LoryBot | Advanced AI Chatbot Security & Risk Analysis

wordpress.org/plugins/lorybot-ai-chatbot

LoryBot is a AI Chatbot for WordPress

10 active installs v1.4.1 PHP 5.3+ WP 4.9+ Updated Feb 4, 2025
ai-chatbotartificial-intelligence-chatchatbot-plugincustomer-support-chatwp-chatbot
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LoryBot | Advanced AI Chatbot Safe to Use in 2026?

Generally Safe

Score 92/100

LoryBot | Advanced AI Chatbot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the static analysis, the 'lorybot-ai-chatbot' plugin v1.4.1 exhibits a generally strong security posture. There are no identified critical or high-severity code signals, dangerous functions, or taint flows, indicating that the developers have implemented good coding practices for preventing common vulnerabilities. The complete absence of unescaped output and the exclusive use of prepared statements for SQL queries are significant strengths. Furthermore, the plugin has no recorded vulnerability history, suggesting a mature and secure development lifecycle.

However, there are a few areas that warrant attention. The plugin relies entirely on WordPress's core authentication and authorization mechanisms, as evidenced by the zero capability checks and zero nonce checks. While this can be a good practice to leverage existing security, it also means that any vulnerabilities within these core checks could indirectly affect the plugin. The presence of file operations and external HTTP requests, although not flagged as insecure in this analysis, always represent potential attack vectors that require careful monitoring. The lack of a documented vulnerability history is positive, but it is not a guarantee of future security.

In conclusion, 'lorybot-ai-chatbot' v1.4.1 appears to be a well-developed plugin with a focus on secure coding. The absence of exploitable flaws in the static analysis and its clean vulnerability history are positive indicators. The primary areas for consideration are the potential indirect impact of core WordPress vulnerabilities and the inherent risks associated with file operations and external requests. Continued vigilance and prompt updates in response to any future security findings will be crucial for maintaining its security.

Key Concerns

  • No capability checks found
  • No nonce checks found on AJAX
Vulnerabilities
None known

LoryBot | Advanced AI Chatbot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LoryBot | Advanced AI Chatbot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
21 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
3
Bundled Libraries
0

Output Escaping

100% escaped21 total outputs
Attack Surface

LoryBot | Advanced AI Chatbot Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionwp_footerincludes\functions-chat-display.php:28
filterwp_kses_allowed_htmlincludes\functions-chat-display.php:43
actionadmin_enqueue_scriptsincludes\functions-enqueue-scripts.php:65
actionwp_enqueue_scriptsincludes\functions-enqueue-scripts.php:69
actionadmin_menuincludes\functions-settings.php:14
actionadmin_initincludes\functions-settings.php:26
actionupdated_optionincludes\functions-settings.php:144
actionupgrader_process_completeincludes\lorybot_update.php:34
actionadmin_initincludes\utils.php:49
actionadmin_enqueue_scriptsincludes\utils.php:78
actionshutdownincludes\utils.php:88
Maintenance & Trust

LoryBot | Advanced AI Chatbot Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 4, 2025
PHP min version5.3
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

LoryBot | Advanced AI Chatbot Developer Profile

lorybot

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LoryBot | Advanced AI Chatbot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lorybot-ai-chatbot/assets/js/script.js/wp-content/plugins/lorybot-ai-chatbot/assets/css/style.css/wp-content/plugins/lorybot-ai-chatbot/assets/css/admin-style.css
Script Paths
/wp-content/plugins/lorybot-ai-chatbot/assets/js/script.js
Version Parameters
lorybot-script?ver=1.4.1lorybot-style?ver=1.4.1

HTML / DOM Fingerprints

HTML Comments
<!-- LoryBot AI Chatbot -->
Data Attributes
data-lorybot-custom-iddata-lorybot-main-colordata-lorybot-background-colordata-lorybot-title-color
JS Globals
chatbot_vars
Shortcode Output
[lorybot-chat]
FAQ

Frequently Asked Questions about LoryBot | Advanced AI Chatbot