JRT AI Agent Security & Risk Analysis

wordpress.org/plugins/jrt-ai-agent

AI support chat widget grounded by your site content, with privacy mode and optional WooCommerce product context.

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Feb 26, 2026
aichatbotchatgptcustomer-supportgemini
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is JRT AI Agent Safe to Use in 2026?

Generally Safe

Score 100/100

JRT AI Agent has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The jrt-ai-agent v1.0.0 plugin exhibits a generally good security posture, with no recorded historical vulnerabilities and a clean taint analysis. The static analysis reveals a small attack surface with all identified entry points (two AJAX handlers) being protected by nonce and capability checks. SQL queries are exclusively handled using prepared statements, and there are no direct file operations or bundled libraries to worry about. However, there are areas for improvement. A significant portion of output (37%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without sanitization. Additionally, the plugin makes two external HTTP requests, and while the analysis doesn't indicate they are directly exploitable for this version, external requests always introduce a degree of risk by relying on the security of third-party services and the integrity of the data retrieved. The lack of any recorded past vulnerabilities is positive, suggesting developers are either diligent or the plugin hasn't been a target. Overall, while the core functionalities appear secure, the unescaped output is the most prominent risk that warrants attention.

Key Concerns

  • Significant unescaped output
  • External HTTP requests present
Vulnerabilities
None known

JRT AI Agent Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

JRT AI Agent Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
85
143 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

63% escaped228 total outputs
Attack Surface

JRT AI Agent Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_jrt_ai_agent_chatincludes\class-jrt-ai-agent-ajax.php:18
noprivwp_ajax_jrt_ai_agent_chatincludes\class-jrt-ai-agent-ajax.php:19
WordPress Hooks 7
actionadmin_menuincludes\class-jrt-ai-agent-admin.php:13
actionadmin_initincludes\class-jrt-ai-agent-admin.php:14
actionadmin_enqueue_scriptsincludes\class-jrt-ai-agent-admin.php:15
actionwp_enqueue_scriptsincludes\class-jrt-ai-agent-plugin.php:50
actionwp_footerincludes\class-jrt-ai-agent-plugin.php:51
actionwp_enqueue_scriptsincludes\class-jrt-ai-agent-plugin.php:145
actionplugins_loadedjrt-ai-agent.php:30
Maintenance & Trust

JRT AI Agent Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.4
Downloads195

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

JRT AI Agent Developer Profile

jrtwebsolutions

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect JRT AI Agent

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jrt-ai-agent/assets/js/jrt-ai-agent-admin.js
Version Parameters
jrt-ai-agent/assets/js/jrt-ai-agent-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
jrt-ai-agent-field-rowjrt-ai-agent-modaljrt-ai-agent-modal[hidden]jrt-ai-agent-modal__overlayjrt-ai-agent-modal__paneljrt-ai-agent-modal__headerjrt-ai-agent-modal__titlejrt-ai-agent-modal__body+4 more
Data Attributes
data-providerdata-api-keydata-modeldata-system-promptdata-gemini-api-keydata-gemini-model+19 more
JS Globals
window.JRT_AI_AGENT_SETTINGSJRT_AI_AGENT_SETTINGS
FAQ

Frequently Asked Questions about JRT AI Agent