AI wrote secure WordPress code in all 32 tests, even without security prompts
A developer ran 32 controlled experiments to test whether AI assistants produce insecure WordPress plugin code when given ordinary feature requests with no security guidance. Each test began in a fresh environment, with no security-related context, plugins, or hints embedded in the prompts. Across all runs, the AI consistently applied correct output escaping, input sanitization, and file access guards without being asked. Even in trickier scenarios — such as rendering clickable URLs, where the wrong escaping function is a common mistake — the model chose the appropriate method every time. The results suggest that modern AI coding assistants may apply secure coding practices as a default habit rather than only in response to explicit instructions.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in