DataAgent Security & Risk Analysis

wordpress.org/plugins/dataagent

AI-powered plugin to turn your data into actionable insights for smarter, data-driven business decisions.

0 active installs v1.3.0 PHP 7.4+ WP 5.8+ Updated Oct 28, 2025
aianalyticsbusiness-intelligencedata-analysisinsights
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DataAgent Safe to Use in 2026?

Generally Safe

Score 100/100

DataAgent has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The dataagent plugin v1.3.0 exhibits a generally strong security posture, with no known historical vulnerabilities and a robust implementation of security best practices in its static analysis. The absence of any recorded CVEs or common vulnerability types suggests a mature and well-maintained codebase. The plugin also demonstrates good coding practices by using prepared statements for all SQL queries and properly escaping the vast majority of its output. The presence of nonce and capability checks on all AJAX handlers further strengthens its defense against common web attacks.

However, a close examination of the static analysis reveals a couple of areas that warrant attention. Specifically, the presence of two 'flows with unsanitized paths' in the taint analysis, despite no critical or high severity findings, indicates potential for subtle vulnerabilities if user-supplied data is not handled meticulously. While the number of file operations and external HTTP requests is not excessively high, any mishandling of inputs related to these operations could pose a risk. The bundled Freemius and Select2 libraries should also be monitored for potential vulnerabilities in their respective versions, though the analysis doesn't explicitly flag them as outdated or problematic.

In conclusion, dataagent v1.3.0 is a well-secured plugin, largely adhering to security best practices. The primary area of concern lies in the two identified unsanitized paths, which, while not leading to critical findings in this analysis, represent a latent risk that requires careful consideration and potential further investigation. The excellent history of no vulnerabilities is a significant positive, but diligence in code review for the identified taint flow issues is recommended.

Key Concerns

  • Flows with unsanitized paths
  • Bundled Freemius v1.0
  • Bundled Select2
Vulnerabilities
None known

DataAgent Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DataAgent Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
1
64 escaped
Nonce Checks
7
Capability Checks
7
File Operations
2
External Requests
8
Bundled Libraries
2

Bundled Libraries

Freemius1.0Select2

SQL Query Safety

100% prepared2 total queries

Output Escaping

98% escaped65 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
ajax_fetch_ollama_models (src\Controller\Settings.php:257)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

DataAgent Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_dataagent_save_settingssrc\API\Setting.php:111
authwp_ajax_dataagent_fetch_openai_modelssrc\Controller\Settings.php:333
authwp_ajax_dataagent_fetch_ollama_modelssrc\Controller\Settings.php:334
authwp_ajax_dataagent_fetch_openrouter_modelssrc\Controller\Settings.php:335
WordPress Hooks 27
filterdataagent_module_scriptsServices\Asset.php:251
actionrest_api_initsrc\API\Chat.php:156
actionrest_api_initsrc\API\Integration.php:168
actionadmin_menusrc\Controller\Chat.php:163
actionadmin_enqueue_scriptssrc\Controller\Google_Site_kit\Google_Site_Kit.php:160
filterdataagent_integrationssrc\Controller\Google_Site_kit\Google_Site_Kit.php:162
filterrest_api_initsrc\Controller\Google_Site_kit\Google_Site_Kit_API.php:179
filterdataagent_backend_enqueue_metabox_post_localizesrc\Controller\Google_Site_kit\Google_Site_Kit_Insight_Traffic.php:157
filterdataagent_backend_enqueue_wc_metabox_product_localizesrc\Controller\Google_Site_kit\Google_Site_Kit_Insight_Traffic.php:158
filterdataagent_integration_google_site_kit_dashboard_datasrc\Controller\Google_Site_kit\Google_Site_Kit_Insight_Traffic.php:160
actionadd_meta_boxessrc\Controller\Post\Insight.php:133
filterdataagent_chat_localize_datasrc\Controller\Resource_Manager.php:67
actiondataagent_enqueue_assetssrc\Controller\Script_Loader.php:173
filterscript_loader_tagsrc\Controller\Script_Loader.php:176
actionadmin_enqueue_scriptssrc\Controller\Script_Loader.php:179
actionadmin_menusrc\Controller\Settings.php:327
actionadmin_initsrc\Controller\Settings.php:330
filteradmin_enqueue_scriptssrc\Controller\WooCommerce\Coupon.php:99
filterpost_row_actionssrc\Controller\WooCommerce\Coupon.php:100
filterdataagent_order_metabox_localizesrc\Controller\WooCommerce\Insight\Insight_Daily_Revenue_Customer.php:149
actionadd_meta_boxessrc\Controller\WooCommerce\Metabox\Order.php:113
actionadd_meta_boxessrc\Controller\WooCommerce\Metabox\Product.php:120
filteradmin_enqueue_scriptssrc\Controller\WooCommerce\Order.php:108
actionmanage_woocommerce_page_wc-orders_custom_columnsrc\Controller\WooCommerce\Order.php:109
filteradmin_enqueue_scriptssrc\Controller\WooCommerce\Product.php:99
filterpost_row_actionssrc\Controller\WooCommerce\Product.php:100
filterdataagent_integrationssrc\Controller\WooCommerce\WooCommerce.php:79
Maintenance & Trust

DataAgent Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 28, 2025
PHP min version7.4
Downloads367

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

DataAgent Developer Profile

Artistudio

2 plugins · 800 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DataAgent

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dataagent/src/js/app.js/wp-content/plugins/dataagent/src/css/app.css/wp-content/plugins/dataagent/src/css/bootstrap.min.css/wp-content/plugins/dataagent/src/css/style.css
Script Paths
/wp-content/plugins/dataagent/src/js/app.js
Version Parameters
dataagent/src/css/app.css?ver=dataagent/src/css/bootstrap.min.css?ver=dataagent/src/css/style.css?ver=dataagent/src/js/app.js?ver=

HTML / DOM Fingerprints

CSS Classes
dataagent-containerdataagent-maindataagent-card
Data Attributes
data-da-typedata-da-actiondata-da-args
JS Globals
DataAgent
REST Endpoints
/wp-json/dataagent/v1/settings/wp-json/dataagent/v1/generate/wp-json/dataagent/v1/datasets/wp-json/dataagent/v1/data
Shortcode Output
[dataagent_ui][dataagent_form]
FAQ

Frequently Asked Questions about DataAgent