
ChatReact – AI Chatbot, Smart Forms & FAQs Security & Risk Analysis
wordpress.org/plugins/chatreactAdd an AI-powered chatbot, anti-spam contact forms, and FAQ accordions to your WordPress site. No coding required.
Is ChatReact – AI Chatbot, Smart Forms & FAQs Safe to Use in 2026?
Generally Safe
Score 100/100ChatReact – AI Chatbot, Smart Forms & FAQs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "chatreact" plugin v1.1.3 exhibits a generally strong security posture based on the provided static analysis. A significant strength is the complete absence of unprotected entry points, with all AJAX handlers and REST API routes appearing to have proper authentication and permission checks. The plugin also demonstrates good practices in its use of prepared statements for all SQL queries and a high percentage of properly escaped output. The low number of external HTTP requests and the presence of nonce checks further contribute to its secure design.
Despite these positive indicators, the taint analysis revealed two flows with unsanitized paths. While these did not escalate to critical or high severity in the static analysis, unsanitized paths represent a potential risk for input validation issues that could be exploited in certain scenarios, especially if combined with other less secure practices. The plugin's vulnerability history shows no recorded CVEs, which is a very positive sign indicating a lack of publicly known exploitable flaws. However, this can also be a reflection of limited testing or discovery rather than guaranteed absolute security.
In conclusion, "chatreact" v1.1.3 appears to be a securely coded plugin with robust access control and data handling mechanisms. The primary area of concern lies with the identified unsanitized paths, which, while not immediately critical, warrant attention and further investigation to ensure no exploitable vulnerabilities exist. The absence of past vulnerabilities is a strong indicator of developer diligence, but the presence of unsanitized paths necessitates vigilance.
Key Concerns
- Flows with unsanitized paths detected
ChatReact – AI Chatbot, Smart Forms & FAQs Security Vulnerabilities
ChatReact – AI Chatbot, Smart Forms & FAQs Release Timeline
ChatReact – AI Chatbot, Smart Forms & FAQs Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ChatReact – AI Chatbot, Smart Forms & FAQs Attack Surface
AJAX Handlers 10
REST API Routes 2
Shortcodes 3
WordPress Hooks 25
Maintenance & Trust
ChatReact – AI Chatbot, Smart Forms & FAQs Maintenance & Trust
Maintenance Signals
Community Trust
ChatReact – AI Chatbot, Smart Forms & FAQs Alternatives
Lime Connect (formerly Userlike) – WordPress Live Chat plugin
userlike
Free live chat plugin to chat with the visitors of your website. Integrate a beautiful and fully customizable chat box. Hosted in Europe.
Live Chat & AI Chatbot – onWebChat
onwebchat
Add live chat and a 24/7 AI chatbot to your site. Engage visitors instantly, automate support, and convert more visitors into customers.
Social Intents – Live Chat
live-chat-support-by-social-intents
AI Chatbot & Live Chat plugin for WordPress. Chat with visitors using ChatGPT, Claude, Gemini, Slack, Teams, and Google Chat.
AI Chatbot for WordPress by Customerly
customerly
AI Chatbot to support customers, create engaging messages and send automated emails.
ILACHAT – AI Chatbot & Live Chat
ilachat
AI-powered chatbot and live chat for WordPress & WooCommerce. Boost support, sales, and lead capture with real-time data.
ChatReact – AI Chatbot, Smart Forms & FAQs Developer Profile
5 plugins · 630 total installs
How We Detect ChatReact – AI Chatbot, Smart Forms & FAQs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/chatreact/assets/css/admin.css/wp-content/plugins/chatreact/assets/js/admin.js/wp-content/plugins/chatreact/assets/js/admin.jschatreact/assets/css/admin.css?ver=chatreact/assets/js/admin.js?ver=HTML / DOM Fingerprints
chatreact-widget-containerchatreact-input-boxchatreact-send-buttonchatreact-message-bubblechatreact-quick-replydata-chatreact-widget-iddata-chatreact-settingschatreactAdmin/wp-json/chatreact/v1/assignments/wp-json/chatreact/v1/post_types/wp-json/chatreact/v1/integration-key/wp-json/chatreact/v1/sitemap-settings/wp-json/chatreact/v1/faq-cache/wp-json/chatreact/v1/faq-cache-settings[chatreact_chatbot[chatreact_form[chatreact_faq