Lopaa Security & Risk Analysis

wordpress.org/plugins/lopaa

AI-powered chatbot for WordPress with WooCommerce integration. Automate customer support, boost engagement, and handle inquiries 24/7.

0 active installs v1.6 PHP 7.4+ WP 5.0+ Updated Nov 28, 2025
aiautomationchatbotcustomer-supportwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Lopaa Safe to Use in 2026?

Generally Safe

Score 100/100

Lopaa has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "lopaa" v1.6 plugin exhibits a generally strong security posture, with no known historical vulnerabilities or critical findings in the static analysis. The absence of AJAX handlers, shortcodes, and cron events, coupled with the single REST API route having a permission callback, significantly limits the plugin's attack surface. The code analysis also indicates good practices in handling SQL queries and nonce checks. However, a notable area of concern is the output escaping, where only 38% of outputs are properly escaped. This presents a risk of Cross-Site Scripting (XSS) vulnerabilities, especially if any of the unsafely escaped data is user-controlled or originates from external sources. The presence of a file operation and an external HTTP request, while not inherently insecure, warrants careful review in conjunction with the output escaping issues to ensure these operations do not lead to further vulnerabilities.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Lopaa Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Lopaa Release Timeline

v1.6Current
v1.5
v1.0
Code Analysis
Analyzed Mar 17, 2026

Lopaa Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
20 escaped
Nonce Checks
2
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

38% escaped52 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
lopaa_settings_page (includes\lopaa-activation.php:52)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Lopaa Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

GET/wp-json/lopaa/v1/ordersincludes\lopaa-orders.php:6
WordPress Hooks 8
actionadmin_menuincludes\lopaa-activation.php:36
actionadmin_initincludes\lopaa-activation.php:37
actionadmin_noticesincludes\lopaa-activation.php:38
actionwp_enqueue_scriptsincludes\lopaa-chat.php:5
actionwp_body_openincludes\lopaa-chat.php:71
actionrest_api_initincludes\lopaa-orders.php:5
actionplugins_loadedlopaa.php:39
actionadmin_noticeslopaa.php:44
Maintenance & Trust

Lopaa Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 28, 2025
PHP min version7.4
Downloads218

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Lopaa Developer Profile

sulopatech

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lopaa

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lopaa/assets/
Script Paths
/wp-content/plugins/lopaa/assets/lopaa-react-app.js
Version Parameters
lopaa/assets/

HTML / DOM Fingerprints

JS Globals
window.ChatbotConfig
REST Endpoints
/wp-json/lopaa/v1/orders
Shortcode Output
<div id="container"></div>
FAQ

Frequently Asked Questions about Lopaa