CustomGPT.ai Chatbot Security & Risk Analysis

wordpress.org/plugins/customgpt-ai-integration

A simple plugin to add the CustomGPT.ai Live Chat Bubble to a WordPress website with a user-specified Project ID and Project Key.

100 active installs v0.3.1 PHP 7.0+ WP 3.0+ Updated Oct 27, 2025
chatbotcustomgpt-aiintegration
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CustomGPT.ai Chatbot Safe to Use in 2026?

Generally Safe

Score 100/100

CustomGPT.ai Chatbot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The static analysis of the 'customgpt-ai-integration' plugin v0.3.1 reveals an exceptionally clean codebase with no identified attack surface, dangerous functions, or unsanitized taint flows. The plugin demonstrates strong security practices by exclusively using prepared statements for SQL queries and properly escaping all output. The absence of file operations and external HTTP requests further reduces potential vulnerabilities. The plugin's vulnerability history is also spotless, with no known CVEs, indicating a low risk of exploitation based on past issues.

However, the most significant concern arises from the complete lack of nonces and capability checks across all entry points. While the current static analysis found zero entry points, if any are introduced or were missed, they would be entirely unprotected. This absence of fundamental WordPress security mechanisms leaves the plugin highly susceptible to common attacks like Cross-Site Request Forgery (CSRF) and unauthorized privilege escalation should any entry points exist. The plugin's strengths lie in its clean code and data handling, but its weakness is a critical oversight in authentication and authorization for any potential interactions.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

CustomGPT.ai Chatbot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CustomGPT.ai Chatbot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

CustomGPT.ai Chatbot Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menucustomgpt-ai.php:22
actionadmin_initcustomgpt-ai.php:85
actionwp_enqueue_scriptscustomgpt-ai.php:111
actionwp_footercustomgpt-ai.php:135
Maintenance & Trust

CustomGPT.ai Chatbot Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 27, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

CustomGPT.ai Chatbot Developer Profile

markocustomgpt

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CustomGPT.ai Chatbot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://cdn.customgpt.ai/js/chat.js

HTML / DOM Fingerprints

CSS Classes
wrap
JS Globals
CustomGPT
FAQ

Frequently Asked Questions about CustomGPT.ai Chatbot