Bit Flows: AI Agent Automation with ChatGPT, Gemini, Claude, Perplexity, Google Sheets and More Security & Risk Analysis

wordpress.org/plugins/bit-pi

Intelligent automation handles your workflows, CRM, forms, WooCommerce, ChatGPT, and more tasks to maximize your marketing and business efficiency.

1K active installs v1.17.0 PHP 7.4+ WP 5.8+ Updated Mar 12, 2026
ai-agentautomationchatgptgoogle-sheetswebhooks
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bit Flows: AI Agent Automation with ChatGPT, Gemini, Claude, Perplexity, Google Sheets and More Safe to Use in 2026?

Generally Safe

Score 100/100

Bit Flows: AI Agent Automation with ChatGPT, Gemini, Claude, Perplexity, Google Sheets and More has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 22d ago
Risk Assessment

The "bit-pi" v1.17.0 plugin exhibits a generally strong security posture, particularly in its handling of SQL queries and output escaping, where 100% of operations utilize prepared statements and proper escaping respectively. The complete absence of known vulnerabilities (CVEs) in its history is a significant positive indicator. Furthermore, the static analysis reveals a remarkably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected or lack proper authentication/permission checks. This suggests a well-contained plugin with limited external interaction points.

However, the presence of the `shell_exec` function, a powerful and potentially dangerous capability, is a notable concern. While the static analysis did not reveal any taint flows or unsanitized paths associated with it, the mere existence of `shell_exec` in the codebase presents a latent risk. If not meticulously secured and controlled, it could be exploited to execute arbitrary commands on the server. The plugin's vulnerability history being completely clear might be due to its limited attack surface and perhaps careful development practices around the `shell_exec` function, but it does not eliminate the inherent risk associated with its presence.

In conclusion, "bit-pi" v1.17.0 demonstrates good security practices in several key areas, leading to a low immediate risk profile. The lack of known vulnerabilities and a well-protected attack surface are commendable. The primary weakness lies in the inclusion of `shell_exec`, which, despite no current exploitable issues identified, warrants careful monitoring and understanding of its implementation.

Key Concerns

  • Dangerous function shell_exec present
Vulnerabilities
None known

Bit Flows: AI Agent Automation with ChatGPT, Gemini, Claude, Perplexity, Google Sheets and More Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bit Flows: AI Agent Automation with ChatGPT, Gemini, Claude, Perplexity, Google Sheets and More Code Analysis

Dangerous Functions
3
Raw SQL Queries
0
2 prepared
Unescaped Output
0
27 escaped
Nonce Checks
4
Capability Checks
0
File Operations
9
External Requests
5
Bundled Libraries
1

Dangerous Functions Found

shell_exec$cpuCount = (int) trim(shell_exec('nproc'));backend\app\src\Queue\BackgroundProcessHandler.php:703
shell_exec$uptime = @shell_exec('uptime');backend\app\src\Queue\BackgroundProcessHandler.php:735
shell_exec$cpuLoad = trim(shell_exec('wmic cpu get loadpercentage'));backend\app\src\Queue\BackgroundProcessHandler.php:746

Bundled Libraries

Lodash

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped27 total outputs
Attack Surface

Bit Flows: AI Agent Automation with ChatGPT, Gemini, Claude, Perplexity, Google Sheets and More Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filtercron_schedulesbackend\app\src\Queue\BackgroundProcessHandler.php:37
actionadmin_noticesbackend\bootstrap.php:11
Maintenance & Trust

Bit Flows: AI Agent Automation with ChatGPT, Gemini, Claude, Perplexity, Google Sheets and More Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 12, 2026
PHP min version7.4
Downloads27K

Community Trust

Rating98/100
Number of ratings61
Active installs1K
Developer Profile

Bit Flows: AI Agent Automation with ChatGPT, Gemini, Claude, Perplexity, Google Sheets and More Developer Profile

Bit Apps

5 plugins · 39K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
43 days
View full developer profile
Detection Fingerprints

How We Detect Bit Flows: AI Agent Automation with ChatGPT, Gemini, Claude, Perplexity, Google Sheets and More

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bit-pi/assets/main-*.css/wp-content/plugins/bit-pi/assets/main-*-ba-assets-*.js
Script Paths
/wp-content/plugins/bit-pi/assets/main-*.js/wp-content/plugins/bit-pi/vite/client/src/config/devHotModule.js/wp-content/plugins/bit-pi/vite/client/@vite/client/wp-content/plugins/bit-pi/vite/client/src/main.tsx
Version Parameters
ver=1.17.0bit-pi-googleapis-PRECONNECTbit-pi-gstatic-PRECONNECT-CROSSORIGINbit-pi-fontbit-pi-index-MODULE

HTML / DOM Fingerprints

JS Globals
window.bit_pi_localized_script
FAQ

Frequently Asked Questions about Bit Flows: AI Agent Automation with ChatGPT, Gemini, Claude, Perplexity, Google Sheets and More