WordClever – AI Content Writer Security & Risk Analysis

wordpress.org/plugins/wordclever-ai-content-writer

WordClever AI Content Writer generates SEO-friendly product descriptions, meta titles, and more for WooCommerce with just a few clicks.

3K active installs v1.0.8 PHP 7.4+ WP 5.2+ Updated Aug 16, 2025
ai-toolai-powered-writingcontent-automationproduct-descriptions
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WordClever – AI Content Writer Safe to Use in 2026?

Generally Safe

Score 100/100

WordClever – AI Content Writer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The plugin "wordclever-ai-content-writer" v1.0.8 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, unpatched vulnerabilities, or critical/high severity issues in the vulnerability history is a significant positive indicator. Furthermore, the code analysis shows excellent practices, including 100% usage of prepared statements for SQL queries and 100% proper output escaping, which are crucial for preventing common web vulnerabilities. The presence of nonce checks on 7 out of 8 AJAX handlers is also a good sign, mitigating potential CSRF attacks.

However, there are a few areas that warrant attention. The most notable concern is the complete lack of capability checks on any of the 8 AJAX handlers. While nonce checks offer some protection, the absence of proper authorization checks means that any user, regardless of their role or permissions, could potentially trigger these AJAX actions. This could lead to unauthorized operations if the AJAX handlers perform sensitive actions. Additionally, the presence of one file operation and nine external HTTP requests, while not inherently vulnerable, increases the plugin's potential attack surface and the risk of introducing vulnerabilities if not handled with extreme care and proper validation of inputs and outputs.

In conclusion, the plugin demonstrates a solid foundation in secure coding practices, particularly concerning SQL and output handling. The lack of historical vulnerabilities is reassuring. The primary weakness lies in the missing capability checks for its AJAX endpoints, which represents the most significant security risk identified. Addressing this would further enhance the plugin's security.

Key Concerns

  • AJAX handlers without capability checks
Vulnerabilities
None known

WordClever – AI Content Writer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WordClever – AI Content Writer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
236 escaped
Nonce Checks
7
Capability Checks
0
File Operations
1
External Requests
9
Bundled Libraries
0

Output Escaping

100% escaped237 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
handle_license_verification (includes\class-wordclever-metabox.php:818)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WordClever – AI Content Writer Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 8

authwp_ajax_wordclever_get_filtered_productsglobal-functions.php:161
noprivwp_ajax_wordclever_get_filtered_productsglobal-functions.php:162
authwp_ajax_wordclever_generate_contentincludes\class-wordclever-metabox.php:8
authwp_ajax_wordclever_get_used_requestincludes\class-wordclever-metabox.php:13
authwp_ajax_wordclever_verify_licenseincludes\class-wordclever-metabox.php:14
authwp_ajax_wordclever_authincludes\class-wordclever-metabox.php:19
authwp_ajax_wordclever_support_tab_formincludes\class-wordclever-metabox.php:20
authwp_ajax_wordclever_reset_auth_passincludes\class-wordclever-metabox.php:21
WordPress Hooks 8
actionadd_meta_boxesincludes\class-wordclever-metabox.php:6
actionadmin_enqueue_scriptsincludes\class-wordclever-metabox.php:7
actionadmin_menuincludes\class-wordclever-metabox.php:9
actionadmin_menuincludes\class-wordclever-metabox.php:10
actionadmin_initincludes\class-wordclever-metabox.php:15
actionadmin_initincludes\class-wordclever-metabox.php:16
actionplugins_loadedwordclever.php:54
actionadmin_noticeswordclever.php:65
Maintenance & Trust

WordClever – AI Content Writer Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 16, 2025
PHP min version7.4
Downloads22K

Community Trust

Rating0/100
Number of ratings0
Active installs3K
Developer Profile

WordClever – AI Content Writer Developer Profile

WP Radiant

74 plugins · 14K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WordClever – AI Content Writer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wordclever-ai-content-writer/assets/css/metabox.css/wp-content/plugins/wordclever-ai-content-writer/assets/js/metabox.js/wp-content/plugins/wordclever-ai-content-writer/assets/images/bundle-banner.png/wp-content/plugins/wordclever-ai-content-writer/assets/css/admin-upsell-banner.css
Script Paths
/wp-content/plugins/wordclever-ai-content-writer/assets/js/metabox.js
Version Parameters
wordclever-ai-content-writer/assets/css/metabox.css?ver=wordclever-ai-content-writer/assets/js/metabox.js?ver=

HTML / DOM Fingerprints

CSS Classes
wordclever-upsell-bannerwordclever-banner-main-wrapwordclever-banner-imgwordclever-banner-contentwordclever-banner-btn-contentwordclever-disocunt-wrapwordclever-bundlle-btnwordclever-username+2 more
Data Attributes
id="wordclever-username"id="wordclever-request-info"id="wordclever-banner-main"
JS Globals
wordclever_ajax_object
REST Endpoints
/wp-json/wordclever/v1/generate_content/wp-json/wordclever/v1/get_used_request/wp-json/wordclever/v1/verify_license/wp-json/wordclever/v1/auth/wp-json/wordclever/v1/support_tab_form/wp-json/wordclever/v1/reset_auth_pass
FAQ

Frequently Asked Questions about WordClever – AI Content Writer