BotMe AI — Add No-Code AI Assistants to Your Website Security & Risk Analysis

wordpress.org/plugins/botme-ai

Add AI-powered chat assistants to your website with no coding required. Create, configure, and deploy custom AI agents to serve your visitors.

0 active installs v1.0.2 PHP + WP 5.0+ Updated Feb 26, 2026
aiassistantautomationchatbotsupport
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BotMe AI — Add No-Code AI Assistants to Your Website Safe to Use in 2026?

Generally Safe

Score 100/100

BotMe AI — Add No-Code AI Assistants to Your Website has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "botme-ai" plugin v1.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping a very high percentage of its output. The security team's focus on capability checks also indicates an awareness of WordPress security principles.

However, there are areas for improvement. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting a well-maintained codebase. The only significant concern stemming from the static analysis is the absence of nonce checks across all its entry points, including the single shortcode. While there are no unescaped outputs or raw SQL queries identified, a shortcode can still be a potential vector for cross-site request forgery (CSRF) if it performs sensitive actions or manipulates data without proper verification.

In conclusion, "botme-ai" v1.0.2 appears to be a secure plugin with a robust foundation. Its adherence to prepared statements and output escaping is excellent. The primary weakness lies in the missing nonce checks, which, while not directly flagged as a vulnerability in this analysis, represents a common area of exposure for shortcodes. Addressing this would further strengthen the plugin's security.

Key Concerns

  • Missing nonce checks on shortcode
Vulnerabilities
None known

BotMe AI — Add No-Code AI Assistants to Your Website Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

BotMe AI — Add No-Code AI Assistants to Your Website Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

BotMe AI — Add No-Code AI Assistants to Your Website Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
115 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

98% escaped117 total outputs
Attack Surface

BotMe AI — Add No-Code AI Assistants to Your Website Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[botme_ai] public/class-botme-ai-public.php:63
WordPress Hooks 10
actionadmin_menuadmin/class-botme-ai-admin.php:62
actionadmin_initadmin/class-botme-ai-admin.php:63
actionadmin_enqueue_scriptsadmin/class-botme-ai-admin.php:66
actionadmin_enqueue_scriptsincludes/class-botme-ai.php:158
actionadmin_enqueue_scriptsincludes/class-botme-ai.php:159
actionwp_enqueue_scriptsincludes/class-botme-ai.php:174
actionwp_enqueue_scriptsincludes/class-botme-ai.php:175
actionwp_enqueue_scriptspublic/class-botme-ai-public.php:62
actionwp_footerpublic/class-botme-ai-public.php:66
actionwp_enqueue_scriptspublic/class-botme-ai-public.php:69
Maintenance & Trust

BotMe AI — Add No-Code AI Assistants to Your Website Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version
Downloads223

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

BotMe AI — Add No-Code AI Assistants to Your Website Developer Profile

perrchick

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BotMe AI — Add No-Code AI Assistants to Your Website

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/botme-ai/assets/css/botme-ai-frontend.css/wp-content/plugins/botme-ai/assets/js/botme-ai-frontend.js
Script Paths
/wp-content/plugins/botme-ai/assets/js/botme-ai-frontend.js/wp-content/plugins/botme-ai/admin/js/botme-ai-admin.js
Version Parameters
botme-ai/assets/css/botme-ai-frontend.css?ver=botme-ai/assets/js/botme-ai-frontend.js?ver=botme-ai/admin/css/botme-ai-admin.css?ver=botme-ai/admin/js/botme-ai-admin.js?ver=

HTML / DOM Fingerprints

JS Globals
BotMeAI
FAQ

Frequently Asked Questions about BotMe AI — Add No-Code AI Assistants to Your Website