
Alkubot – Gamify discounts, sell more and give less at the right time Security & Risk Analysis
wordpress.org/plugins/alkubotThe negotiator chatbot that sells your product to hesitant visitors.
Is Alkubot – Gamify discounts, sell more and give less at the right time Safe to Use in 2026?
Mostly Safe
Score 84/100Alkubot – Gamify discounts, sell more and give less at the right time is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The 'alkubot' plugin v3.0.0 exhibits a mixed security posture, with some positive aspects overshadowed by significant concerns. While the absence of raw SQL queries and a lack of critical or high-severity taint flows are encouraging, the plugin suffers from a substantial attack surface due to three unprotected AJAX handlers. This direct exposure to unauthenticated users presents a considerable risk, as malicious actors could potentially exploit these entry points.
The vulnerability history indicates a past high-severity Cross-Site Request Forgery (CSRF) vulnerability, though it is currently patched. The fact that a high-severity issue was present in the past, combined with the current lack of capability checks and minimal output escaping, suggests a pattern of potential oversight in security best practices. The plugin's limited use of output escaping (17%) further exacerbates the risk of cross-site scripting (XSS) vulnerabilities, especially when combined with the unprotected AJAX endpoints.
In conclusion, while the plugin demonstrates some good practices like using prepared statements for SQL, the presence of multiple unprotected AJAX handlers and poor output escaping practices pose a significant security risk. The past high-severity vulnerability also warrants caution. Developers should prioritize implementing proper authentication and authorization checks for all AJAX handlers and improve output sanitization to mitigate the identified risks.
Key Concerns
- Unprotected AJAX handlers present significant attack surface
- Low percentage of properly escaped output
- Lack of capability checks for AJAX handlers
- History of high-severity vulnerability (CSRF)
Alkubot – Gamify discounts, sell more and give less at the right time Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Alkubot – Gamify discounts, sell more and give less at the right time < 3.0.0 - Cross-Site Request Forgery
Alkubot – Gamify discounts, sell more and give less at the right time Code Analysis
Output Escaping
Data Flow Analysis
Alkubot – Gamify discounts, sell more and give less at the right time Attack Surface
AJAX Handlers 3
WordPress Hooks 9
Maintenance & Trust
Alkubot – Gamify discounts, sell more and give less at the right time Maintenance & Trust
Maintenance Signals
Community Trust
Alkubot – Gamify discounts, sell more and give less at the right time Alternatives
Sitewide Discount for WooCommerce: Apply Discount to All Products
global-shop-discount-for-woocommerce
Add global shop discount to all WooCommerce products. Beautifully.
Manage Discount in Admin Orders for WooCommerce
manage-discount-in-admin-orders-for-woocommerce
This plugin allows you to manage discounts in WooCommerce orders placed in the backoffice.
Notification WooCommerce
notification-woocommerce
The easy and ultimate solution for notifiaction that lets your customer set notification for product availablity and/or discount.
BenriBot for WooCommerce
benribot-for-woocommerce
Integrates the BenriBot AI chat widget into your WooCommerce store with a modern React-based admin interface.
ConvertyBot – AI Sales Assistant for WooCommerce
convertybot
Transform your WooCommerce store into a 24/7 sales machine! AI-powered chatbot that recommends products, generates coupons, and converts visitors into …
Alkubot – Gamify discounts, sell more and give less at the right time Developer Profile
1 plugin · 10 total installs
How We Detect Alkubot – Gamify discounts, sell more and give less at the right time
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/alkubot/assets/css/admin/adminMenu.css/wp-content/plugins/alkubot/assets/css/admin/notification.css/wp-content/plugins/alkubot/assets/css/admin/admin.css/wp-content/plugins/alkubot/assets/js/adminPopup.js/wp-content/plugins/alkubot/assets/js/admin.js/wp-content/plugins/alkubot/index.js/wp-content/plugins/alkubot/assets/js/adminPopup.js/wp-content/plugins/alkubot/assets/js/admin.js/wp-content/plugins/alkubot/index.jsalkubotAdminMenualkubotAdminNotificationalkubotAdminalkubot-admin-popupalkubot-adminalkubot-frontendHTML / DOM Fingerprints
alkubot-admin-menualkubot-notificationalkubot-admin-wrapperdata-alkubot-chatalkubot/wp-json/alkubot/v1/product/wp-json/alkubot/v1/category/wp-json/alkubot/v1/coupon/wp-json/alkubot/v1/store/wp-json/alkubot/v1/notification