
Inbox Security & Risk Analysis
wordpress.org/plugins/inboxAll types of messages among users and admin including support departments are possible with this plugin.
Is Inbox Safe to Use in 2026?
Generally Safe
Score 92/100Inbox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "inbox" plugin version 1.2.2 exhibits a concerning security posture, primarily due to a large number of unprotected entry points. With 18 AJAX handlers, 14 of which lack authentication checks, and a total of 22 entry points with 14 unprotected, the plugin presents a significant attack surface. While the use of prepared statements for SQL queries is a positive sign, the extremely low percentage of properly escaped output (4%) is a critical weakness, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis further highlights this concern with 3 high severity flows, indicating potential for code injection or data leakage through unsanitized paths. The absence of any recorded CVEs and vulnerability history might suggest a lack of past exploitation or discovery, but it should not be interpreted as a guarantee of current security, especially given the identified code-level weaknesses. In conclusion, despite some good practices like prepared statements, the "inbox" plugin's security is significantly undermined by its extensive unprotected attack surface and poor output escaping, making it a high-risk plugin.
Key Concerns
- 14 AJAX handlers without auth checks
- 4% properly escaped output
- 3 high severity taint flows
- 7 flows with unsanitized paths
- 4 shortcodes
Inbox Security Vulnerabilities
Inbox Release Timeline
Inbox Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Inbox Attack Surface
AJAX Handlers 18
Shortcodes 4
WordPress Hooks 14
Maintenance & Trust
Inbox Maintenance & Trust
Maintenance Signals
Community Trust
Inbox Alternatives
Chaport — Live Chat & Chatbots
chaport
Modern live chat plugin for WordPress. Powerful features: multi-channel, chatbots, customization, etc. Free plan. Unlimited chats & websites.
HelpCrunch – Live Chat, Chatbot & Knowledge Base for Customer Service
helpcrunch-live-chat
The one-stop platform for even stronger customer relations. Bolster your customer support with its live chat, chatbot, and knowledge base software.
ProProfs Chat- Live Chat & Chatbot Plugin
proprofs-chat
ProProfs Chat is a SaaS-based live chat software that helps businesses of all sizes communicate with their website visitors and customers in real-time …
Tidio – Live Chat & AI Chatbots
tidio-live-chat
Add Tidio Live Chat to your WordPress for free to answer customers’ questions, engage website visitors, generate leads, and increase sales.
Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button
button-contact-vr
Powerful platform with Live Chat, AI Chatbots, and Real-Time Visitor Monitoring! Also, create Call, Email, SMS, & Contact buttons to increase conv …
Inbox Developer Profile
44 plugins · 33K total installs
How We Detect Inbox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/inbox/css/front.css/wp-content/plugins/inbox/js/front.js/wp-content/plugins/inbox/css/admin.css/wp-content/plugins/inbox/js/admin.js/wp-content/plugins/inbox/js/front.js/wp-content/plugins/inbox/js/admin.jsinbox/css/front.css?ver=inbox/js/front.js?ver=inbox/css/admin.css?ver=inbox/js/admin.js?ver=HTML / DOM Fingerprints
inbox-compose-textareainbox-message-listinbox-message-iteminbox-reply-boxinbox-sidebar-menuinbox-user-list<!-- Exit if accessed directly --><!-- Plugin Name: Inbox --><!-- Version: 1.2.2 -->data-inbox-iddata-user-idwindow.inbox_ajax_urlwindow.inbox_current_user_idvar wp_inbox_mail_headers/wp-json/inbox/v1/messages/wp-json/inbox/v1/send_message[inbox_messages][inbox_compose_form][inbox_user_list]