AfroditaBot Security & Risk Analysis

wordpress.org/plugins/afrodita

AfroditaBot añade un widget de chat flotante basado en inteligencia artificial a tu sitio web WordPress. Ideal para atención al cliente automatizada.

10 active installs v5.0 PHP 7.4+ WP 6.8+ Updated Jun 22, 2025
aiassistantchatbotfloating-chatgpt
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AfroditaBot Safe to Use in 2026?

Generally Safe

Score 100/100

AfroditaBot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The 'afrodita' plugin v5.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and properly escaping a high percentage of its outputs. There are no recorded vulnerabilities or CVEs, suggesting a history of responsible development or a lack of public exposure to exploits.

However, significant security concerns arise from its attack surface. The plugin exposes three AJAX handlers, all of which lack authentication checks. This is a critical oversight, as it allows any unauthenticated user to trigger these handlers, potentially leading to unauthorized actions or information disclosure if the handlers themselves have exploitable logic that wasn't flagged in the static analysis (e.g., due to lack of taint flow data). The absence of nonce checks further exacerbates this risk, making it easier for attackers to craft malicious requests.

While the static analysis did not reveal critical taint flows or unsanitized paths, the lack of authentication on a substantial portion of its entry points is a major weakness. The vulnerability history being clear is a positive indicator, but it doesn't negate the immediate risks posed by the exposed AJAX endpoints. The plugin's strengths lie in its careful SQL handling and output escaping, but these are overshadowed by the readily accessible unprotected AJAX functionality.

Key Concerns

  • AJAX handlers without authentication checks
  • AJAX handlers without nonce checks
  • Unescaped output detected
Vulnerabilities
None known

AfroditaBot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AfroditaBot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped12 total outputs
Attack Surface
3 unprotected

AfroditaBot Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_guardar_usuario_jsonafrodita.php:139
authwp_ajax_obtener_config_usuarioafrodita.php:209
noprivwp_ajax_obtener_config_usuarioafrodita.php:210
WordPress Hooks 7
actionadmin_menuafrodita.php:44
actionadmin_enqueue_scriptsafrodita.php:59
actionwp_enqueue_scriptsafrodita.php:126
actionadmin_enqueue_scriptsafrodita.php:128
filterupload_mimesafrodita.php:250
actionadmin_enqueue_scriptsafrodita.php:280
actionwp_footerafrodita.php:328
Maintenance & Trust

AfroditaBot Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 22, 2025
PHP min version7.4
Downloads890

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

AfroditaBot Developer Profile

afroditachatbot

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AfroditaBot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/afrodita/assets/css/chat-widget2.css/wp-content/plugins/afrodita/assets/js/chat-widget2.js/wp-content/plugins/afrodita/assets/css/Afrotw.css
Script Paths
/wp-content/plugins/afrodita/assets/js/chat-widget2.js
Version Parameters
afroiabo-style?ver=2.3afroiabo-script?ver=2.3afrodiabo-tailwind?ver=4.5

HTML / DOM Fingerprints

CSS Classes
afrodiabo-tailwind
Data Attributes
data-admin-emaildata-site-url
JS Globals
afroiaboChatWidgetConfigappConfig
REST Endpoints
/wp-json/afrodita/v1/get-config/wp-json/afrodita/v1/send-message
FAQ

Frequently Asked Questions about AfroditaBot