FukuroChat Connector Security & Risk Analysis

wordpress.org/plugins/fukurochat-connector

Connect your WooCommerce store to FukuroChat AI Assistant. Automatic product sync, intelligent chatbot widget, and seamless integration.

0 active installs v1.0.10 PHP 7.4+ WP 5.0+ Updated Jan 23, 2026
aichatchatbotecommercewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FukuroChat Connector Safe to Use in 2026?

Generally Safe

Score 100/100

FukuroChat Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The fukurochat-connector plugin v1.0.10 exhibits a generally positive security posture, demonstrating good practices in several key areas. The complete absence of known CVEs and the use of prepared statements for all SQL queries are significant strengths. Furthermore, the plugin shows a strong adherence to output escaping with 98% of outputs properly escaped and utilizes capability checks consistently for its entry points.

However, there are specific areas of concern that introduce potential risks. The plugin exposes five AJAX handlers, with two of them lacking proper authentication checks. This presents a clear attack vector where unauthenticated users could potentially interact with sensitive functionality. While the taint analysis found no unsanitized paths, the presence of these unprotected AJAX endpoints means that any data passed to them, even if handled securely internally, could be initiated by malicious actors.

Overall, the plugin's vulnerability history is clean, which is a positive indicator. The strengths in SQL handling and output escaping are commendable. Nevertheless, the unprotected AJAX handlers represent a tangible security risk that needs to be addressed to improve the plugin's overall security. Addressing these unprotected entry points should be a priority.

Key Concerns

  • AJAX handlers without auth checks
Vulnerabilities
None known

FukuroChat Connector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

FukuroChat Connector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
1
58 escaped
Nonce Checks
4
Capability Checks
5
File Operations
0
External Requests
6
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

98% escaped59 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ajax_toggle_sync (fukurochat-connector.php:1824)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

FukuroChat Connector Attack Surface

Entry Points5
Unprotected2

AJAX Handlers 5

authwp_ajax_fukurochat_track_add_to_cartfukurochat-connector.php:52
noprivwp_ajax_fukurochat_track_add_to_cartfukurochat-connector.php:53
authwp_ajax_fukurochat_exchange_tokenfukurochat-connector.php:56
authwp_ajax_fukurochat_toggle_syncfukurochat-connector.php:59
authwp_ajax_fukurochat_initial_syncfukurochat-connector.php:62
WordPress Hooks 18
actionadmin_menufukurochat-connector.php:23
actionadmin_initfukurochat-connector.php:24
actionwp_footerfukurochat-connector.php:27
actioncustomize_registerfukurochat-connector.php:30
actionwoocommerce_new_productfukurochat-connector.php:33
actionwoocommerce_update_productfukurochat-connector.php:34
actionwp_trash_postfukurochat-connector.php:35
actionbefore_delete_postfukurochat-connector.php:36
actiontransition_post_statusfukurochat-connector.php:39
actionadmin_noticesfukurochat-connector.php:42
actionwoocommerce_new_orderfukurochat-connector.php:45
actionwoocommerce_thankyoufukurochat-connector.php:46
actionwp_footerfukurochat-connector.php:47
actionwoocommerce_checkout_create_orderfukurochat-connector.php:48
actionwoocommerce_store_api_checkout_order_processedfukurochat-connector.php:49
actionadd_meta_boxesfukurochat-connector.php:65
actionsave_postfukurochat-connector.php:66
actionadmin_enqueue_scriptsfukurochat-connector.php:105
Maintenance & Trust

FukuroChat Connector Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 23, 2026
PHP min version7.4
Downloads411

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

FukuroChat Connector Developer Profile

FukuroChat

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FukuroChat Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fukurochat-connector/icon-256x256.png

HTML / DOM Fingerprints

CSS Classes
fukuro-step
Data Attributes
data-fukurochat-target-iddata-fukurochat-bubble-textdata-fukurochat-positiondata-fukurochat-offset-horizontaldata-fukurochat-offset-vertical
JS Globals
fukuroChatWidgetfukuroChatInit
REST Endpoints
/wp-json/fukurochat/v1/connection-status/wp-json/fukurochat/v1/sync-status/wp-json/fukurochat/v1/sync-products/wp-json/fukurochat/v1/logs/wp-json/fukurochat/v1/tracking-status
FAQ

Frequently Asked Questions about FukuroChat Connector