
Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Security & Risk Analysis
wordpress.org/plugins/kimiyiai-chatbotEnhance your WordPress site with Free ChatGPT AI Chatbot. Easily create lifelike digital humans to Answer Questions with Voice, Provide 24/7 Support, …
Is Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Safe to Use in 2026?
Generally Safe
Score 100/100Kimiyi AI – AI Chatbot with Digital Human, ChatGPT has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kimiyiai-chatbot" v1.5.3 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events with missing authentication checks significantly limits the potential attack surface. Furthermore, the code adheres to secure coding practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and properly escaping all identified output. The plugin also avoids file operations and does not bundle any external libraries, further reducing potential security risks. The single external HTTP request is a point to monitor, but its security implications are unknown without further context. The single nonce check is a positive sign for input validation.
However, the lack of identified capability checks is a notable concern. While the static analysis did not find any exploitable taint flows or known historical vulnerabilities, this does not guarantee the absence of future issues. The absence of capability checks means that certain actions within the plugin might be accessible to users who should not have that privilege, which could lead to privilege escalation or unauthorized data access if such actions exist. The vulnerability history showing no recorded CVEs suggests a history of responsible development or a lack of past scrutiny. This, combined with the current low-risk profile, indicates a plugin that is likely secure for its current functionality, but the absence of capability checks represents a potential weakness that could be exploited if functionality is added or if existing functionality is not sufficiently protected.
Key Concerns
- No capability checks found
Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Security Vulnerabilities
Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Release Timeline
Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Code Analysis
Output Escaping
Data Flow Analysis
Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Attack Surface
WordPress Hooks 4
Maintenance & Trust
Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Maintenance & Trust
Maintenance Signals
Community Trust
Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Alternatives
Tidio – Live Chat & AI Chatbots
tidio-live-chat
Add Tidio Live Chat to your WordPress for free to answer customers’ questions, engage website visitors, generate leads, and increase sales.
Crisp – Live Chat and Chatbot
crisp
A Free, one-click-to-install, Live Chat and chatbot plugin. No coding skills are required. Used by more than 30 000 customers on WordPress.
Support Board Cloud
support-board-cloud
A Free one-click-to-install Live Chat plugin. No coding skills required. Used by more than 2000 customers on WordPress.
SaleSmartly – Live Chat & Chat Bot Integrate
salesmartly-chat
Smart Sales Human service for your customers
MsgSmartly By Digidopt
msgsmartly-by-digidopt
A Free one-click-to-install Live Chat plugin. No coding skills required. Used by more than 2000 customers on WordPress.
Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Developer Profile
1 plugin · 0 total installs
How We Detect Kimiyi AI – AI Chatbot with Digital Human, ChatGPT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kimiyiai-chatbot/images/icon.pnghttps://widget.kimiyi.ai/DeployJS/Deploy3.jsHTML / DOM Fingerprints
cc-labelsname="my_Kimiyi_update_setting"