Before the coffee is cold
Testing the security of AI-written WordPress code, in the open.
Jun 26, 20263 min read54

Search for a command to run...
Series
A hands-on series testing whether AI-generated WordPress code is secure, from the simplest plugin to the complex.
Testing the security of AI-written WordPress code, in the open.

Two WordPress functions people constantly mix up, and the XSS hole that opens when they do.

A fair test, every plugin read by hand, and a result I did not expect.

Same request, three assistants, twenty-four injection-safe plugins, and the one default that split them.

The AI wrote WordPress code that escapes JavaScript correctly. Then I asked whether it was safe on purpose, or safe by luck.
