Ask My Content – AI Q&A Chatbot Security & Risk Analysis

wordpress.org/plugins/ask-my-content

AI-powered Q&A chatbot floating chat, block and shortcode that answers questions based on your own site's pages and posts.

20 active installs v0.9.0 PHP 7.4+ WP 5.8+ Updated Feb 19, 2026
aichatbotcontent-searchknowledge-basevirtual-assistant
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Ask My Content – AI Q&A Chatbot Safe to Use in 2026?

Generally Safe

Score 100/100

Ask My Content – AI Q&A Chatbot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "ask-my-content" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. The absence of known CVEs and any recorded vulnerability history suggests a generally stable codebase. However, a significant concern arises from the presence of numerous unprotected AJAX handlers. With 7 out of 12 AJAX handlers lacking authentication checks, this opens a considerable attack surface for unauthorized actions, especially since these handlers represent direct entry points into the plugin's functionality. While taint analysis found no critical or high-severity issues, the lack of nonce checks on these unprotected AJAX endpoints, despite some capability checks being present, is a notable weakness. The plugin also has a relatively small attack surface outside of these AJAX handlers. In conclusion, while the plugin avoids common pitfalls like raw SQL and significant output escaping issues, the unsecured AJAX endpoints are a critical area that needs immediate attention to mitigate potential risks.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on some AJAX handlers
Vulnerabilities
None known

Ask My Content – AI Q&A Chatbot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ask My Content – AI Q&A Chatbot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
8
148 escaped
Nonce Checks
7
Capability Checks
8
File Operations
1
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

95% escaped156 total outputs
Attack Surface
7 unprotected

Ask My Content – AI Q&A Chatbot Attack Surface

Entry Points13
Unprotected7

AJAX Handlers 12

authwp_ajax_askmyco_admin_queryincludes\api.php:257
authwp_ajax_askmyco_public_queryincludes\api.php:267
noprivwp_ajax_askmyco_public_queryincludes\api.php:269
authwp_ajax_askmyco_refresh_public_nonceincludes\api.php:276
noprivwp_ajax_askmyco_refresh_public_nonceincludes\api.php:277
authwp_ajax_askmyco_refresh_admin_nonceincludes\api.php:288
authwp_ajax_askmyco_get_countersincludes\api.php:464
authwp_ajax_askmyco_get_paymentsincludes\api.php:491
authwp_ajax_askmyco_create_stripe_checkoutincludes\api.php:512
authwp_ajax_askmyco_get_statusincludes\settings.php:193
authwp_ajax_askmyco_loopback_testincludes\settings_warnings.php:8
noprivwp_ajax_askmyco_loopback_testincludes\settings_warnings.php:9

Shortcodes 1

[ask_my_content] ask-my-content.php:398
WordPress Hooks 12
actioninitask-my-content.php:74
actionwp_enqueue_scriptsask-my-content.php:281
actionwp_footerask-my-content.php:309
actionadmin_enqueue_scriptsask-my-content.php:461
actionupgrader_process_completeincludes\activate.php:192
filteraskmyco_backend_timeoutincludes\api.php:351
actionadmin_menuincludes\settings.php:15
actionadmin_initincludes\settings.php:65
actionsave_postincludes\sync.php:9
actionbefore_delete_postincludes\sync.php:34
actionwp_trash_postincludes\sync.php:50
actioninitincludes\utils.php:140
Maintenance & Trust

Ask My Content – AI Q&A Chatbot Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version7.4
Downloads817

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Ask My Content – AI Q&A Chatbot Developer Profile

Pavel Web Design LLC

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ask My Content – AI Q&A Chatbot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ask-my-content/assets/js/amc-chat-core.js/wp-content/plugins/ask-my-content/assets/js/ask-my-content.js/wp-content/plugins/ask-my-content/assets/js/amc-admin-init.js/wp-content/plugins/ask-my-content/assets/css/ask-my-content.css/wp-content/plugins/ask-my-content/assets/js/askmyco-settings.js/wp-content/plugins/ask-my-content/assets/js/amc-payments.js
Script Paths
/wp-content/plugins/ask-my-content/assets/js/amc-chat-core.js/wp-content/plugins/ask-my-content/assets/js/ask-my-content.js/wp-content/plugins/ask-my-content/assets/js/amc-admin-init.js/wp-content/plugins/ask-my-content/assets/js/askmyco-settings.js/wp-content/plugins/ask-my-content/assets/js/amc-payments.js
Version Parameters
ask-my-content/assets/js/amc-chat-core.js?ver=ask-my-content/assets/js/ask-my-content.js?ver=ask-my-content/assets/js/amc-admin-init.js?ver=ask-my-content/assets/css/ask-my-content.css?ver=ask-my-content/assets/js/askmyco-settings.js?ver=ask-my-content/assets/js/amc-payments.js?ver=

HTML / DOM Fingerprints

CSS Classes
amc-chatamc-chat-headeramc-chat-input-areaamc-chat-messageamc-chat-message-useramc-chat-message-botamc-chat-inputamc-chat-send-button
JS Globals
amcChatCoreamcChat
FAQ

Frequently Asked Questions about Ask My Content – AI Q&A Chatbot