BlueBot – AI Powered Chatbot Security & Risk Analysis

wordpress.org/plugins/bluebot-ai-powered-chatbot

BlueBot is an AI chatbot plugin for WordPress that uses OpenAI API to improve user interaction on your site.

10 active installs v1.0.4 PHP 7.4+ WP 5.0+ Updated May 1, 2025
aichatbotlive-chatlive-supportopenai
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BlueBot – AI Powered Chatbot Safe to Use in 2026?

Generally Safe

Score 100/100

BlueBot – AI Powered Chatbot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The plugin "bluebot-ai-powered-chatbot" v1.0.4 exhibits a generally good security posture with several strengths, including the complete absence of known vulnerabilities and the exclusive use of prepared statements for all SQL queries. Additionally, the plugin demonstrates strong output escaping practices, with nearly all output properly escaped, and avoids dangerous functions and file operations. However, there are notable areas of concern. The plugin exposes two AJAX handlers without any authentication checks, creating a significant attack surface that could potentially be exploited by unauthenticated users. While no critical or high-severity taint flows were identified, the lack of taint analysis data means the possibility of such issues cannot be entirely ruled out.

The vulnerability history is clean, indicating a well-maintained plugin or a lack of past security scrutiny. The limited number of entry points, coupled with the majority of them being properly secured, is a positive sign. The primary risk lies in the unprotected AJAX handlers. While the plugin adheres to good practices in other areas like SQL and output handling, these unprotected entry points represent a clear and present danger that requires immediate attention.

Key Concerns

  • 2 AJAX handlers without auth checks
Vulnerabilities
None known

BlueBot – AI Powered Chatbot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BlueBot – AI Powered Chatbot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
12 prepared
Unescaped Output
2
81 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared12 total queries

Output Escaping

98% escaped83 total outputs
Attack Surface
2 unprotected

BlueBot – AI Powered Chatbot Attack Surface

Entry Points5
Unprotected2

AJAX Handlers 2

authwp_ajax_bccbai_refresh_nonceutility_functions\frontend_utility.php:12
noprivwp_ajax_bccbai_refresh_nonceutility_functions\frontend_utility.php:13

REST API Routes 2

POST/wp-json/bccbai/v1/chatbotincludes\class-bccbai-chatbot-api.php:30
GET/wp-json/bccbai/v1/chatbot/historyincludes\class-bccbai-chatbot-api.php:35

Shortcodes 1

[bccbai_chatbot] frontend\class-bccbai-chatbot-frontend.php:9
WordPress Hooks 12
actionadmin_menuadmin\class-bccbai-chatbot-admin.php:23
actionadmin_enqueue_scriptsadmin\class-bccbai-chatbot-admin.php:24
actionadmin_initadmin\class-bccbai-chatbot-admin.php:25
actionadmin_post_bccbai_start_content_analysisadmin\class-bccbai-chatbot-admin.php:28
actionadmin_initadmin\class-bccbai-chatbot-admin.php:31
actionplugins_loadedbluebot-ai-powered-chatbot.php:28
actioninitbluebot-ai-powered-chatbot.php:48
actionplugins_loadedbluebot-ai-powered-chatbot.php:75
actionrest_api_initincludes\class-bccbai-chatbot-api.php:25
filterwp_mail_content_typeincludes\class-bccbai-chatbot-conversation-manager.php:172
actioninitincludes\class-bccbai-chatbot.php:30
actionwp_footerincludes\class-bccbai-chatbot.php:63
Maintenance & Trust

BlueBot – AI Powered Chatbot Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 1, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BlueBot – AI Powered Chatbot Developer Profile

Salil Agarwal

2 plugins · 110 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BlueBot – AI Powered Chatbot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bluebot-ai-powered-chatbot/assets/admin/css/bccbai-admin.css/wp-content/plugins/bluebot-ai-powered-chatbot/assets/admin/js/bccbai-admin.js/wp-content/plugins/bluebot-ai-powered-chatbot/assets/admin/css/bccbai-accordion.css/wp-content/plugins/bluebot-ai-powered-chatbot/assets/admin/js/bccbai-accordion.js
Script Paths
/wp-content/plugins/bluebot-ai-powered-chatbot/assets/admin/js/bccbai-admin.js/wp-content/plugins/bluebot-ai-powered-chatbot/assets/admin/js/bccbai-accordion.js
Version Parameters
bluebot-ai-powered-chatbot/assets/admin/css/bccbai-admin.css?ver=bluebot-ai-powered-chatbot/assets/admin/js/bccbai-admin.js?ver=bluebot-ai-powered-chatbot/assets/admin/css/bccbai-accordion.css?ver=bluebot-ai-powered-chatbot/assets/admin/js/bccbai-accordion.js?ver=

HTML / DOM Fingerprints

CSS Classes
bccbai-chatbot-admin-stylebccbai-chatbot-accordion-style
HTML Comments
<!-- The `BCCBAI_Chatbot_Admin` class handles the admin-specific functionality of the BCCBAI Chatbot plugin. --><!-- Content Analysis Settings --><!-- Trigger auto content analysis if necessary -->
Data Attributes
data-bccbai-chatbot-nonce
JS Globals
bccbai_chatbot_display_modeBCCBAI_CHATBOT_VERSIONbccbai_chatbot_settings
FAQ

Frequently Asked Questions about BlueBot – AI Powered Chatbot