Instabot: Chatbot to Increase Conversions on WordPress. Try for Free Security & Risk Analysis

wordpress.org/plugins/instabot

Increase conversions by adding a chatbot to your WP site. Gather valuable user data. Curate your site and convert users quickly and effectively.

40 active installs v1.14 PHP 7.0+ WP 5.0+ Updated Unknown
aichat-botchatbotinstabotnatural-language-processing
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 7, 2025
Safety Verdict

Is Instabot: Chatbot to Increase Conversions on WordPress. Try for Free Safe to Use in 2026?

Generally Safe

Score 99/100

Instabot: Chatbot to Increase Conversions on WordPress. Try for Free has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 7, 2025
Risk Assessment

The 'instabot' plugin v1.14 exhibits a mixed security posture. On the positive side, the static analysis reveals a commendable lack of dangerous functions, no raw SQL queries, and a good percentage of properly escaped output, indicating efforts towards secure coding practices. Furthermore, the absence of known critical or high severity vulnerabilities in its history and the fact that its single historical CVE is patched are positive indicators. However, there are areas of concern. The presence of a single external HTTP request without further context could potentially introduce risks if not handled securely. While taint analysis shows no issues, the lack of thorough analysis for flows (0 total flows analyzed) means that potential vulnerabilities might have been missed. The historical CVE being a CSRF vulnerability, even if patched, suggests that the plugin has had past issues that require vigilance. The plugin has a history of vulnerabilities, and while none are currently unpatched, this pattern warrants caution. The limited scope of the static analysis in terms of entry points and the lack of deeper taint flow analysis suggest that further investigation might be beneficial to ensure a truly robust security profile. Overall, the plugin shows good progress in secure coding but has historical context and a single external request that necessitate ongoing monitoring and potentially deeper security audits.

Key Concerns

  • Historical CVE present, even if patched
  • External HTTP request without context
  • Limited taint flow analysis (0 flows analyzed)
  • Medium severity historical vulnerability
Vulnerabilities
1

Instabot: Chatbot to Increase Conversions on WordPress. Try for Free Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22571medium · 6.1Cross-Site Request Forgery (CSRF)

Instabot <= 1.10 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Jan 7, 2025 Patched in 1.11 (396d)
Code Analysis
Analyzed Mar 16, 2026

Instabot: Chatbot to Increase Conversions on WordPress. Try for Free Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
11 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

69% escaped16 total outputs
Attack Surface

Instabot: Chatbot to Increase Conversions on WordPress. Try for Free Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_headsrc\Plugin.php:34
actionadmin_menusrc\Plugin.php:79
actionadmin_enqueue_scriptssrc\Plugin.php:88
Maintenance & Trust

Instabot: Chatbot to Increase Conversions on WordPress. Try for Free Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.0
Downloads4K

Community Trust

Rating100/100
Number of ratings3
Active installs40
Developer Profile

Instabot: Chatbot to Increase Conversions on WordPress. Try for Free Developer Profile

instabot

1 plugin · 40 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
396 days
View full developer profile
Detection Fingerprints

How We Detect Instabot: Chatbot to Increase Conversions on WordPress. Try for Free

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/instabot/assets/admin.css
Version Parameters
instabot-admin-css?ver=

HTML / DOM Fingerprints

JS Globals
window.addEventListenerwindow.attachEventwindow.onloadvar elementvar tagsvar m
FAQ

Frequently Asked Questions about Instabot: Chatbot to Increase Conversions on WordPress. Try for Free