60 AI-written WordPress plugins, and JavaScript escaping that is safe by accident A developer's study of 60 AI-written WordPress plugins found that coding assistants often escape output for the wrong context, leaving security holes such as javascript: URLs in href attributes. The post details how context-dependent escaping functions like esc_url() and wp_json_encode() are needed, and notes that AI assistants frequently fail to apply them correctly in JavaScript contexts. This post has two halves: what "escape your output" actually means once the obvious answer stops working, and then a study of whether current AI assistants get that harder version right. It continues a series https://blog.lunetrax.com/so-can-you-stop-checking-ais-wordpress-code on what coding assistants actually produce when a non-expert asks them for WordPress code. Start with a line that passes review and still leaves a hole: echo '