BOLT AI Features Security & Risk Analysis

wordpress.org/plugins/bolt-ai-features

AI-powered chatbot with intelligent Q&A, floating chat interface, content embedding, user history, and admin dashboard.

0 active installs v0.6.0 PHP 7.4+ WP 5.6+ Updated Unknown
assistantchatchatbotembeddingrag
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BOLT AI Features Safe to Use in 2026?

Generally Safe

Score 100/100

BOLT AI Features has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The bolt-ai-features plugin version 0.6.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history are positive indicators. The code analysis reveals no critical or high-severity taint flows, and SQL queries are exclusively handled using prepared statements. Furthermore, the plugin demonstrates good practice by incorporating nonce and capability checks on many of its AJAX handlers, and there are no immediate concerns regarding dangerous functions, file operations, or bundled libraries. The limited attack surface, particularly with all AJAX handlers protected, is also a strength.

However, there are areas for improvement. A significant portion of the output (24%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. While the plugin has 20 AJAX handlers, only 7 have capability checks, leaving 13 potentially vulnerable to unauthorized access if their function is sensitive. The plugin also makes 15 external HTTP requests, and without further analysis, it's unknown if these are handled securely, potentially exposing the site to risks if the external services are compromised or if data is transmitted insecurely. Despite these potential risks, the plugin's current history and lack of critical code findings suggest a moderate overall risk profile with opportunities for refinement.

Key Concerns

  • Unescaped output detected
  • Limited capability checks on AJAX
  • External HTTP requests without auth
Vulnerabilities
None known

BOLT AI Features Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

BOLT AI Features Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
35
108 escaped
Nonce Checks
10
Capability Checks
7
File Operations
0
External Requests
15
Bundled Libraries
0

Output Escaping

76% escaped143 total outputs
Data Flows
All sanitized

Data Flow Analysis

5 flows
boltai_getUserChatHistory (bolt-ai-features.php:586)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BOLT AI Features Attack Surface

Entry Points20
Unprotected0

AJAX Handlers 20

authwp_ajax_boltai_processContentForEmbeddingbolt-ai-features.php:24
noprivwp_ajax_boltai_getUserChatHistorybolt-ai-features.php:26
authwp_ajax_boltai_getUserChatHistorybolt-ai-features.php:27
noprivwp_ajax_boltai_getAllUsersAggregatedChatHistorybolt-ai-features.php:28
authwp_ajax_boltai_getAllUsersAggregatedChatHistorybolt-ai-features.php:29
noprivwp_ajax_boltai_getApiAuthenticationTokenbolt-ai-features.php:30
authwp_ajax_boltai_getApiAuthenticationTokenbolt-ai-features.php:31
noprivwp_ajax_boltai_submitQuestionToAIbolt-ai-features.php:32
authwp_ajax_boltai_submitQuestionToAIbolt-ai-features.php:33
noprivwp_ajax_boltai_submitUserFeedbackbolt-ai-features.php:34
authwp_ajax_boltai_submitUserFeedbackbolt-ai-features.php:35
noprivwp_ajax_boltai_deleteQuestionAndFeedbackbolt-ai-features.php:36
authwp_ajax_boltai_deleteQuestionAndFeedbackbolt-ai-features.php:37
noprivwp_ajax_boltai_deleteUserDatabolt-ai-features.php:38
authwp_ajax_boltai_deleteUserDatabolt-ai-features.php:39
authwp_ajax_boltai_getAIModelNamebolt-ai-features.php:43
authwp_ajax_boltai_getUsageStatisticsbolt-ai-features.php:44
authwp_ajax_boltai_retrieveSiteConfigurationbolt-ai-features.php:45
authwp_ajax_boltai_getUserIdentificationDatabolt-ai-features.php:523
noprivwp_ajax_boltai_getUserIdentificationDatabolt-ai-features.php:524
WordPress Hooks 7
actionadmin_menubolt-ai-features.php:25
actionwp_enqueue_scriptsbolt-ai-features.php:40
actionadmin_enqueue_scriptsbolt-ai-features.php:41
actionadmin_initbolt-ai-features.php:42
actionadmin_initbolt-ai-features.php:126
actionwp_enqueue_scriptsbolt-ai-features.php:1169
actionwp_footerbolt-ai-features.php:1280
Maintenance & Trust

BOLT AI Features Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads290

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

BOLT AI Features Developer Profile

hsmwbolt

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BOLT AI Features

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bolt-ai-features/build/index.js/wp-content/plugins/bolt-ai-features/build/style-index.css/wp-content/plugins/bolt-ai-features/assets/css/admin-style.css/wp-content/plugins/bolt-ai-features/assets/css/bolt-chatbot-style.css/wp-content/plugins/bolt-ai-features/assets/js/bolt-chatbot.js/wp-content/plugins/bolt-ai-features/assets/js/bolt-chatHistory.js/wp-content/plugins/bolt-ai-features/assets/js/bolt-chatSettings.js/wp-content/plugins/bolt-ai-features/assets/js/bolt-data-user.js+5 more
Script Paths
/wp-content/plugins/bolt-ai-features/build/index.js/wp-content/plugins/bolt-ai-features/build/style-index.css/wp-content/plugins/bolt-ai-features/assets/css/admin-style.css/wp-content/plugins/bolt-ai-features/assets/css/bolt-chatbot-style.css/wp-content/plugins/bolt-ai-features/assets/js/bolt-chatbot.js/wp-content/plugins/bolt-ai-features/assets/js/bolt-chatHistory.js+7 more
Version Parameters
bolt-ai-features/build/index.js?ver=bolt-ai-features/build/style-index.css?ver=bolt-ai-features/assets/css/admin-style.css?ver=bolt-ai-features/assets/css/bolt-chatbot-style.css?ver=bolt-ai-features/assets/js/bolt-chatbot.js?ver=bolt-ai-features/assets/js/bolt-chatHistory.js?ver=bolt-ai-features/assets/js/bolt-chatSettings.js?ver=bolt-ai-features/assets/js/bolt-data-user.js?ver=bolt-ai-features/assets/js/bolt-embeddings.js?ver=bolt-ai-features/assets/js/bolt-login-protection.js?ver=bolt-ai-features/assets/js/bolt-models.js?ver=bolt-ai-features/assets/js/bolt-overview.js?ver=bolt-ai-features/assets/js/bolt-statistics.js?ver=

HTML / DOM Fingerprints

CSS Classes
boltai-chat-containerboltai-chat-windowboltai-chat-headerboltai-chat-messagesboltai-messageboltai-user-messageboltai-ai-messageboltai-input-area+17 more
HTML Comments
<!-- BOLT AI Features Plugin --><!-- Admin settings for BOLT AI --><!-- User data management for BOLT AI --><!-- Embeddings management for BOLT AI -->+1 more
Data Attributes
data-boltai-actiondata-boltai-noncedata-boltai-chat-id
JS Globals
window.boltai_ajax_objectwindow.boltai_chat_settings
REST Endpoints
/wp-json/boltai/v1/processContentForEmbedding/wp-json/boltai/v1/getUserChatHistory/wp-json/boltai/v1/getAllUsersAggregatedChatHistory/wp-json/boltai/v1/getApiAuthenticationToken/wp-json/boltai/v1/submitQuestionToAI/wp-json/boltai/v1/submitUserFeedback/wp-json/boltai/v1/deleteQuestionAndFeedback/wp-json/boltai/v1/deleteUserData/wp-json/boltai/v1/getAIModelName/wp-json/boltai/v1/getUsageStatistics/wp-json/boltai/v1/retrieveSiteConfiguration
FAQ

Frequently Asked Questions about BOLT AI Features