GPT-trainer Security & Risk Analysis

wordpress.org/plugins/gpt-trainer

GPT-Trainer empowers you to build a ChatGPT-like AI chat portal using your own data. No-code. Embed your AI chatbot directly onto your WordPress websi …

20 active installs v1.0.1 PHP 7.0+ WP 4.7+ Updated May 22, 2025
aichatbotcustomer-servicegptlive-chat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GPT-trainer Safe to Use in 2026?

Generally Safe

Score 100/100

GPT-trainer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The gpt-trainer v1.0.1 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, raw SQL queries, or file operations is a significant strength. Furthermore, the 100% proper output escaping and the lack of external HTTP requests indicate a diligent approach to preventing common web vulnerabilities.

However, a notable concern arises from the complete lack of nonce checks and capability checks. While the current analysis shows zero entry points without authentication, this absence of explicit checks leaves the plugin vulnerable if any new entry points are introduced or if existing ones are inadvertently exposed. The zero taint flows and zero known CVEs are positive indicators, suggesting the plugin has a history of being secure or has not been a target. Despite the strong internal coding practices observed, the lack of authorization enforcement mechanisms is a potential weakness that could be exploited in the future.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

GPT-trainer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GPT-trainer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Attack Surface

GPT-trainer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menugpt-trainer.php:13
actionadmin_initgpt-trainer.php:19
actionadmin_enqueue_scriptsgpt-trainer.php:104
actionwp_enqueue_scriptsgpt-trainer.php:105
actionwp_footergpt-trainer.php:115
Maintenance & Trust

GPT-trainer Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMay 22, 2025
PHP min version7.0
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

GPT-trainer Developer Profile

Hunter

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GPT-trainer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gpt-trainer/gpt-trainer.css
Script Paths
https://app.gpt-trainer.com/widget-asset.min.js
Version Parameters
gpt-trainer-admin-css?ver=1.0.0chatbot-script?ver=2

HTML / DOM Fingerprints

CSS Classes
gpt-trainer-admin-csslogo-containerform-groupnote-labelsubmit-btn-container
Data Attributes
id="gpt_trainer_uuid"
JS Globals
GPTTConfig
FAQ

Frequently Asked Questions about GPT-trainer