

However, there are areas that warrant attention. The presence of 5 taint flows with unsanitized paths, even though not classified as critical or high severity, suggests potential for unexpected behavior or information leakage if exploited. Additionally, while 82% of output is properly escaped, the remaining 18% could present a cross-site scripting (XSS) risk if user-controlled data is involved in those unescaped outputs. The plugin also performs file operations and makes external HTTP requests, which are common vectors for introducing vulnerabilities if not handled with extreme care.

Key Concerns

  • Taint flows with unsanitized paths
  • Unescaped output detected
  • File operations detected
  • External HTTP requests detected
Vulnerabilities
None known

WBAI BlogsAi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WBAI BlogsAi Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

WBAI BlogsAi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
59
260 escaped
Nonce Checks
13
Capability Checks
10
File Operations
1
External Requests
3
Bundled Libraries
0

Output Escaping

82% escaped319 total outputs
Data Flows · Security
5 unsanitized

Data Flow Analysis

11 flows5 with unsanitized paths
<call-server> (includes\call-server.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WBAI BlogsAi Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 7

authwp_ajax_wbai_blogsai_regenerate_image_from_listincludes\images.php:174
authwp_ajax_wbai_blogsai_save_excerpt_prefpages\edit-article.php:42
authwp_ajax_wbai_blogsai_generate_blog_ideaspages\generate-ideas.php:4
authwp_ajax_wbai_blogsai_save_blog_ideapages\generate-ideas.php:5
authwp_ajax_wbai_blogsai_delete_blog_ideapages\generate-ideas.php:151
authwp_ajax_wbai_blogsai_relancer_blog_ideapages\ideas.php:4
authwp_ajax_wbai_blogsai_generate_keywordspages\keywords.php:111
WordPress Hooks 23
actioninitincludes\call-server.php:118
filtercron_schedulesincludes\cron.php:4
actionwbai_blogsai_poll_images_eventincludes\cron.php:14
actionwp_headincludes\function.php:22
actioncurrent_screenincludes\function.php:36
actionadmin_enqueue_scriptsincludes\function.php:45
filterhttp_api_argsincludes\http.php:5
actionadd_meta_boxesincludes\images.php:15
filtermanage_posts_columnsincludes\images.php:79
actionmanage_posts_custom_columnincludes\images.php:85
actionadmin_enqueue_scriptsincludes\images.php:142
actionadmin_menuincludes\menu.php:4
actionadmin_menuincludes\menu.php:70
actioninitpages\edit-article.php:6
actionedit_form_after_titlepages\edit-article.php:19
actionadmin_enqueue_scriptspages\edit-article.php:68
actionadmin_enqueue_scriptspages\generate-ideas.php:759
actionadmin_enqueue_scriptspages\generate-single.php:826
actionadmin_enqueue_scriptspages\keywords.php:193
actionadmin_initpages\settings.php:7
actionadmin_initpages\settings.php:172
actionadmin_enqueue_scriptspages\settings.php:691
actionadmin_enqueue_scriptswbai-blogsai.php:90
Maintenance & Trust

WBAI BlogsAi Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.3
Downloads470

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

WBAI BlogsAi Developer Profile

raphaelvallat

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WBAI BlogsAi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wbai-blogsai/assets/css/style.css/wp-content/plugins/wbai-blogsai/assets/js/script.js
Script Paths
/wp-content/plugins/wbai-blogsai/assets/js/script.js
Version Parameters
wbai-blogsai/assets/css/style.css?ver=wbai-blogsai/assets/js/script.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-wbai-token
JS Globals
wbai_blogsai_vars
FAQ

Frequently Asked Questions about WBAI BlogsAi