InsertChat Security & Risk Analysis

wordpress.org/plugins/insertchat

InsertChat – Advanced AI-Powered Chatbots for WordPress

30 active installs v1.1.6 PHP 7.0+ WP 4.7+ Updated Sep 26, 2024
ai-chatbotai-creatorchatgptchatgpt-for-wordpressinsertchat
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is InsertChat Safe to Use in 2026?

Generally Safe

Score 92/100

InsertChat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of the "insertchat" plugin version 1.1.6 reveals a generally strong security posture with no detected critical or high severity issues in taint analysis, dangerous functions, or SQL injection vulnerabilities. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output. The absence of known CVEs and a clean vulnerability history further bolsters this positive assessment, suggesting a well-maintained and secure codebase.

However, the analysis does highlight a few areas for improvement. The plugin makes an external HTTP request, which, while not inherently a vulnerability, represents a potential attack vector if the target endpoint is compromised or if the request is not handled securely. Furthermore, the complete lack of capability checks and the sole reliance on a single nonce check for its entire attack surface (which is zero in this case, but still noteworthy in principle) could be a concern if the plugin were to expand its functionality or introduce new entry points in the future. The zero reported entry points is a strength in minimizing the attack surface but also makes the lack of broader security checks seem less critical than it might otherwise be.

In conclusion, "insertchat" v1.1.6 appears to be a secure plugin based on the provided data, with a strong emphasis on secure coding practices like prepared statements and output escaping. The absence of historical vulnerabilities is a significant positive indicator. The minor concerns around the external HTTP request and the limited scope of capability checks are areas that could be reviewed for further hardening, especially if the plugin's complexity or feature set were to increase.

Key Concerns

  • External HTTP requests made by plugin
  • No capability checks found
Vulnerabilities
None known

InsertChat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

InsertChat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
9 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

90% escaped10 total outputs
Attack Surface

InsertChat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwp_enqueue_scriptsinsertchat.php:207
actionadmin_headinsertchat.php:208
actionadmin_enqueue_scriptsinsertchat.php:209
actionadmin_enqueue_scriptsinsertchat.php:210
actionadmin_menuinsertchat.php:211
actionadmin_initinsertchat.php:212
Maintenance & Trust

InsertChat Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 26, 2024
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

InsertChat Developer Profile

Zak

1 plugin · 30 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect InsertChat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/insertchat/insertchat-admin-style.css
Script Paths
https://bot.insertchat.com/widgets/chatbot.js
Version Parameters
insertchat-admin-style?ver=chatbot.js?wordpress=true&widget_id=

HTML / DOM Fingerprints

CSS Classes
insertchat-wrapinsertchat-form-containerinsertchat-logo-containerinsertchat-form-groupsubmit-btn-container
Data Attributes
id='insertchat_id'
JS Globals
window.ICG_BOT_IDwindow.ICG_BOT_TYPEwindow.ICG_BOT_HEIGHTwindow.ICG_BOT_AUTOFOCUSwindow.ICG_BOT_OVERRIDE_OPENERwindow.ICG_USER_ID+5 more
FAQ

Frequently Asked Questions about InsertChat