
Cliengo – Chatbot Security & Risk Analysis
wordpress.org/plugins/cliengoCliengo helps you scale your business by automating customer contact points and providing 24/7 responses.
Is Cliengo – Chatbot Safe to Use in 2026?
Generally Safe
Score 95/100Cliengo – Chatbot has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The Cliengo plugin v3.0.4 presents a mixed security posture. On the positive side, it demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively, and shows a relatively high percentage of properly escaped output, along with a reasonable number of nonce and capability checks. This suggests some level of attention to common web security pitfalls.
However, significant concerns arise from the substantial attack surface exposed through AJAX handlers. All eight identified AJAX handlers lack authentication checks, making them prime targets for unauthorized actions. Furthermore, the taint analysis reveals flows with unsanitized paths, although none are categorized as critical or high severity in this specific analysis. The plugin's vulnerability history is a major red flag, with four known CVEs, two of which remain unpatched. The prevalence of medium-severity vulnerabilities, particularly Cross-Site Request Forgery (CSRF) and Missing Authorization, reinforces the concerns identified in the static analysis regarding unprotected entry points.
In conclusion, while the plugin exhibits some strengths in secure coding practices like prepared statements, the significant number of unprotected AJAX endpoints and the history of unpatched medium-severity vulnerabilities, especially those related to authorization and CSRF, indicate a substantial risk. Users should exercise caution and prioritize updating the plugin to address the known vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- Unpatched CVEs
- Flows with unsanitized paths
- Missing authorization checks
- Cross-Site Request Forgery (CSRF) history
Cliengo – Chatbot Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Cliengo – Chatbot <= 3.0.4 - Missing Authorization
Cliengo – Chatbot <= 3.0.4 - Cross-Site Request Forgery
Cliengo - Chatbot <= 3.0.2 - Missing Authorization to Unauthenticated Chatbot Settings Update
Cliengo - Chatbot <= 3.0.2 - Missing Authorization to Authorized (Subscriber+) Chatbot Settings Update
Cliengo – Chatbot Release Timeline
Cliengo – Chatbot Code Analysis
Output Escaping
Data Flow Analysis
Cliengo – Chatbot Attack Surface
AJAX Handlers 8
WordPress Hooks 6
Maintenance & Trust
Cliengo – Chatbot Maintenance & Trust
Maintenance Signals
Community Trust
Cliengo – Chatbot Alternatives
SiteBirds | AI Chat, Lead Capture, Bookings & Accessibility
a11y-enhancer
Turn your existing WordPress site into a lead and booking machine with AI chat, lead capture, bookings, built-in accessibility improvements, smart sca …
AnyTimeReply – Sales chatbot
anytimereply
AnyTimeReply is the automated sales chatbot available to customers round the clock. It collect leads in interactive way and manage customer queries.
Chat-In Inc
chat-in
Chat-In es una solucion integral al momento de obtener contactos de tu página.
CometLeads Contact
cometleads-contact
Replace your static contact form with a conversational chatbot and you’ll see more leads coming your way.
Furie™ AI Chat / Live Handoff, Auto Engagement, and Lead Generation
furie-ai-chat-widget
Add a powerful AI chat widget to your site. Engage visitors, automate replies, capture leads, and boost conversions — FREE FOREVER.
Cliengo – Chatbot Developer Profile
1 plugin · 2K total installs
How We Detect Cliengo – Chatbot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cliengo/public/css/cliengo-public.css/wp-content/plugins/cliengo/public/js/cliengo-public.js/wp-content/plugins/cliengo/admin/extras/cliengo-bootstrap/cliengo-bootstrap.css/wp-content/plugins/cliengo/admin/css/cliengo-admin.css/wp-content/plugins/cliengo/admin/js/vue.min.js/wp-content/plugins/cliengo/admin/js/vue-resource.min.js/wp-content/plugins/cliengo/admin/js/cliengo-admin.js/wp-content/plugins/cliengo/public/js/cliengo-public.js/wp-content/plugins/cliengo/admin/js/vue.min.js/wp-content/plugins/cliengo/admin/js/vue-resource.min.js/wp-content/plugins/cliengo/admin/js/cliengo-admin.jscliengo/css/cliengo-public.css?ver=cliengo/js/cliengo-public.js?ver=cliengo/extras/cliengo-bootstrap/cliengo-bootstrap.css?ver=cliengo/css/cliengo-admin.css?ver=cliengo/js/vue.min.js?ver=cliengo/js/vue-resource.min.js?ver=cliengo/js/cliengo-admin.js?ver=HTML / DOM Fingerprints
cliengo-chatbot<!-- DO NOT MODIFY THIS FILE. --><!-- This file is auto-generated by the cliengo plugin -->data-cliengo-chatwindow.cliengo_options