Authyo ChatLead – Chatbot Lead Capture Security & Risk Analysis

wordpress.org/plugins/authyo-chatlead

Capture and verify leads with Authyo OTP APIs. Interactive chatbot with email and phone verification, customizable forms, and lead management.

0 active installs v1.0.1 PHP 7.2+ WP 5.0+ Updated Feb 19, 2026
chatbotcontact-formlead-capturelead-managementotp-verification
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Authyo ChatLead – Chatbot Lead Capture Safe to Use in 2026?

Generally Safe

Score 100/100

Authyo ChatLead – Chatbot Lead Capture has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The authyo-chatlead plugin, version 1.0.1, exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query preparation and output escaping, with 79% of SQL queries using prepared statements and 98% of outputs properly escaped. The plugin also has a clean vulnerability history, with no recorded CVEs, indicating a lack of publicly known security flaws. However, a significant concern arises from the attack surface analysis. Two AJAX handlers are present, and critically, both lack authentication checks. This creates a direct entry point for unauthenticated attackers to potentially interact with sensitive plugin functionalities.

The taint analysis shows two flows with unsanitized paths, although these are not flagged as critical or high severity. This warrants further investigation into the nature of these unsanitized paths, as even low-severity issues can sometimes be chained with other vulnerabilities or exploited in specific contexts. While the absence of dangerous functions, REST API vulnerabilities, and bundled libraries is positive, the unprotected AJAX endpoints represent the most immediate and significant security risk. A balanced conclusion is that while the plugin has a solid foundation in secure coding practices for SQL and output, the unprotected AJAX handlers expose it to potential exploitation by unauthenticated users.

Key Concerns

  • AJAX handlers without authentication checks
  • Flows with unsanitized paths (non-critical)
Vulnerabilities
None known

Authyo ChatLead – Chatbot Lead Capture Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Authyo ChatLead – Chatbot Lead Capture Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
11 prepared
Unescaped Output
2
100 escaped
Nonce Checks
7
Capability Checks
4
File Operations
1
External Requests
2
Bundled Libraries
0

SQL Query Safety

79% prepared14 total queries

Output Escaping

98% escaped102 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
display_leads_page (admin\class-authyo-chatlead-admin.php:375)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Authyo ChatLead – Chatbot Lead Capture Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 2

authwp_ajax_authyo_chatlead_test_otpincludes\class-authyo-chatlead.php:146
authwp_ajax_authyo_chatlead_verify_test_otpincludes\class-authyo-chatlead.php:147

Shortcodes 2

[authyo_chatlead] frontend\class-authyo-chatlead-public.php:57
[chatlead_by_authyo] frontend\class-authyo-chatlead-public.php:59
WordPress Hooks 15
actionwp_footerfrontend\class-authyo-chatlead-public.php:80
actionadmin_initincludes\class-authyo-chatlead-customizer.php:54
actionadmin_menuincludes\class-authyo-chatlead-customizer.php:55
actionwp_enqueue_scriptsincludes\class-authyo-chatlead-customizer.php:56
actionadmin_menuincludes\class-authyo-chatlead.php:140
actionadmin_initincludes\class-authyo-chatlead.php:141
actionadmin_enqueue_scriptsincludes\class-authyo-chatlead.php:142
actionwp_enqueue_scriptsincludes\class-authyo-chatlead.php:166
actionwp_enqueue_scriptsincludes\class-authyo-chatlead.php:167
actioninitincludes\class-authyo-chatlead.php:171
actioninitincludes\class-authyo-chatlead.php:174
actionauthyo_chatlead_daily_country_refreshincludes\class-authyo-chatlead.php:178
actionadmin_post_authyo_chatlead_refresh_countriesincludes\class-authyo-chatlead.php:182
actionrest_api_initincludes\class-authyo-chatlead.php:187
actionrest_api_initincludes\class-authyo-chatlead.php:191

Scheduled Events 1

authyo_chatlead_daily_country_refresh
Maintenance & Trust

Authyo ChatLead – Chatbot Lead Capture Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version7.2
Downloads199

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Authyo ChatLead – Chatbot Lead Capture Developer Profile

Konceptwise Digital Media Pvt Ltd

10 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Authyo ChatLead – Chatbot Lead Capture

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/authyo-chatlead/admin/css/authyo-chatlead-form-builder.css/wp-content/plugins/authyo-chatlead/admin/css/authyo-chatlead-leads.css/wp-content/plugins/authyo-chatlead/admin/css/authyo-chatlead-admin-settings.css/wp-content/plugins/authyo-chatlead/admin/js/authyo-chatlead-form-builder.js/wp-content/plugins/authyo-chatlead/admin/js/authyo-chatlead-test-otp.js/wp-content/plugins/authyo-chatlead/js/authyo-chatlead.js/wp-content/plugins/authyo-chatlead/css/authyo-chatlead.css/wp-content/plugins/authyo-chatlead/assets/css/authyo-chatlead-frontend.css+1 more
Script Paths
admin/js/authyo-chatlead-form-builder.jsadmin/js/authyo-chatlead-test-otp.jsjs/authyo-chatlead.jsassets/js/authyo-chatlead-frontend.js
Version Parameters
authyo-chatlead-form-builder?ver=authyo-chatlead-leads?ver=authyo-chatlead-admin-settings?ver=authyo-chatlead-test-otp?ver=authyo-chatlead.js?ver=authyo-chatlead.css?ver=authyo-chatlead-frontend.css?ver=authyo-chatlead-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
authyo-chatlead-widget-container
HTML Comments
<!-- authyo-chatlead-widget -->
Data Attributes
data-authyo-chatlead-id
JS Globals
authyoChatLeadAdminParams
REST Endpoints
/wp-json/authyo-chatlead/v1/submit
FAQ

Frequently Asked Questions about Authyo ChatLead – Chatbot Lead Capture