
Kognetiks Chatbot for WordPress Security & Risk Analysis
wordpress.org/plugins/chatbot-chatgptQuiet proof that your website is working. Turn real visitor conversations into clear insight, automatically. No dashboards. No guesswork.
Is Kognetiks Chatbot for WordPress Safe to Use in 2026?
Mostly Safe
Score 83/100Kognetiks Chatbot for WordPress is generally safe to use. 9 past CVEs were resolved. Keep it updated.
The "chatbot-chatgpt" v2.4.6 plugin exhibits a mixed security posture. While it demonstrates good practices with a high percentage of prepared SQL statements and properly escaped output, significant concerns arise from its attack surface and historical vulnerability patterns. The presence of 10 AJAX handlers without authentication checks represents a substantial risk, as it creates direct entry points for unauthenticated attackers to potentially exploit. Furthermore, the taint analysis revealing 7 high severity flows indicates potential for sensitive data manipulation or execution of unintended actions when user input is not properly sanitized. The plugin's history of 9 known CVEs, including 2 critical ones, and the recurrence of common vulnerability types like Improper Authorization and Cross-Site Scripting suggest a pattern of exploitable weaknesses that require ongoing vigilance. Despite the current lack of unpatched vulnerabilities and the presence of numerous capability and nonce checks, the inherent risks from unprotected entry points and past security failures warrant careful consideration.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Total known CVEs
- Critical severity CVEs
- Bundled Freemius v1.0 library
- Dangerous function: unserialize
Kognetiks Chatbot for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
9 total CVEs
Kognetiks Chatbot <= 2.3.5 - Missing Authorization to Unauthenticated Limited File Uploads and Conversation Erasing
Kognetiks Chatbot for WordPress <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Assistant Addition
Kognetiks Chatbot for WordPress <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Assistant Update
Kognetiks Chatbot for WordPress <= 2.1.7 - Reflected Cross-Site Scripting
Kognetiks Chatbot for WordPress <= 2.1.8 - Cross-Site Request Forgery to Authenticated (Subscriber+) Assistant Modification
Kognetiks Chatbot for WordPress <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Assistant Deletion
Kognetiks Chatbot for WordPress <= 1.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Kognetiks Chatbot for WordPress <= 2.0.0 - Unauthenticated Arbitrary File Upload
Kognetiks Chatbot for WordPress <= 1.9.9 - Unauthenticated Arbitrary File Upload via chatbot_chatgpt_upload_file_to_assistant Function
Kognetiks Chatbot for WordPress Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Kognetiks Chatbot for WordPress Attack Surface
AJAX Handlers 32
REST API Routes 1
Shortcodes 4
WordPress Hooks 116
Scheduled Events 38
Maintenance & Trust
Kognetiks Chatbot for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Kognetiks Chatbot for WordPress Alternatives
LocoAI – Auto Translate For Loco Translate
automatic-translator-addon-for-loco-translate
LocoAI - Auto Translate For Loco Translate is a powerful tool for developers looking to quickly translate their WordPress plugins and themes.
BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor
betterdocs
A full-featured documentation plugin including AI writing assistance to create knowledge bases, docs, FAQs, wikis, and more with easy drag & drop UI.
WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
chatbot
AI ChatBot for WordPress WPBot - Automated 24/7 Live Chat Customer Support. NATIVE, Lead Generation, Forms, Gemini, DialogFlow, ChatGPT, OpenRouter
AI Chatbot – Jotform
jotform-ai-chatbot
AI chatbot that automates support, answers FAQs, drives WooCommerce sales, generates leads, and boosts engagement — easy setup, no coding!
AI WP Writer – SEO content generator, chatGPT, Gemini
ai-wp-writer
Create high-quality SEO articles and AI images. Auto-fill website. Generate, rewrite and translate with AI. Powered by Gemini, GPT-5, NanoBanana, FLUX
Kognetiks Chatbot for WordPress Developer Profile
3 plugins · 910 total installs
How We Detect Kognetiks Chatbot for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/chatbot-chatgpt/css/frontend.css/wp-content/plugins/chatbot-chatgpt/js/frontend.js/wp-content/plugins/chatbot-chatgpt/js/frontend.jschatbot-chatgpt/css/frontend.css?ver=chatbot-chatgpt/js/frontend.js?ver=HTML / DOM Fingerprints
kognetiks-chatbot-containerkognetiks-chat-messagekognetiks-chat-bubblekognetiks-user-messagekognetiks-assistant-messagekognetiks-input-areakognetiks-send-buttonDO NOT REMOVE THIS IF, IT IS ESSENTIAL FOR THEfunction_exists CALL ABOVE TO PROPERLY WORK.Start output buffering earlier to prevent "headers already sent" issues - Ver 2.1.8Assign a unique ID to the visitor and logged-in users - Ver 2.0.4+27 morekognetiks_unique_idchatbot_chatgpt_plugin_versionchatbot_chatgpt_plugin_dir_pathchatbot_chatgpt_plugin_dir_urlsession_iduser_id