Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Security & Risk Analysis

wordpress.org/plugins/kimiyiai-chatbot

Enhance your WordPress site with Free ChatGPT AI Chatbot. Easily create lifelike digital humans to Answer Questions with Voice, Provide 24/7 Support, …

0 active installs v1.5.3 PHP + WP 6.7+ Updated Dec 1, 2025
chatchatbotfree-live-chatlive-chatlivechat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Safe to Use in 2026?

Generally Safe

Score 100/100

Kimiyi AI – AI Chatbot with Digital Human, ChatGPT has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "kimiyiai-chatbot" v1.5.3 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events with missing authentication checks significantly limits the potential attack surface. Furthermore, the code adheres to secure coding practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and properly escaping all identified output. The plugin also avoids file operations and does not bundle any external libraries, further reducing potential security risks. The single external HTTP request is a point to monitor, but its security implications are unknown without further context. The single nonce check is a positive sign for input validation.

However, the lack of identified capability checks is a notable concern. While the static analysis did not find any exploitable taint flows or known historical vulnerabilities, this does not guarantee the absence of future issues. The absence of capability checks means that certain actions within the plugin might be accessible to users who should not have that privilege, which could lead to privilege escalation or unauthorized data access if such actions exist. The vulnerability history showing no recorded CVEs suggests a history of responsible development or a lack of past scrutiny. This, combined with the current low-risk profile, indicates a plugin that is likely secure for its current functionality, but the absence of capability checks represents a potential weakness that could be exploited if functionality is added or if existing functionality is not sufficiently protected.

Key Concerns

  • No capability checks found
Vulnerabilities
None known

Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Release Timeline

v1.6.3
v1.6.2
v1.6.1
v1.6.0
v1.5.3Current
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 6, 2026

Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
12 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped12 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
Kimiyi_footer_text_admin_page (kimiyiai-chatbot.php:65)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_headkimiyiai-chatbot.php:15
actionadmin_initkimiyiai-chatbot.php:41
actionadmin_menukimiyiai-chatbot.php:57
actionadmin_menukimiyiai-chatbot.php:64
Maintenance & Trust

Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings10
Active installs0
Developer Profile

Kimiyi AI – AI Chatbot with Digital Human, ChatGPT Developer Profile

Kimiyi.ai

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kimiyi AI – AI Chatbot with Digital Human, ChatGPT

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kimiyiai-chatbot/images/icon.png
Script Paths
https://widget.kimiyi.ai/DeployJS/Deploy3.js

HTML / DOM Fingerprints

CSS Classes
cc-labels
Data Attributes
name="my_Kimiyi_update_setting"
FAQ

Frequently Asked Questions about Kimiyi AI – AI Chatbot with Digital Human, ChatGPT