AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant Security & Risk Analysis

wordpress.org/plugins/chatbot-ai-free-models

Add an AI Chatbot to your WordPress site for instant live chat or customer support. Featuring GPT, Claude, Llama and 70+ free models.

100 active installs v1.6.7 PHP 7.4+ WP 5.0+ Updated Dec 3, 2025
ai-chatbotchatbotcustomer-supportlive-chatvirtual-assistant
99
A · Safe
CVEs total1
Unpatched0
Last CVEOct 23, 2025
Safety Verdict

Is AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant Safe to Use in 2026?

Generally Safe

Score 99/100

AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 23, 2025Updated 4mo ago
Risk Assessment

The "chatbot-ai-free-models" plugin v1.6.7 demonstrates a generally good security posture based on the static analysis. It boasts a relatively small attack surface with all entry points protected by authorization checks, and a high percentage of SQL queries using prepared statements and output being properly escaped. The absence of file operations and critical/high severity taint flows further strengthens its security. However, the presence of external HTTP requests, while not inherently vulnerable, represents a potential area for future risk if those external services are compromised or misconfigured. The vulnerability history, despite one medium-severity CVE related to CSV injection, shows that historical issues are being patched, indicating a responsive development team. The lack of currently unpatched vulnerabilities is a positive sign.

While the code analysis reveals strong adherence to secure coding practices in most areas, the external HTTP requests warrant a cautious approach. The single medium-severity CVE, though patched, serves as a reminder that even seemingly secure plugins can harbor vulnerabilities. Overall, the plugin appears well-maintained and secure against common threats, with a low risk profile. The focus on securing entry points and using prepared statements is commendable, and the developer's track record on patching vulnerabilities is positive. The primary area for continued vigilance would be the security of any external dependencies or services it interacts with.

Key Concerns

  • One medium severity CVE in history
  • External HTTP requests present
Vulnerabilities
1

AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-11576medium · 4.3Improper Neutralization of Formula Elements in a CSV File

AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant <= 1.6.5 - Unauthenticated CSV Injection

Oct 23, 2025 Patched in 1.6.6 (2d)
Code Analysis
Analyzed Mar 16, 2026

AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
10 prepared
Unescaped Output
16
164 escaped
Nonce Checks
11
Capability Checks
5
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

59% prepared17 total queries

Output Escaping

91% escaped180 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
<settings-page> (admin\views\settings-page.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 6

authwp_ajax_newcodebyte_chatbot_send_messageincludes\class-chatbot-ajax.php:39
noprivwp_ajax_newcodebyte_chatbot_send_messageincludes\class-chatbot-ajax.php:40
authwp_ajax_newcodebyte_chatbot_delete_messagesincludes\class-chatbot-ajax.php:41
authwp_ajax_newcodebyte_chatbot_export_messagesincludes\class-chatbot-ajax.php:42
authwp_ajax_newcodebyte_chatbot_get_conversation_messagesincludes\class-chatbot-ajax.php:43
authwp_ajax_newcodebyte_chatbot_mark_as_readincludes\class-chatbot-ajax.php:44

Shortcodes 1

[newcodebyte_chatbot] includes\class-chatbot-frontend.php:28
WordPress Hooks 9
actionadmin_noticesadmin\views\settings-page.php:44
actionadmin_menuincludes\class-chatbot-admin.php:20
actionadmin_enqueue_scriptsincludes\class-chatbot-admin.php:21
actionadmin_enqueue_scriptsincludes\class-chatbot-admin.php:22
actionwp_enqueue_scriptsincludes\class-chatbot-frontend.php:22
actionwp_footerincludes\class-chatbot-frontend.php:25
actionadmin_initincludes\class-chatbot-install.php:23
actionplugins_loadedincludes\class-chatbot-main.php:49
actioninitincludes\class-chatbot-main.php:50
Maintenance & Trust

AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings8
Active installs100
Developer Profile

AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant Developer Profile

NewCodeByte

3 plugins · 190 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
2 days
View full developer profile
Detection Fingerprints

How We Detect AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chatbot-ai-free-models/assets/css/chatbot-admin.css/wp-content/plugins/chatbot-ai-free-models/assets/js/chatbot-admin.js/wp-content/plugins/chatbot-ai-free-models/assets/js/chatbot.js/wp-content/plugins/chatbot-ai-free-models/assets/css/chatbot.css/wp-content/plugins/chatbot-ai-free-models/assets/js/marked.min.js/wp-content/plugins/chatbot-ai-free-models/assets/js/purify.min.js
Script Paths
/wp-content/plugins/chatbot-ai-free-models/assets/js/chatbot-admin.js/wp-content/plugins/chatbot-ai-free-models/assets/js/chatbot.js/wp-content/plugins/chatbot-ai-free-models/assets/js/marked.min.js/wp-content/plugins/chatbot-ai-free-models/assets/js/purify.min.js
Version Parameters
chatbot-ai-free-models/assets/css/chatbot-admin.css?ver=chatbot-ai-free-models/assets/js/chatbot-admin.js?ver=chatbot-ai-free-models/assets/js/chatbot.js?ver=chatbot-ai-free-models/assets/css/chatbot.css?ver=chatbot-ai-free-models/assets/js/marked.min.js?ver=chatbot-ai-free-models/assets/js/purify.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
awaiting-modpending-count
Data Attributes
data-conversation-iddata-message-iddata-is-read
JS Globals
chatbot_admin_vars
Shortcode Output
[newcodebyte_chatbot]
FAQ

Frequently Asked Questions about AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant