CW – AI GPT Chatbot Security & Risk Analysis

wordpress.org/plugins/cw-ai-gpt-chatbot

The AI GPT Chatbot for WordPress interface: a straightforward platform to integrate your AI GPT Chatbot code.

0 active installs v1.0.0 PHP + WP 6.0.1+ Updated Aug 23, 2024
ai-botai-gpt-chatbotchatbotchatgptlive-chat
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CW – AI GPT Chatbot Safe to Use in 2026?

Generally Safe

Score 92/100

CW – AI GPT Chatbot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "cw-ai-gpt-chatbot" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates excellent security practices by having zero AJAX handlers, REST API routes, shortcodes, or cron events that could serve as direct entry points. Notably, all observed SQL queries utilize prepared statements, and all output is properly escaped, significantly reducing the risk of injection vulnerabilities and cross-site scripting (XSS) attacks. The absence of file operations and external HTTP requests further minimizes the attack surface.

Taint analysis shows no unsanitized paths, indicating that user-supplied data is not being processed in a way that could lead to vulnerabilities. The presence of one nonce check is a positive sign, although the absence of capability checks on any potential entry points (which are none in this case) is a point to consider for future development if the plugin evolves. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a diligent approach to security by its developers.

Overall, this plugin appears to be very securely coded with a minimal attack surface and no identified vulnerabilities. Its strengths lie in its lack of exploitable entry points and robust data handling. The primary weakness, if any, would be the lack of explicit capability checks, but this is mitigated by the current absence of user-accessible entry points. The current version is highly secure.

Vulnerabilities
None known

CW – AI GPT Chatbot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CW – AI GPT Chatbot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
13 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped13 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
cwai_save_chat_whisperer_code (chat-whisperer-live-ai-chatbot.php:148)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CW – AI GPT Chatbot Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuchat-whisperer-live-ai-chatbot.php:79
actionadmin_initchat-whisperer-live-ai-chatbot.php:140
actionadmin_post_save_chat_whisperer_codechat-whisperer-live-ai-chatbot.php:160
actionwp_enqueue_scriptschat-whisperer-live-ai-chatbot.php:167
actionwp_footerchat-whisperer-live-ai-chatbot.php:179
actionplugins_loadedincludes\class-chat-whisperer-live-ai-chatbot.php:142
actionadmin_enqueue_scriptsincludes\class-chat-whisperer-live-ai-chatbot.php:157
actionadmin_enqueue_scriptsincludes\class-chat-whisperer-live-ai-chatbot.php:158
actionwp_enqueue_scriptsincludes\class-chat-whisperer-live-ai-chatbot.php:173
actionwp_enqueue_scriptsincludes\class-chat-whisperer-live-ai-chatbot.php:174
Maintenance & Trust

CW – AI GPT Chatbot Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedAug 23, 2024
PHP min version
Downloads584

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

CW – AI GPT Chatbot Developer Profile

chatwhisperer

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CW – AI GPT Chatbot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cw-ai-gpt-chatbot/public/img/Background.svg/wp-content/plugins/cw-ai-gpt-chatbot/public/img/logo.jpg/wp-content/plugins/cw-ai-gpt-chatbot/public/img/demo.png
Script Paths
https://12df09207176de9430943693b151d54a.cdn.bubble.io/f1696333530817x835991923915557500/iframeResizer.min.js

HTML / DOM Fingerprints

CSS Classes
cwai-chat-whisperer-input
Data Attributes
id="chatbot"
JS Globals
iFrameResize
FAQ

Frequently Asked Questions about CW – AI GPT Chatbot