
BOLT AI Features Security & Risk Analysis
wordpress.org/plugins/bolt-ai-featuresAI-powered chatbot with intelligent Q&A, floating chat interface, content embedding, user history, and admin dashboard.
Is BOLT AI Features Safe to Use in 2026?
Generally Safe
Score 100/100BOLT AI Features has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bolt-ai-features plugin version 0.6.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history are positive indicators. The code analysis reveals no critical or high-severity taint flows, and SQL queries are exclusively handled using prepared statements. Furthermore, the plugin demonstrates good practice by incorporating nonce and capability checks on many of its AJAX handlers, and there are no immediate concerns regarding dangerous functions, file operations, or bundled libraries. The limited attack surface, particularly with all AJAX handlers protected, is also a strength.
However, there are areas for improvement. A significant portion of the output (24%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. While the plugin has 20 AJAX handlers, only 7 have capability checks, leaving 13 potentially vulnerable to unauthorized access if their function is sensitive. The plugin also makes 15 external HTTP requests, and without further analysis, it's unknown if these are handled securely, potentially exposing the site to risks if the external services are compromised or if data is transmitted insecurely. Despite these potential risks, the plugin's current history and lack of critical code findings suggest a moderate overall risk profile with opportunities for refinement.
Key Concerns
- Unescaped output detected
- Limited capability checks on AJAX
- External HTTP requests without auth
BOLT AI Features Security Vulnerabilities
BOLT AI Features Code Analysis
Output Escaping
Data Flow Analysis
BOLT AI Features Attack Surface
AJAX Handlers 20
WordPress Hooks 7
Maintenance & Trust
BOLT AI Features Maintenance & Trust
Maintenance Signals
Community Trust
BOLT AI Features Alternatives
UltraPress – AI Assistant, Chatbot & SEO
ultrapress
The AI Brain for your WordPress site. Engage visitors with a smart chatbot and enhance your SEO with AI-powered tools.
AI Chatbot for WordPress by Customerly
customerly
AI Chatbot to support customers, create engaging messages and send automated emails.
BuddyBot – OpenAI Assistants, AI Chatbots and Support Agents for WordPress
buddybot-ai-custom-ai-assistant-and-chat-agent
Discover AI Chatbots for WordPress, only plugin built on native OpenAI assistants. Explore a new different way to chat!
AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant
chatbot-ai-free-models
Add an AI Chatbot to your WordPress site for instant live chat or customer support. Featuring GPT, Claude, Llama and 70+ free models.
Cheshire Cat Chatbot
cheshire-cat-chatbot
A WordPress plugin to integrate the Cheshire Cat AI chatbot, offering seamless conversational AI for your site.
BOLT AI Features Developer Profile
1 plugin · 0 total installs
How We Detect BOLT AI Features
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bolt-ai-features/build/index.js/wp-content/plugins/bolt-ai-features/build/style-index.css/wp-content/plugins/bolt-ai-features/assets/css/admin-style.css/wp-content/plugins/bolt-ai-features/assets/css/bolt-chatbot-style.css/wp-content/plugins/bolt-ai-features/assets/js/bolt-chatbot.js/wp-content/plugins/bolt-ai-features/assets/js/bolt-chatHistory.js/wp-content/plugins/bolt-ai-features/assets/js/bolt-chatSettings.js/wp-content/plugins/bolt-ai-features/assets/js/bolt-data-user.js+5 more/wp-content/plugins/bolt-ai-features/build/index.js/wp-content/plugins/bolt-ai-features/build/style-index.css/wp-content/plugins/bolt-ai-features/assets/css/admin-style.css/wp-content/plugins/bolt-ai-features/assets/css/bolt-chatbot-style.css/wp-content/plugins/bolt-ai-features/assets/js/bolt-chatbot.js/wp-content/plugins/bolt-ai-features/assets/js/bolt-chatHistory.js+7 morebolt-ai-features/build/index.js?ver=bolt-ai-features/build/style-index.css?ver=bolt-ai-features/assets/css/admin-style.css?ver=bolt-ai-features/assets/css/bolt-chatbot-style.css?ver=bolt-ai-features/assets/js/bolt-chatbot.js?ver=bolt-ai-features/assets/js/bolt-chatHistory.js?ver=bolt-ai-features/assets/js/bolt-chatSettings.js?ver=bolt-ai-features/assets/js/bolt-data-user.js?ver=bolt-ai-features/assets/js/bolt-embeddings.js?ver=bolt-ai-features/assets/js/bolt-login-protection.js?ver=bolt-ai-features/assets/js/bolt-models.js?ver=bolt-ai-features/assets/js/bolt-overview.js?ver=bolt-ai-features/assets/js/bolt-statistics.js?ver=HTML / DOM Fingerprints
boltai-chat-containerboltai-chat-windowboltai-chat-headerboltai-chat-messagesboltai-messageboltai-user-messageboltai-ai-messageboltai-input-area+17 more<!-- BOLT AI Features Plugin --><!-- Admin settings for BOLT AI --><!-- User data management for BOLT AI --><!-- Embeddings management for BOLT AI -->+1 moredata-boltai-actiondata-boltai-noncedata-boltai-chat-idwindow.boltai_ajax_objectwindow.boltai_chat_settings/wp-json/boltai/v1/processContentForEmbedding/wp-json/boltai/v1/getUserChatHistory/wp-json/boltai/v1/getAllUsersAggregatedChatHistory/wp-json/boltai/v1/getApiAuthenticationToken/wp-json/boltai/v1/submitQuestionToAI/wp-json/boltai/v1/submitUserFeedback/wp-json/boltai/v1/deleteQuestionAndFeedback/wp-json/boltai/v1/deleteUserData/wp-json/boltai/v1/getAIModelName/wp-json/boltai/v1/getUsageStatistics/wp-json/boltai/v1/retrieveSiteConfiguration