
AIOHM Knowledge Assistant Security & Risk Analysis
wordpress.org/plugins/aiohm-knowledge-assistantTransform your WordPress site into an intelligent knowledge base with AI-powered chatbots that embody your brand's unique voice.
Is AIOHM Knowledge Assistant Safe to Use in 2026?
Generally Safe
Score 100/100AIOHM Knowledge Assistant has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The aiohm-knowledge-assistant plugin v1.5.2 exhibits a generally strong security posture with several positive indicators. Notably, all identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) appear to have proper authentication checks, and the plugin demonstrates excellent output escaping practices, with 100% of outputs being properly escaped. Furthermore, a significant majority of SQL queries (89%) are protected by prepared statements, and the plugin includes a robust number of nonce and capability checks. The absence of any known CVEs or past vulnerabilities also contributes to a favorable security profile.
However, the static analysis does reveal some areas of concern that warrant attention. The presence of 17 taint flows with unsanitized paths, particularly 12 classified as high severity, indicates a potential risk. While no critical severity taint flows were found, these high-severity flows suggest that user-supplied data might be processed in a way that could lead to unintended consequences or vulnerabilities if exploited. The number of file operations (33) and external HTTP requests (10) also represent potential attack vectors, although the analysis doesn't specify if these are handled securely.
In conclusion, while the plugin has implemented many crucial security best practices, the 12 high-severity taint flows with unsanitized paths represent a tangible risk that should be investigated and remediated. The plugin's strong track record and good implementation of core security features are commendable, but a thorough review of these specific taint flows is necessary to ensure complete security.
Key Concerns
- High severity unsanitized taint flows
AIOHM Knowledge Assistant Security Vulnerabilities
AIOHM Knowledge Assistant Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
AIOHM Knowledge Assistant Attack Surface
AJAX Handlers 66
Shortcodes 4
WordPress Hooks 35
Scheduled Events 2
Maintenance & Trust
AIOHM Knowledge Assistant Maintenance & Trust
Maintenance Signals
Community Trust
AIOHM Knowledge Assistant Alternatives
Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search
echo-knowledge-base
A fully featured, easy-to-use documentation plugin with AI chat and search integration. Build beautiful knowledge bases, FAQs, docs, and wikis.
Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System
support-genix-lite
Manage customer support with a powerful helpdesk & support ticket system — track customer tickets, resolve, and streamline your support workflow.
AI Chatbot for WordPress by Customerly
customerly
AI Chatbot to support customers, create engaging messages and send automated emails.
BuddyBot – OpenAI Assistants, AI Chatbots and Support Agents for WordPress
buddybot-ai-custom-ai-assistant-and-chat-agent
Discover AI Chatbots for WordPress, only plugin built on native OpenAI assistants. Explore a new different way to chat!
Zeno – AI-Powered Chatbot
zeno-chatbot-ai
An AI-powered WordPress automation chatbot plugin that helps you automate support, engage visitors, and answer questions using OpenAI or Google Gemini
AIOHM Knowledge Assistant Developer Profile
1 plugin · 10 total installs
How We Detect AIOHM Knowledge Assistant
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aiohm-knowledge-assistant/assets/css/aiohm-pdf-generation.css/wp-content/plugins/aiohm-knowledge-assistant/assets/js/aiohm-pdf-generation.js/wp-content/plugins/aiohm-knowledge-assistant/assets/js/aiohm-chat.js/wp-content/plugins/aiohm-knowledge-assistant/assets/js/aiohm-chat-shortcode.js/wp-content/plugins/aiohm-knowledge-assistant/assets/js/aiohm-qa-shortcode.js/wp-content/plugins/aiohm-knowledge-assistant/assets/js/aiohm-search-shortcode.js/wp-content/plugins/aiohm-knowledge-assistant/assets/js/aiohm-pdf-generation.js/wp-content/plugins/aiohm-knowledge-assistant/assets/js/aiohm-chat.js/wp-content/plugins/aiohm-knowledge-assistant/assets/js/aiohm-chat-shortcode.js/wp-content/plugins/aiohm-knowledge-assistant/assets/js/aiohm-qa-shortcode.js/wp-content/plugins/aiohm-knowledge-assistant/assets/js/aiohm-search-shortcode.jsaiohm-knowledge-assistant/assets/css/aiohm-pdf-generation.css?ver=aiohm-knowledge-assistant/assets/js/aiohm-pdf-generation.js?ver=aiohm-knowledge-assistant/assets/js/aiohm-chat.js?ver=aiohm-knowledge-assistant/assets/js/aiohm-chat-shortcode.js?ver=aiohm-knowledge-assistant/assets/js/aiohm-qa-shortcode.js?ver=aiohm-knowledge-assistant/assets/js/aiohm-search-shortcode.js?ver=HTML / DOM Fingerprints
data-aiohm-qa-triggerdata-aiohm-qa-iddata-aiohm-chat-triggerdata-aiohm-chat-iddata-aiohm-search-triggerdata-aiohm-search-idaiohm_qa_shortcode_paramsaiohm_chat_shortcode_paramsaiohm_search_shortcode_params/wp-json/aiohm-knowledge-assistant/v1/search/wp-json/aiohm-knowledge-assistant/v1/chat[aiohm_knowledge_assistant_qa][aiohm_knowledge_assistant_chat][aiohm_knowledge_assistant_search]