Chatolia Security & Risk Analysis

wordpress.org/plugins/chatolia

Embed and manage your Chatolia AI chatbots on WordPress.

30 active installs v1.1.3 PHP 7.4+ WP 5.8+ Updated Dec 7, 2025
aiassistantchatchatbotllm
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Chatolia Safe to Use in 2026?

Generally Safe

Score 100/100

Chatolia has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "chatolia" plugin v1.1.3 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, and file operations is commendable. Furthermore, a high percentage of output escaping and the presence of nonce and capability checks suggest good development practices for input validation and access control. The limited attack surface, consisting of only one shortcode and no unprotected entry points, further reinforces this positive assessment.

However, a critical area of concern arises from the taint analysis, which identified one flow with an unsanitized path. While the severity is not explicitly stated as high or critical in the taint analysis section, the presence of an unsanitized path itself is a significant risk that could lead to vulnerabilities like path traversal if not handled properly elsewhere in the code.

The plugin's vulnerability history is clean, with no known CVEs recorded. This indicates a potential track record of security consciousness or simply a lack of past discovered vulnerabilities. While this is a positive sign, it's important not to solely rely on this, especially when a taint analysis flags a potential issue. The plugin benefits from a lack of bundled libraries, avoiding the risks associated with outdated components. Overall, "chatolia" is well-coded with good security practices, but the identified unsanitized path in the taint analysis warrants careful review and remediation.

Key Concerns

  • Flow with unsanitized path found
  • 75% output escaping (25% unescaped)
Vulnerabilities
None known

Chatolia Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Chatolia Release Timeline

v1.1.3Current
v1.1.2
v1.1.1
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Chatolia Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
56 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

75% escaped75 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
maybe_render_admin_notices (admin\class-chatolia-admin.php:703)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Chatolia Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[chatolia] public\class-chatolia-public.php:134
WordPress Hooks 12
actionadmin_menuadmin\class-chatolia-admin.php:84
actionadmin_initadmin\class-chatolia-admin.php:85
actionadmin_post_chatolia_create_agentadmin\class-chatolia-admin.php:86
actionadmin_post_chatolia_widget_previewadmin\class-chatolia-admin.php:87
actionadmin_noticesadmin\class-chatolia-admin.php:88
actionadmin_enqueue_scriptsincludes\class-chatolia.php:137
actionadmin_enqueue_scriptsincludes\class-chatolia.php:138
actionwp_enqueue_scriptsincludes\class-chatolia.php:153
actionwp_enqueue_scriptsincludes\class-chatolia.php:154
actioninitincludes\class-chatolia.php:155
filterscript_loader_tagincludes\class-chatolia.php:157
actionwp_footerincludes\class-chatolia.php:159
Maintenance & Trust

Chatolia Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 7, 2025
PHP min version7.4
Downloads464

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Chatolia Developer Profile

senols

2 plugins · 10K total installs

85
trust score
Avg Security Score
95/100
Avg Patch Time
44 days
View full developer profile
Detection Fingerprints

How We Detect Chatolia

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chatolia/admin/css/chatolia-admin.css/wp-content/plugins/chatolia/admin/js/chatolia-admin.js/wp-content/plugins/chatolia/public/css/chatolia-public.css/wp-content/plugins/chatolia/public/js/chatolia-public.js
Script Paths
/wp-content/plugins/chatolia/admin/js/chatolia-admin.js/wp-content/plugins/chatolia/public/js/chatolia-public.js
Version Parameters
chatolia/admin/css/chatolia-admin.css?ver=chatolia/admin/js/chatolia-admin.js?ver=chatolia/public/css/chatolia-public.css?ver=chatolia/public/js/chatolia-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
chatolia-widget-containerchatolia-icon-widget
Data Attributes
data-chatolia-widget-iddata-chatolia-themedata-chatolia-positiondata-chatolia-agent-id
JS Globals
ChatoliaPublic
REST Endpoints
/wp-json/chatolia/v1/widget
Shortcode Output
[chatoliachatolia_widget_idchatolia_agent_id
FAQ

Frequently Asked Questions about Chatolia