GBP AutoReply AI Security & Risk Analysis

wordpress.org/plugins/gbp-autoreply-ai

Easily manage Google Business Profile reviews and generate smart AI replies with ChatGPT—all in your WP dashboard.

0 active installs v1.1 PHP 7.4+ WP 6.0+ Updated Sep 25, 2025
aichatgptgoogle-business-profilegoogle-reviewsreviews
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GBP AutoReply AI Safe to Use in 2026?

Generally Safe

Score 100/100

GBP AutoReply AI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The gbp-autoreply-ai plugin v1.1 exhibits a generally good security posture with several strong practices in place. The overwhelming majority of outputs are properly escaped, and SQL queries predominantly utilize prepared statements, significantly reducing the risk of common injection vulnerabilities. The absence of known CVEs and no recorded vulnerability history are positive indicators of past security diligence. The plugin also demonstrates a good number of nonce and capability checks, contributing to its overall resilience.

However, a notable concern arises from the presence of one AJAX handler lacking authentication checks. This creates a potential entry point for attackers to trigger actions within the plugin without proper authorization, which could lead to unintended consequences or further exploitation depending on the functionality of that specific handler. While taint analysis shows no critical or high-severity issues, the existence of this unprotected AJAX endpoint remains a significant weakness.

In conclusion, while the plugin benefits from strong output escaping and prepared SQL statements, the single unprotected AJAX handler presents a clear and actionable security risk. Addressing this specific vulnerability should be the immediate priority to enhance the plugin's security. The overall lack of historical vulnerabilities is encouraging, but ongoing vigilance is always recommended, especially given the identified unprotected entry point.

Key Concerns

  • Unprotected AJAX handler found
Vulnerabilities
None known

GBP AutoReply AI Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GBP AutoReply AI Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
4 prepared
Unescaped Output
1
134 escaped
Nonce Checks
13
Capability Checks
5
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

80% prepared5 total queries

Output Escaping

99% escaped135 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
gbizp_get_new_ai_response_callback (gbp-autoreply-ai.php:179)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

GBP AutoReply AI Attack Surface

Entry Points5
Unprotected1

AJAX Handlers 5

authwp_ajax_gbizp_get_new_ai_replygbp-autoreply-ai.php:127
authwp_ajax_gbizp_save_ai_responsegbp-autoreply-ai.php:152
authwp_ajax_gbizp_get_new_ai_responsegbp-autoreply-ai.php:178
authwp_ajax_gbizp_delete_saved_reviewsgbp-autoreply-ai.php:228
authwp_ajax_gbizp_save_reviews_linkgbp-autoreply-ai.php:258
WordPress Hooks 3
actionadmin_menugbp-autoreply-ai.php:68
actionadmin_enqueue_scriptsgbp-autoreply-ai.php:81
actioninitincludes\class-gbp-business-profile.php:129
Maintenance & Trust

GBP AutoReply AI Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 25, 2025
PHP min version7.4
Downloads226

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

GBP AutoReply AI Developer Profile

Guru Plugins

8 plugins · 320 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GBP AutoReply AI

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gbp-autoreply-ai/assets/admin.css/wp-content/plugins/gbp-autoreply-ai/assets/admin.js
Script Paths
/wp-content/plugins/gbp-autoreply-ai/assets/admin.js
Version Parameters
gbp-autoreply-ai/assets/admin.css?ver=gbp-autoreply-ai/assets/admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-review_id
JS Globals
GBIZP_AJAXwindow.GBP_API_KEY_MISSING
REST Endpoints
/wp-json/gbp-autoreply-ai/v1/some-endpoint
FAQ

Frequently Asked Questions about GBP AutoReply AI