
ConvertyBot – AI Sales Assistant for WooCommerce Security & Risk Analysis
wordpress.org/plugins/convertybotTransform your WooCommerce store into a 24/7 sales machine! AI-powered chatbot that recommends products, generates coupons, and converts visitors into …
Is ConvertyBot – AI Sales Assistant for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100ConvertyBot – AI Sales Assistant for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Convertybot plugin v1.0.32 presents a mixed security posture. On the positive side, it shows good practices regarding SQL queries, with a high percentage utilizing prepared statements, and a strong emphasis on output escaping, with over 90% of outputs properly handled. The absence of known CVEs and a clean vulnerability history are also significant strengths, suggesting a history of responsible development and patching. Furthermore, the plugin avoids dangerous functions and file operations, which are common attack vectors. However, the plugin has a notable concern regarding its attack surface. It exposes 71 AJAX handlers, and a significant portion (4) lack any authentication checks. This is a critical oversight that could allow unauthenticated users to trigger plugin functionality. Additionally, the taint analysis reveals 11 high-severity flows with unsanitized paths. While these are not explicitly marked as vulnerabilities in the history, unsanitized paths can often lead to exploitable conditions if not properly handled. The combination of unprotected AJAX endpoints and high-severity unsanitized flows indicates a potential for privilege escalation or denial-of-service vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
ConvertyBot – AI Sales Assistant for WooCommerce Security Vulnerabilities
ConvertyBot – AI Sales Assistant for WooCommerce Release Timeline
ConvertyBot – AI Sales Assistant for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ConvertyBot – AI Sales Assistant for WooCommerce Attack Surface
AJAX Handlers 71
WordPress Hooks 48
Scheduled Events 4
Maintenance & Trust
ConvertyBot – AI Sales Assistant for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ConvertyBot – AI Sales Assistant for WooCommerce Alternatives
Sales Analytics for WooCommerce
sales-analytics-for-woocommerce
Sales Analytics for WooCommerce: detailed reports, payment analytics, AI-based insights, CSV/PDF export, multi-currency, and chart visuals.
AICA – Smart AI Commerce Assistant
aica-smart-ai-commerce-assistant
Transform your WooCommerce store with an intelligent AI shopping assistant that helps customers find products, answers questions, and boosts sales.
BenriBot for WooCommerce
benribot-for-woocommerce
Integrates the BenriBot AI chat widget into your WooCommerce store with a modern React-based admin interface.
chatpod ai
chatpod-ai
AI-powered sales and support agent for WooCommerce stores. Drives sales, handles support, and captures leads 24/7.
CMSPS Revenue Pulse Advisor
cmsps-revenue-pulse-advisor
Generate AI-powered WooCommerce revenue analysis in wp-admin and review saved reports, trends, and recommendations.
ConvertyBot – AI Sales Assistant for WooCommerce Developer Profile
3 plugins · 0 total installs
How We Detect ConvertyBot – AI Sales Assistant for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/convertybot/assets/css/chatbot.css/wp-content/plugins/convertybot/assets/css/vendor/bootstrap.min.css/wp-content/plugins/convertybot/assets/js/chatbot.js/wp-content/plugins/convertybot/assets/js/vendor/bootstrap.bundle.min.js/wp-content/plugins/convertybot/assets/js/chatbot.js/wp-content/plugins/convertybot/assets/js/vendor/bootstrap.bundle.min.jsconvertybot/assets/css/chatbot.css?ver=convertybot/assets/css/vendor/bootstrap.min.css?ver=convertybot/assets/js/chatbot.js?ver=convertybot/assets/js/vendor/bootstrap.bundle.min.js?ver=HTML / DOM Fingerprints
convertybot-chat-containerconvertybot-headerconvertybot-messageconvertybot-input-areaconvertybot-quick-reply<!-- ConvertyBot Chatbot Start --><!-- ConvertyBot Chatbot End -->data-convertybot-api-urldata-convertybot-widget-iddata-convertybot-product-idwindow.convertybotAppwindow.convertybotSettingsvar convertybot_settings =/wp-json/convertybot/v1/get_widget_settings/wp-json/convertybot/v1/send_message/wp-json/convertybot/v1/get_product_suggestions[convertybot_chat][convertybot_widget]