
Inqyra Security & Risk Analysis
wordpress.org/plugins/inqyraAI-powered chatbot that answers visitor questions based on your own WordPress content. Bring your own API key — zero markup.
Is Inqyra Safe to Use in 2026?
Generally Safe
Score 100/100Inqyra has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "inqyra" v1.1.5 plugin exhibits a mixed security posture. On one hand, it demonstrates strong adherence to secure coding practices with 100% of SQL queries using prepared statements and all output properly escaped. The presence of numerous nonce and capability checks (42 and 43 respectively) also suggests an awareness of securing WordPress functionalities. Furthermore, the plugin's vulnerability history is clean, with no recorded CVEs, indicating a history of robust security.
However, a significant concern arises from the extensive attack surface exposed through AJAX handlers. All 24 identified AJAX handlers lack authentication checks, making them direct entry points for potential attackers. While no critical or high severity taint flows were explicitly detailed, the 5 flows with unsanitized paths within the analyzed 14 taint flows are a serious red flag. These unsanitized paths, combined with the unprotected AJAX endpoints, create a high probability of exploitation if an attacker can trigger these flows. The bundled libraries, Select2 and Freemius v1.0, also warrant attention for potential version-specific vulnerabilities, although no specific issues are detailed here.
In conclusion, "inqyra" v1.1.5 has strengths in its database interaction and output handling. Nevertheless, the lack of authentication on a large number of AJAX handlers and the presence of unsanitized paths in taint flows represent critical security weaknesses that significantly elevate the risk profile of this plugin. Immediate attention should be directed towards securing these AJAX endpoints.
Key Concerns
- All AJAX handlers lack authentication checks
- 5 flows with unsanitized paths found
- Bundled library Select2 (version not specified)
- Bundled library Freemius v1.0 (potential outdated version)
Inqyra Security Vulnerabilities
Inqyra Release Timeline
Inqyra Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Inqyra Attack Surface
AJAX Handlers 24
WordPress Hooks 28
Scheduled Events 5
Maintenance & Trust
Inqyra Maintenance & Trust
Maintenance Signals
Community Trust
Inqyra Alternatives
HybridAI Chatbot
hybridai-chatbot
Automatically integrates the HybridAI Chatbot into your WordPress site, allowing users to chat with an AI assistant powered by HybridAI.
Lime Connect (formerly Userlike) – WordPress Live Chat plugin
userlike
Free live chat plugin to chat with the visitors of your website. Integrate a beautiful and fully customizable chat box. Hosted in Europe.
Live Chat & AI Chatbot – onWebChat
onwebchat
Add live chat and a 24/7 AI chatbot to your site. Engage visitors instantly, automate support, and convert more visitors into customers.
Social Intents – Live Chat
live-chat-support-by-social-intents
AI Chatbot & Live Chat plugin for WordPress. Chat with visitors using ChatGPT, Claude, Gemini, Slack, Teams, and Google Chat.
AI Chatbot for WordPress by Customerly
customerly
AI Chatbot to support customers, create engaging messages and send automated emails.
Inqyra Developer Profile
1 plugin · 0 total installs
How We Detect Inqyra
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/inqyra/assets/css/inqyra-admin-style.css/wp-content/plugins/inqyra/assets/css/inqyra-chatbot.css/wp-content/plugins/inqyra/assets/css/inqyra-frontend.css/wp-content/plugins/inqyra/assets/js/inqyra-admin.js/wp-content/plugins/inqyra/assets/js/inqyra-chatbot.js/wp-content/plugins/inqyra/assets/js/inqyra-frontend.js/wp-content/plugins/inqyra/assets/js/inqyra-vendor.jsinqyra/assets/css/inqyra-admin-style.css?ver=inqyra/assets/css/inqyra-chatbot.css?ver=inqyra/assets/css/inqyra-frontend.css?ver=inqyra/assets/js/inqyra-admin.js?ver=inqyra/assets/js/inqyra-chatbot.js?ver=inqyra/assets/js/inqyra-frontend.js?ver=inqyra/assets/js/inqyra-vendor.js?ver=HTML / DOM Fingerprints
inqyra-chatbot-iconinqyra-chatbot-widgetinqyra-chat-bubbleinqyra-chat-messageinqyra-chat-input-wrapper<!-- Inqyra Admin Page --><!-- Inqyra Chatbot Widget --><!-- Inqyra Chat Bubble -->data-inqyra-api-keydata-inqyra-modeldata-inqyra-widget-idinqyraChatbotinqyraSettings/wp-json/inqyra/v1/message/wp-json/inqyra/v1/conversations[inqyra_chat]