Brambles.ai: Affiliate AI Shopping Chatbot Security & Risk Analysis

wordpress.org/plugins/brambles-ai

Affiliate AI shopping chatbot that monetizes your content with conversational commerce. Earn revenue through AI-powered agentic shopping.

0 active installs v0.2.2 PHP 7.4+ WP 5.0+ Updated Feb 9, 2026
affiliateaichatbotecommercemonetize
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Brambles.ai: Affiliate AI Shopping Chatbot Safe to Use in 2026?

Generally Safe

Score 100/100

Brambles.ai: Affiliate AI Shopping Chatbot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The brambles-ai v0.2.2 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. It demonstrates good practices by utilizing prepared statements for all SQL queries and appears to implement nonce and capability checks on its identified entry points. The absence of dangerous functions, file operations, and critical or high-severity taint flows further contributes to a positive security outlook. The vulnerability history being entirely clear with no recorded CVEs is a significant strength, suggesting a well-maintained and secure codebase.

However, a minor concern arises from the output escaping. While 72% of outputs are properly escaped, this still leaves a portion potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not handled carefully in the unescaped outputs. The presence of two external HTTP requests, while not inherently a vulnerability, warrants attention to ensure these requests are made securely and to trusted endpoints, especially if any user-supplied data is included in these requests. The limited attack surface is a positive factor, but the efficiency of the security controls on these entry points needs to be confirmed through further in-depth analysis.

In conclusion, brambles-ai v0.2.2 appears to be a secure plugin with minimal evident risks. The primary area for potential improvement lies in ensuring 100% output escaping to mitigate any lingering XSS risks. The lack of historical vulnerabilities is a strong indicator of the plugin's current security, but ongoing vigilance and thorough code reviews remain essential for any software.

Key Concerns

  • Unescaped output identified
  • External HTTP requests present
Vulnerabilities
None known

Brambles.ai: Affiliate AI Shopping Chatbot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Brambles.ai: Affiliate AI Shopping Chatbot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
21 escaped
Nonce Checks
4
Capability Checks
4
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

72% escaped29 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
ajax_toggle_widget (brambles-ai.php:54)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Brambles.ai: Affiliate AI Shopping Chatbot Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_brambles_ai_toggle_widgetbrambles-ai.php:51

Shortcodes 1

[brambles_ai] brambles-ai.php:41
WordPress Hooks 12
actioninitbrambles-ai.php:33
actionwp_enqueue_scriptsbrambles-ai.php:34
actionadmin_menubrambles-ai.php:35
actionadmin_initbrambles-ai.php:36
actionadmin_initbrambles-ai.php:37
actionadmin_noticesbrambles-ai.php:38
actionadmin_enqueue_scriptsbrambles-ai.php:39
actionadmin_enqueue_scriptsbrambles-ai.php:40
actionadmin_post_brambles_ai_retry_onboardbrambles-ai.php:46
actionadmin_post_brambles_ai_connect_stripebrambles-ai.php:47
actionadmin_post_brambles_ai_stripe_returnbrambles-ai.php:48
filterscript_loader_tagbrambles-ai.php:823
Maintenance & Trust

Brambles.ai: Affiliate AI Shopping Chatbot Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 9, 2026
PHP min version7.4
Downloads243

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Brambles.ai: Affiliate AI Shopping Chatbot Developer Profile

Brambles.ai

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Brambles.ai: Affiliate AI Shopping Chatbot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/brambles-ai/assets/widget-style.css/wp-content/plugins/brambles-ai/assets/widget-script.js/wp-content/plugins/brambles-ai/assets/admin-style.css
Script Paths
/wp-content/plugins/brambles-ai/assets/widget-script.js
Version Parameters
brambles-ai/assets/widget-style.css?ver=brambles-ai/assets/widget-script.js?ver=brambles-ai/assets/admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
brambles-ai-widget-containerbrambles-setup-cardbrambles-herobrambles-progress-barbrambles-progress-fillbrambles-stepbrambles-step-numberbrambles-step-content+6 more
HTML Comments
<!-- Brambles.ai Widget --><!-- Brambles.ai Settings Page --><!-- Brambles AI Admin Menu Icon --><!-- Brambles AI Admin Settings Page -->+6 more
Data Attributes
data-brambles-ai-iddata-brambles-ai-config
JS Globals
BramblesAIWidget
REST Endpoints
/wp-json/brambles-ai/v1/widget/wp-json/brambles-ai/v1/settings
Shortcode Output
[brambles_ai]
FAQ

Frequently Asked Questions about Brambles.ai: Affiliate AI Shopping Chatbot