Bot On Site Security & Risk Analysis

wordpress.org/plugins/bot-on-site

Official BOS plugin: one-click connect to embed your AI assistant; optional manual key; status endpoint and cache-purge helpers.

0 active installs v1.0.0 PHP 7.2+ WP 5.2+ Updated Oct 15, 2025
aiautomationchatbotcustomer-supportlive-chat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bot On Site Safe to Use in 2026?

Generally Safe

Score 100/100

Bot On Site has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The 'bot-on-site' v1.0.0 plugin exhibits a generally strong security posture, with several positive indicators. Notably, the absence of dangerous functions, file operations, external HTTP requests, and the complete utilization of prepared statements for SQL queries are commendable practices. All output is properly escaped, and the plugin benefits from a clean vulnerability history with no recorded CVEs, suggesting a commitment to secure development or a lack of past exploitable issues.

However, a significant concern arises from the presence of one AJAX handler that lacks authentication checks. This represents a direct, unprotected entry point into the plugin, which could potentially be leveraged by unauthenticated users. While taint analysis shows no immediate critical or high-severity issues, this unprotected AJAX endpoint warrants careful consideration as it bypasses standard WordPress security mechanisms like nonces and capability checks.

In conclusion, 'bot-on-site' v1.0.0 demonstrates good coding hygiene in most areas. The lack of known vulnerabilities and secure handling of sensitive operations like SQL are strengths. Nevertheless, the single unprotected AJAX endpoint is a clear weakness that introduces an unnecessary risk of unauthorized access or execution of plugin functions.

Key Concerns

  • Unprotected AJAX handler
Vulnerabilities
None known

Bot On Site Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Bot On Site Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Bot On Site Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
54 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped54 total outputs
Attack Surface
1 unprotected

Bot On Site Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_bos_official_purgebot-on-site.php:188
WordPress Hooks 10
actionadmin_initbot-on-site.php:42
actionwp_footerbot-on-site.php:61
actionadmin_initbot-on-site.php:91
actionadmin_noticesbot-on-site.php:114
actionadmin_noticesbot-on-site.php:127
actionadmin_noticesbot-on-site.php:143
actionadmin_initbot-on-site.php:150
actionadmin_menubot-on-site.php:161
actionadmin_enqueue_scriptsbot-on-site.php:177
actionrest_api_initbot-on-site.php:195
Maintenance & Trust

Bot On Site Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 15, 2025
PHP min version7.2
Downloads191

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Bot On Site Developer Profile

botonsite

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bot On Site

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bot-on-site/assets/admin.css/wp-content/plugins/bot-on-site/assets/admin.js
Script Paths
https://cdn.botonsite.com/v1/bos.js
Version Parameters
bot-on-site/assets/admin.css?ver=bot-on-site/assets/admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-key
JS Globals
BOS_OFFICIAL
REST Endpoints
/wp-json/bos-official/v1
FAQ

Frequently Asked Questions about Bot On Site