Hey Trisha Security & Risk Analysis

wordpress.org/plugins/hey-trisha

AI-powered chatbot using OpenAI GPT for WordPress and WooCommerce. Natural language queries, product management, and intelligent responses.

0 active installs v2.1.7 PHP 7.4.3+ WP 5.0+ Updated Unknown
aichatbotnlpopenaiwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hey Trisha Safe to Use in 2026?

Generally Safe

Score 100/100

Hey Trisha has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "hey-trisha" v2.1.7 plugin exhibits a generally good security posture with a high percentage of properly escaped outputs and prepared SQL statements, indicating a focus on secure coding practices. The lack of any recorded vulnerabilities or CVEs further supports this. However, the static analysis reveals potential areas of concern. Specifically, the presence of 4 taint flows with unsanitized paths, all categorized as high severity, is a significant risk. These flows could potentially lead to the injection of malicious code or data if not properly handled. Additionally, one REST API route lacks a permission callback, creating an unprotected entry point that could be exploited.

Key Concerns

  • High severity unsanitized taint flows (4)
  • REST API route without permission callback
Vulnerabilities
None known

Hey Trisha Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hey Trisha Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
13 prepared
Unescaped Output
5
103 escaped
Nonce Checks
8
Capability Checks
35
File Operations
3
External Requests
7
Bundled Libraries
0

SQL Query Safety

81% prepared16 total queries

Output Escaping

95% escaped108 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

8 flows4 with unsanitized paths
heytrisha_handle_settings_save (heytrisha-woo.php:587)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Hey Trisha Attack Surface

Entry Points17
Unprotected1

AJAX Handlers 9

authwp_ajax_heytrisha_accept_termsheytrisha-woo.php:217
authwp_ajax_heytrisha_queryheytrisha-woo.php:2965
authwp_ajax_heytrisha_get_chatsheytrisha-woo.php:3014
authwp_ajax_heytrisha_create_chatheytrisha-woo.php:3044
authwp_ajax_heytrisha_get_chatheytrisha-woo.php:3079
authwp_ajax_heytrisha_save_messageheytrisha-woo.php:3123
authwp_ajax_heytrisha_update_chatheytrisha-woo.php:3164
authwp_ajax_heytrisha_get_personal_dataheytrisha-woo.php:3240
authwp_ajax_heytrisha_update_personal_dataheytrisha-woo.php:3478

REST API Routes 8

GET/wp-json/heytrisha/v1/configheytrisha-woo.php:2288
GET/wp-json/heytrisha/v1/chatsheytrisha-woo.php:3535
GET/wp-json/heytrisha/v1/chats/(?P<id>\d+)heytrisha-woo.php:3558
POST/wp-json/heytrisha/v1/chatsheytrisha-woo.php:3590
POST/wp-json/heytrisha/v1/chats/(?P<id>\d+)heytrisha-woo.php:3624
DELETE/wp-json/heytrisha/v1/chats/(?P<id>\d+)heytrisha-woo.php:3645
POST/wp-json/heytrisha/v1/chats/(?P<id>\d+)/archiveheytrisha-woo.php:3664
POST/wp-json/heytrisha/v1/chats/(?P<id>\d+)/messagesheytrisha-woo.php:3685
WordPress Hooks 24
filterscript_loader_tagheytrisha-woo.php:151
actionadmin_enqueue_scriptsheytrisha-woo.php:177
actionadmin_initheytrisha-woo.php:246
actionadmin_footerheytrisha-woo.php:254
filterplugin_row_metaheytrisha-woo.php:282
actionadmin_menuheytrisha-woo.php:349
actionadmin_headheytrisha-woo.php:391
actionadmin_noticesheytrisha-woo.php:395
actionadmin_noticesheytrisha-woo.php:402
actionadmin_noticesheytrisha-woo.php:442
actionadmin_initheytrisha-woo.php:700
actionadmin_initheytrisha-woo.php:1271
actionadmin_initheytrisha-woo.php:1319
actionadmin_initheytrisha-woo.php:1340
actionmuplugins_loadedheytrisha-woo.php:2153
actionplugins_loadedheytrisha-woo.php:2154
actioninitheytrisha-woo.php:2155
actionrest_api_initheytrisha-woo.php:2156
filterwp_die_handlerheytrisha-woo.php:2160
filterrest_pre_dispatchheytrisha-woo.php:2199
filterrest_post_dispatchheytrisha-woo.php:2236
filterrest_pre_serve_requestheytrisha-woo.php:2270
actionrest_api_initheytrisha-woo.php:2405
actionrest_api_initheytrisha-woo.php:3721
Maintenance & Trust

Hey Trisha Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4.3
Downloads441

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Hey Trisha Developer Profile

Manikandan Chandran

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hey Trisha

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hey-trisha/assets/css/chatbot.css/wp-content/plugins/hey-trisha/assets/js/chatbot.js
Script Paths
https://unpkg.com/react@18/umd/react.production.min.jshttps://unpkg.com/react-dom@18/umd/react-dom.production.min.js/wp-content/plugins/hey-trisha/assets/js/chatbot.js
Version Parameters
hey-trisha/assets/css/chatbot.css?ver=hey-trisha/assets/js/chatbot.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- ✅ CRITICAL: Prevent fatal error if another version of this plugin is already loaded --><!-- This can happen if the old plugin folder (e.g., "hey-trisha") is still active --><!-- while a new version with a different folder name is being activated. --><!-- ✅ CRITICAL: Suppress PHP notices/warnings for our REST API endpoints -->+31 more
Data Attributes
crossorigin="anonymous"
JS Globals
heytrishaConfig
REST Endpoints
/wp-json/heytrisha/v1/
FAQ

Frequently Asked Questions about Hey Trisha