ChatBot Conversational AI Support Security & Risk Analysis

wordpress.org/plugins/chatbot-com-ai-platform

Chatbot for WP, using a ChatGPT-like AI to self-learn and create replies. Easy training based on the website content. Quick setup, easy installation.

1K active installs v1.1.4 PHP 5.6+ WP 3.4+ Updated Jan 23, 2026
botchat-botchatbotchatbot-pluginlive-chat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ChatBot Conversational AI Support Safe to Use in 2026?

Generally Safe

Score 100/100

ChatBot Conversational AI Support has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin 'chatbot-com-ai-platform' v1.1.4 presents a generally positive security posture based on the provided static analysis. The complete absence of direct attack surface points like AJAX handlers, REST API routes, shortcodes, and cron events, especially those lacking authentication, is a significant strength. Furthermore, the plugin demonstrates good practice by exclusively using prepared statements for its SQL queries. The limited number of external HTTP requests and the presence of nonce and capability checks also contribute to a secure foundation.

However, a key concern arises from the taint analysis, which identified two flows with unsanitized paths. While these did not escalate to critical or high severity in this analysis, the presence of unsanitized paths indicates a potential for injection vulnerabilities if data is not properly validated or sanitized before being processed. The output escaping metric is also a point of concern, with only 19% of outputs being properly escaped. This leaves a significant portion of dynamic content vulnerable to Cross-Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts into the user's browser.

The plugin's vulnerability history is clean, with no recorded CVEs. This, coupled with the good practices in other areas, suggests a potentially well-maintained and secure codebase. However, the identified taint flows and low output escaping rate are weaknesses that require immediate attention. The overall assessment is that the plugin has a good foundation but exhibits critical flaws in output escaping and potential unsanitized data handling that significantly increase its risk profile.

Key Concerns

  • Unsanitized path taint flows detected
  • Low percentage of properly escaped output
Vulnerabilities
None known

ChatBot Conversational AI Support Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ChatBot Conversational AI Support Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

19% escaped27 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
initialize (admin\classes\chatbotcom-admin.php:15)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ChatBot Conversational AI Support Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuadmin\classes\chatbotcom-admin.php:118
actionadmin_enqueue_scriptsadmin\classes\chatbotcom-admin.php:132
actionadmin_initadmin\classes\chatbotcom-admin.php:194
actionwp_footerpublic\classes\chatbotcom-public.php:10
Maintenance & Trust

ChatBot Conversational AI Support Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.0
Last updatedJan 23, 2026
PHP min version5.6
Downloads38K

Community Trust

Rating74/100
Number of ratings10
Active installs1K
Developer Profile

ChatBot Conversational AI Support Developer Profile

WP-LiveChat

10 plugins · 113K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
1833 days
View full developer profile
Detection Fingerprints

How We Detect ChatBot Conversational AI Support

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chatbot-com-ai-platform/admin/assets/style/menu-icon.css/wp-content/plugins/chatbot-com-ai-platform/admin/assets/style/style.css/wp-content/plugins/chatbot-com-ai-platform/admin/assets/scripts/login-sdk.js/wp-content/plugins/chatbot-com-ai-platform/admin/assets/scripts/script.js
Script Paths
/wp-content/plugins/chatbot-com-ai-platform/admin/assets/scripts/login-sdk.js/wp-content/plugins/chatbot-com-ai-platform/admin/assets/scripts/script.js
Version Parameters
chatbot-com-ai-platform/admin/assets/style/menu-icon.css?ver=chatbot-com-ai-platform/admin/assets/style/style.css?ver=chatbot-com-ai-platform/admin/assets/scripts/login-sdk.js?ver=chatbot-com-ai-platform/admin/assets/scripts/script.js?ver=

HTML / DOM Fingerprints

JS Globals
wpSdkConfigwpUtils
FAQ

Frequently Asked Questions about ChatBot Conversational AI Support