Cliengo – Chatbot Security & Risk Analysis

wordpress.org/plugins/cliengo

Cliengo helps you scale your business by automating customer contact points and providing 24/7 responses.

2K active installs v3.0.5 PHP 5.2.4+ WP 4.4+ Updated Mar 17, 2026
chatbotcliengoleads
95
A · Safe
CVEs total4
Unpatched0
Last CVEFeb 9, 2026
Safety Verdict

Is Cliengo – Chatbot Safe to Use in 2026?

Generally Safe

Score 95/100

Cliengo – Chatbot has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

4 known CVEsLast CVE: Feb 9, 2026Updated 2mo ago
Risk Assessment

The Cliengo plugin v3.0.4 presents a mixed security posture. On the positive side, it demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively, and shows a relatively high percentage of properly escaped output, along with a reasonable number of nonce and capability checks. This suggests some level of attention to common web security pitfalls.

However, significant concerns arise from the substantial attack surface exposed through AJAX handlers. All eight identified AJAX handlers lack authentication checks, making them prime targets for unauthorized actions. Furthermore, the taint analysis reveals flows with unsanitized paths, although none are categorized as critical or high severity in this specific analysis. The plugin's vulnerability history is a major red flag, with four known CVEs, two of which remain unpatched. The prevalence of medium-severity vulnerabilities, particularly Cross-Site Request Forgery (CSRF) and Missing Authorization, reinforces the concerns identified in the static analysis regarding unprotected entry points.

In conclusion, while the plugin exhibits some strengths in secure coding practices like prepared statements, the significant number of unprotected AJAX endpoints and the history of unpatched medium-severity vulnerabilities, especially those related to authorization and CSRF, indicate a substantial risk. Users should exercise caution and prioritize updating the plugin to address the known vulnerabilities.

Key Concerns

  • Unprotected AJAX handlers
  • Unpatched CVEs
  • Flows with unsanitized paths
  • Missing authorization checks
  • Cross-Site Request Forgery (CSRF) history
Vulnerabilities
4 published

Cliengo – Chatbot Security Vulnerabilities

CVEs by Year

3 CVEs in 2024
2024
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2025-69388medium · 4.3Missing Authorization

Cliengo – Chatbot <= 3.0.4 - Missing Authorization

Feb 9, 2026 Patched in 3.0.5 (66d)
CVE-2024-37923medium · 5.4Cross-Site Request Forgery (CSRF)

Cliengo – Chatbot <= 3.0.4 - Cross-Site Request Forgery

Jul 9, 2024 Patched in 3.0.5 (646d)
CVE-2024-5992medium · 6.5Missing Authorization

Cliengo - Chatbot <= 3.0.2 - Missing Authorization to Unauthenticated Chatbot Settings Update

Jul 8, 2024 Patched in 3.0.3 (24d)
CVE-2024-5993medium · 5.4Missing Authorization

Cliengo - Chatbot <= 3.0.2 - Missing Authorization to Authorized (Subscriber+) Chatbot Settings Update

Jul 8, 2024 Patched in 3.0.3 (25d)
Code Analysis
Analyzed Mar 16, 2026

Cliengo – Chatbot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
30 escaped
Nonce Checks
5
Capability Checks
3
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

86% escaped35 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
update_chatbot_token (admin\class-cliengo-form.php:80)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

Cliengo – Chatbot Attack Surface

Entry Points8
Unprotected8

AJAX Handlers 8

authwp_ajax_update_chatbot_tokenincludes\class-cliengo.php:166
noprivwp_ajax_update_chatbot_tokenincludes\class-cliengo.php:167
authwp_ajax_wordpress_loginincludes\class-cliengo.php:168
authwp_ajax_wp_registrationincludes\class-cliengo.php:169
noprivwp_ajax_wp_registrationincludes\class-cliengo.php:170
authwp_ajax_update_sessionincludes\class-cliengo.php:171
authwp_ajax_update_chatbot_positionincludes\class-cliengo.php:172
authwp_ajax_restore_sessionincludes\class-cliengo.php:173
WordPress Hooks 6
actionplugins_loadedincludes\class-cliengo.php:147
actionadmin_enqueue_scriptsincludes\class-cliengo.php:163
actionadmin_enqueue_scriptsincludes\class-cliengo.php:164
actionadmin_menuincludes\class-cliengo.php:165
actionwp_enqueue_scriptsincludes\class-cliengo.php:187
actionwp_enqueue_scriptsincludes\class-cliengo.php:188
Maintenance & Trust

Cliengo – Chatbot Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 17, 2026
PHP min version5.2.4
Downloads54K

Community Trust

Rating80/100
Number of ratings3
Active installs2K
Developer Profile

Cliengo – Chatbot Developer Profile

cliengo

1 plugin · 2K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
190 days
View full developer profile
Detection Fingerprints

How We Detect Cliengo – Chatbot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cliengo/public/css/cliengo-public.css/wp-content/plugins/cliengo/public/js/cliengo-public.js/wp-content/plugins/cliengo/admin/extras/cliengo-bootstrap/cliengo-bootstrap.css/wp-content/plugins/cliengo/admin/css/cliengo-admin.css/wp-content/plugins/cliengo/admin/js/vue.min.js/wp-content/plugins/cliengo/admin/js/vue-resource.min.js/wp-content/plugins/cliengo/admin/js/cliengo-admin.js
Script Paths
/wp-content/plugins/cliengo/public/js/cliengo-public.js/wp-content/plugins/cliengo/admin/js/vue.min.js/wp-content/plugins/cliengo/admin/js/vue-resource.min.js/wp-content/plugins/cliengo/admin/js/cliengo-admin.js
Version Parameters
cliengo/css/cliengo-public.css?ver=cliengo/js/cliengo-public.js?ver=cliengo/extras/cliengo-bootstrap/cliengo-bootstrap.css?ver=cliengo/css/cliengo-admin.css?ver=cliengo/js/vue.min.js?ver=cliengo/js/vue-resource.min.js?ver=cliengo/js/cliengo-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
cliengo-chatbot
HTML Comments
<!-- DO NOT MODIFY THIS FILE. --><!-- This file is auto-generated by the cliengo plugin -->
Data Attributes
data-cliengo-chat
JS Globals
window.cliengo_options
FAQ

Frequently Asked Questions about Cliengo – Chatbot