
AI Chatbot for WordPress by Customerly Security & Risk Analysis
wordpress.org/plugins/customerlyAI Chatbot to support customers, create engaging messages and send automated emails.
Is AI Chatbot for WordPress by Customerly Safe to Use in 2026?
Generally Safe
Score 85/100AI Chatbot for WordPress by Customerly has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The customerly plugin v2.5.4 exhibits a mixed security posture. On the positive side, the absence of known CVEs and the use of prepared statements for all SQL queries are strong indicators of good security practices. The plugin also avoids dangerous functions, file operations, and external HTTP requests, further minimizing common attack vectors. However, a significant concern is the presence of one unprotected AJAX handler, which represents a direct entry point for potential attackers. While taint analysis found no issues, and output escaping is present for most outputs, the lack of proper authorization checks on this AJAX endpoint is a critical oversight. This single unprotected entry point, combined with zero nonce checks and zero capability checks, exposes the plugin to potential unauthorized actions if the AJAX handler performs sensitive operations. The vulnerability history is clean, which is excellent, but this doesn't negate the immediate risks identified in the static analysis. Overall, the plugin has a solid foundation in many security areas, but the unprotected AJAX handler is a glaring weakness that needs immediate attention to mitigate risks.
Key Concerns
- Unprotected AJAX handler
- No nonce checks on AJAX handlers
- No capability checks on entry points
- Partial output escaping (65%)
AI Chatbot for WordPress by Customerly Security Vulnerabilities
AI Chatbot for WordPress by Customerly Code Analysis
Output Escaping
Data Flow Analysis
AI Chatbot for WordPress by Customerly Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
AI Chatbot for WordPress by Customerly Maintenance & Trust
Maintenance Signals
Community Trust
AI Chatbot for WordPress by Customerly Alternatives
Social Intents – Live Chat
live-chat-support-by-social-intents
AI Chatbot & Live Chat plugin for WordPress. Chat with visitors using ChatGPT, Claude, Gemini, Slack, Teams, and Google Chat.
Limb AI Chatbot
limb-chatbot
AI chatbot with ChatGPT, Gemini 2.5, RAG technology, WooCommerce integration, live agent, and unlimited knowledge training.
Bubblibot – GPT-5 Chatbot for WordPress
bubblibot
AI-powered chatbot with GPT-5 support that learns from your content to provide instant, accurate answers to visitor questions.
Vitxi Converse – Intelligent AI chatbot for Social Media
vitxi-converse
Intelligent AI chatbot that manages your social media customer service, providing instant, 24/7 support to your followers.
Chat Button & Custom ChatGPT-Powered Bot by GetButton.io
whatshelp-chat-button
Floating button for chatting with your visitors via WhatsApp, Messenger, Contact form, and more.
AI Chatbot for WordPress by Customerly Developer Profile
1 plugin · 400 total installs
How We Detect AI Chatbot for WordPress by Customerly
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/customerly/assets/css/admin-notices-style.css/wp-content/plugins/customerly/assets/js/admin-notices-script.jsHTML / DOM Fingerprints
cly-cf7-api-dismiss-notice-foreverdata-customerly-widget-idCustomerlyChat