Boei – Chat Widget & AI Chatbot with 50+ Channels Security & Risk Analysis

wordpress.org/plugins/boei-help

Capture every lead. Reply instantly. Close more deals. AI chatbot, 50+ contact channels, single inbox, and lead tracking—all in one WordPress plugin.

1K active installs v1.8.0 PHP + WP 5.0+ Updated Jan 15, 2026
ai-agentchat-widgetcontact-formlead-generationomnichannel
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Boei – Chat Widget & AI Chatbot with 50+ Channels Safe to Use in 2026?

Generally Safe

Score 100/100

Boei – Chat Widget & AI Chatbot with 50+ Channels has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "boei-help" v1.8.0 plugin exhibits a generally good security posture, with no known vulnerabilities in its history and a well-protected attack surface. The plugin utilizes prepared statements for all SQL queries and includes nonce and capability checks for its single AJAX entry point. This demonstrates a commitment to following secure development practices.

However, a notable concern arises from the taint analysis, which identified two flows with unsanitized paths. While no critical or high severity issues were flagged, the presence of unsanitized paths, even if not leading to immediate exploitation in this analysis, represents a potential risk. Furthermore, the output escaping is only properly implemented for 49% of outputs, suggesting a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed.

Overall, the plugin is strong in its defense against common web vulnerabilities like SQL injection and unauthorized access. The absence of a vulnerability history is a positive indicator. The primary weaknesses lie in the potential for unsanitized path issues and insufficient output escaping, which could be exploited in conjunction with other factors or if the plugin's functionality changes. Addressing these areas would significantly enhance its security.

Key Concerns

  • Unsanitized paths identified in taint analysis
  • Low percentage of properly escaped output
Vulnerabilities
None known

Boei – Chat Widget & AI Chatbot with 50+ Channels Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Boei – Chat Widget & AI Chatbot with 50+ Channels Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
31
30 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

49% escaped61 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
boei_ajax_verify_key (boei-help.php:71)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Boei – Chat Widget & AI Chatbot with 50+ Channels Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_boei_verify_keyboei-help.php:94
WordPress Hooks 4
actioninitboei-help.php:34
actionwp_enqueue_scriptsboei-help.php:166
actionadmin_menuboei-help.php:209
actionadmin_noticesboei-help.php:548
Maintenance & Trust

Boei – Chat Widget & AI Chatbot with 50+ Channels Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 15, 2026
PHP min version
Downloads21K

Community Trust

Rating100/100
Number of ratings30
Active installs1K
Developer Profile

Boei – Chat Widget & AI Chatbot with 50+ Channels Developer Profile

Boei

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Boei – Chat Widget & AI Chatbot with 50+ Channels

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/boei-help/boei-help.js
Script Paths
https://app.boei.help/embed/k/https://cdn.boei.help/hello.js

HTML / DOM Fingerprints

CSS Classes
boei-card
Data Attributes
data-boei-key
JS Globals
BoeiWidgetSettings
REST Endpoints
/wp-json/boei-help/v1/settings
FAQ

Frequently Asked Questions about Boei – Chat Widget & AI Chatbot with 50+ Channels