
GBP AutoReply AI Security & Risk Analysis
wordpress.org/plugins/gbp-autoreply-aiEasily manage Google Business Profile reviews and generate smart AI replies with ChatGPT—all in your WP dashboard.
Is GBP AutoReply AI Safe to Use in 2026?
Generally Safe
Score 100/100GBP AutoReply AI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The gbp-autoreply-ai plugin v1.1 exhibits a generally good security posture with several strong practices in place. The overwhelming majority of outputs are properly escaped, and SQL queries predominantly utilize prepared statements, significantly reducing the risk of common injection vulnerabilities. The absence of known CVEs and no recorded vulnerability history are positive indicators of past security diligence. The plugin also demonstrates a good number of nonce and capability checks, contributing to its overall resilience.
However, a notable concern arises from the presence of one AJAX handler lacking authentication checks. This creates a potential entry point for attackers to trigger actions within the plugin without proper authorization, which could lead to unintended consequences or further exploitation depending on the functionality of that specific handler. While taint analysis shows no critical or high-severity issues, the existence of this unprotected AJAX endpoint remains a significant weakness.
In conclusion, while the plugin benefits from strong output escaping and prepared SQL statements, the single unprotected AJAX handler presents a clear and actionable security risk. Addressing this specific vulnerability should be the immediate priority to enhance the plugin's security. The overall lack of historical vulnerabilities is encouraging, but ongoing vigilance is always recommended, especially given the identified unprotected entry point.
Key Concerns
- Unprotected AJAX handler found
GBP AutoReply AI Security Vulnerabilities
GBP AutoReply AI Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
GBP AutoReply AI Attack Surface
AJAX Handlers 5
WordPress Hooks 3
Maintenance & Trust
GBP AutoReply AI Maintenance & Trust
Maintenance Signals
Community Trust
GBP AutoReply AI Alternatives
Free Customer Service Tools by OpenWidget
free-customer-service-tools-by-openwidget
Enhance engagement and trust with AI-based tools, Google Reviews, bug reporting, live chat, FAQs, and more! No coding skills required.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
LocoAI – Auto Translate For Loco Translate
automatic-translator-addon-for-loco-translate
LocoAI - Auto Translate For Loco Translate is a powerful tool for developers looking to quickly translate their WordPress plugins and themes.
BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor
betterdocs
A full-featured documentation plugin including AI writing assistance to create knowledge bases, docs, FAQs, wikis, and more with easy drag & drop UI.
GBP AutoReply AI Developer Profile
8 plugins · 320 total installs
How We Detect GBP AutoReply AI
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gbp-autoreply-ai/assets/admin.css/wp-content/plugins/gbp-autoreply-ai/assets/admin.js/wp-content/plugins/gbp-autoreply-ai/assets/admin.jsgbp-autoreply-ai/assets/admin.css?ver=gbp-autoreply-ai/assets/admin.js?ver=HTML / DOM Fingerprints
data-review_idGBIZP_AJAXwindow.GBP_API_KEY_MISSING/wp-json/gbp-autoreply-ai/v1/some-endpoint