
SiteForge Chat Security & Risk Analysis
wordpress.org/plugins/botfoundrySiteForge Chat is a powerful, yet easy-to-use WordPress chatbot creation tool that helps you create a custom smart AI chatbot for your your website.
Is SiteForge Chat Safe to Use in 2026?
Generally Safe
Score 92/100SiteForge Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "botfoundry" plugin v0.0.8 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, 100% use of prepared statements for SQL queries, and complete output escaping are significant strengths. The plugin also shows no recorded vulnerability history, suggesting a consistent track record of security. However, there are notable areas for improvement that introduce risk.
The primary concern lies within the REST API, where 5 out of 20 routes lack permission callbacks. This creates an unprotected attack surface that could potentially be exploited by unauthenticated users, depending on the functionality exposed by these routes. Furthermore, the complete absence of nonce checks across all entry points, including the unprotected REST API routes, is a significant oversight. While the REST API routes are the most obvious entry points for concern due to missing permission checks, any plugin functionality that accepts user input should ideally incorporate nonce verification to mitigate CSRF attacks.
Despite the positive aspects like secure SQL handling and output escaping, the unprotected REST API routes and the lack of nonce checks present tangible security weaknesses. The plugin's vulnerability history is clean, but this does not negate the risks identified in the current codebase. A balanced assessment indicates a plugin with some good security foundations but requiring immediate attention to its exposed REST API endpoints and the implementation of nonce checks to achieve a more robust security profile.
Key Concerns
- REST API routes without permission callbacks
- Missing nonce checks
SiteForge Chat Security Vulnerabilities
SiteForge Chat Release Timeline
SiteForge Chat Code Analysis
SQL Query Safety
Output Escaping
SiteForge Chat Attack Surface
REST API Routes 20
WordPress Hooks 7
Maintenance & Trust
SiteForge Chat Maintenance & Trust
Maintenance Signals
Community Trust
SiteForge Chat Alternatives
Quorlyx
quorlyx
AI-powered chatbot & content engine. Automate sales, support, and SEO with Gemini, OpenAI, Anthropic, DeepSeek & Grok.
Typebot
typebot
Collect 4x more responses with conversational apps using Typebot.
AI Chatbot & Workflow Automation by AIWU
ai-copilot-content-generator
AI automations you’ll actually use: Workflow Builder, AI Chatbot, AI Forms, Content Generation, Autoblogging, WooCommerce AI and MCP.
AxiaChat AI – Free AI Chatbot (Answers Customers Automatically)
axiachat-ai
The best AI Chatbot for WordPress. Like having ChatGPT trained on your content — turn your site into a 24/7 sales & support machine.
MxChat – AI Chatbot & Content Generation for WordPress
mxchat-basic
The best free AI chatbot and content generation plugin for WordPress. Train ChatGPT, Claude, Gemini, or Grok on your website content.
SiteForge Chat Developer Profile
2 plugins · 100 total installs
How We Detect SiteForge Chat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/botfoundry/build/index.css/wp-content/plugins/botfoundry/build/index.js/wp-content/plugins/botfoundry/visitors-build/visitors.css/wp-content/plugins/botfoundry/visitors-build/visitors.jsbuild/index.jsvisitors-build/visitors.jsBotFoundry-scriptBotFoundry-styleHTML / DOM Fingerprints
botfoundry-settingsbotfoundry-visitorsmy_script_data/wp-json/botfoundry/v1/init/wp-json/botfoundry/v1/get-settings/wp-json/botfoundry/v1/add-page-data/wp-json/botfoundry/v1/remove-page-data/wp-json/botfoundry/v1/set-ai/wp-json/botfoundry/v1/set-chatbot-settings/wp-json/botfoundry/v1/set-ai-enabled/wp-json/botfoundry/v1/set-chatbot-colors/wp-json/botfoundry/v1/set-no-powered-by/wp-json/botfoundry/v1/set-visible-on-setting/wp-json/botfoundry/v1/get-visible-on-setting/wp-json/botfoundry/v1/set-visible-on-pages