
KimaAI | AI Chatbot, ChatGPT content writer and more Security & Risk Analysis
wordpress.org/plugins/kimaaiKimaAI is the first true all-in-one AI plugin for WordPress.
Is KimaAI | AI Chatbot, ChatGPT content writer and more Safe to Use in 2026?
Generally Safe
Score 100/100KimaAI | AI Chatbot, ChatGPT content writer and more has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kimaai" plugin version 1.4.7 exhibits a generally positive security posture with several good practices observed. A high percentage of SQL queries utilize prepared statements (84%) and output escaping is also well-handled (90%). The plugin also demonstrates good use of capability checks (15) and a reasonable number of nonce checks (1) for its entry points. Notably, there is no recorded vulnerability history, suggesting a history of secure development or diligent patching by the developers.
However, concerns arise from the plugin's attack surface, specifically the REST API. With 19 REST API routes, 5 of which lack permission callbacks, there is a significant risk of unauthorized access and data manipulation if these endpoints are not properly secured within the plugin's logic. While the static analysis did not detect any dangerous functions or unsanitized taint flows, the unprotected REST API routes present a clear vulnerability vector that requires immediate attention. The presence of bundled libraries (Freemius v1.0) is noted, though their specific security implications depend on their version and integration.
In conclusion, "kimaai" v1.4.7 has strengths in its code hygiene for SQL and output handling, and a clean vulnerability history. Nevertheless, the unsecured REST API endpoints are a critical weakness that significantly elevates the risk profile of this plugin. Further investigation into the functionality of these unprotected routes is highly recommended.
Key Concerns
- REST API routes without permission callbacks
KimaAI | AI Chatbot, ChatGPT content writer and more Security Vulnerabilities
KimaAI | AI Chatbot, ChatGPT content writer and more Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
KimaAI | AI Chatbot, ChatGPT content writer and more Attack Surface
REST API Routes 19
Shortcodes 1
WordPress Hooks 20
Maintenance & Trust
KimaAI | AI Chatbot, ChatGPT content writer and more Maintenance & Trust
Maintenance Signals
Community Trust
KimaAI | AI Chatbot, ChatGPT content writer and more Alternatives
Angie – Agentic AI for WordPress (Beta)
angie
Angie Code: Your expert WordPress developer, powered by AI. Build anything you can imagine without writing a single line of code.
UltraPress – AI Assistant, Chatbot & SEO
ultrapress
The AI Brain for your WordPress site. Engage visitors with a smart chatbot and enhance your SEO with AI-powered tools.
AI Chatbot for WordPress by Customerly
customerly
AI Chatbot to support customers, create engaging messages and send automated emails.
BuddyBot – OpenAI Assistants, AI Chatbots and Support Agents for WordPress
buddybot-ai-custom-ai-assistant-and-chat-agent
Discover AI Chatbots for WordPress, only plugin built on native OpenAI assistants. Explore a new different way to chat!
AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant
chatbot-ai-free-models
Add an AI Chatbot to your WordPress site for instant live chat or customer support. Featuring GPT, Claude, Llama and 70+ free models.
KimaAI | AI Chatbot, ChatGPT content writer and more Developer Profile
3 plugins · 500 total installs
How We Detect KimaAI | AI Chatbot, ChatGPT content writer and more
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kimaai/build/admin/admin.css/wp-content/plugins/kimaai/build/admin/index.js/wp-content/plugins/kimaai/assets/fonts/persian/yekan-font.css/wp-content/plugins/kimaai/build/admin/index.jskimaai-admin?ver=kimaai-admin-rtl?ver=HTML / DOM Fingerprints
kimaai-admin-pagedata-kimaai-chatboxwindow.__KIMAAI_CODE_EDITOR_SETTINGS__kimaaiAdmin/kimaai/v1[kimaai_chatbot]