ZRSoft AI Article Autopilot Security & Risk Analysis

wordpress.org/plugins/zrsoft-ai-article-autopilot

Generate SEO-ready posts with AI (text + optional featured image) from wp-admin.

0 active installs v0.2.2 PHP 7.4+ WP 6.0+ Updated Jan 10, 2026
aiautomationcontentseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ZRSoft AI Article Autopilot Safe to Use in 2026?

Generally Safe

Score 100/100

ZRSoft AI Article Autopilot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "zrsoft-ai-article-autopilot" v0.2.2 plugin exhibits a generally strong security posture based on the static analysis. The code adheres to good practices by utilizing prepared statements for all SQL queries and properly escaping all output. There are no identified critical or high severity taint flows, and the vulnerability history is clean, with no recorded CVEs. This suggests a conscientious development approach regarding common web vulnerabilities.

However, a significant concern arises from the presence of one unprotected AJAX handler. This represents a direct entry point into the plugin's functionality that lacks authentication checks. While the static analysis did not reveal specific vulnerabilities stemming from this handler, an unprotected AJAX endpoint is a prime target for attackers seeking to exploit plugin logic, potentially leading to unauthorized actions or information disclosure if the internal logic is not robustly secured against unauthenticated access.

In conclusion, the plugin demonstrates strengths in its secure coding practices for database interactions and output handling, and a clean vulnerability record. Nevertheless, the unprotected AJAX handler introduces a notable security weakness that warrants immediate attention. It's crucial to implement appropriate authentication and authorization checks for this endpoint to mitigate potential risks and maintain a robust security profile.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

ZRSoft AI Article Autopilot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ZRSoft AI Article Autopilot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
111 escaped
Nonce Checks
3
Capability Checks
3
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped111 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
aiac_render_settings_page (ai-article-autopilot.php:494)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

ZRSoft AI Article Autopilot Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_aiac_generateai-article-autopilot.php:397
WordPress Hooks 3
actionadmin_enqueue_scriptsai-article-autopilot.php:362
actionadmin_menuai-article-autopilot.php:366
actionwp_headai-article-autopilot.php:477
Maintenance & Trust

ZRSoft AI Article Autopilot Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 10, 2026
PHP min version7.4
Downloads112

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ZRSoft AI Article Autopilot Developer Profile

diamanto2011

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ZRSoft AI Article Autopilot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zrsoft-ai-article-autopilot/assets/css/admin.css/wp-content/plugins/zrsoft-ai-article-autopilot/assets/js/admin.js
Script Paths
/wp-content/plugins/zrsoft-ai-article-autopilot/assets/js/admin.js
Version Parameters
zrsoft-ai-article-autopilot/assets/css/admin.css?ver=zrsoft-ai-article-autopilot/assets/js/admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- wp:heading {"level":%d} --><!-- /wp:heading --><!-- wp:paragraph --><!-- /wp:paragraph -->+6 more
Data Attributes
id="aiac-root"
FAQ

Frequently Asked Questions about ZRSoft AI Article Autopilot