Ochatbot – AI Chatbot for eCommerce & Support Security & Risk Analysis

wordpress.org/plugins/ochatbot-and-ometrics-conversion-optimization-tools

Increase eCommerce sales and leads with Ochatbot - a free AI Chatbot.

60 active installs v1.3.02 PHP 7.0+ WP 4.7+ Updated Dec 22, 2025
ai-chatbotchat-botchatbotwoocommerce-botwoocommerce-chatbot
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ochatbot – AI Chatbot for eCommerce & Support Safe to Use in 2026?

Generally Safe

Score 100/100

Ochatbot – AI Chatbot for eCommerce & Support has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "ochatbot-and-ometrics-conversion-optimization-tools" plugin version 1.3.02 exhibits a generally good security posture based on the provided static analysis. All identified entry points, including AJAX handlers and REST API routes, appear to have proper authentication checks, significantly reducing the risk of unauthorized access. The plugin also avoids dangerous functions, uses prepared statements for all SQL queries, and has a clean history with no recorded vulnerabilities. This suggests a conscientious approach to security during development.

However, a notable concern is the relatively low percentage of properly escaped output (64%). This leaves a potential window for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without sufficient sanitization. While no critical or high-severity taint flows were detected, and the attack surface is protected, this output escaping issue warrants attention. The plugin's lack of historical vulnerabilities is a positive indicator, but it's important to remember that this only reflects past findings and doesn't guarantee future security.

In conclusion, the plugin demonstrates several strong security practices, particularly in its handling of access control and data persistence. The primary weakness identified is the insufficient output escaping, which, while not a critical flaw based on the current analysis, represents a potential risk that should be addressed to further harden the plugin's security.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Ochatbot – AI Chatbot for eCommerce & Support Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ochatbot – AI Chatbot for eCommerce & Support Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
60 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

64% escaped94 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
adminPanelConnect (wp-ometrics.php:408)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Ochatbot – AI Chatbot for eCommerce & Support Attack Surface

Entry Points10
Unprotected0

AJAX Handlers 2

authwp_ajax_wpometrics_review_actionincludes\class-wpometrics_reviews.php:49
authwp_ajax_ometrics_submitwp-ometrics.php:93

REST API Routes 8

GET/wp-json/wp-ometrics/v1/order/(?P<order_id>.+)wp-ometrics.php:108
GET/wp-json/wp-ometrics/v1/conversionwp-ometrics.php:114
GET/wp-json/wp-ometrics/v1/productswp-ometrics.php:120
GET/wp-json/wp-ometrics/v1/products/(?P<product_id>[\d]+)/variationswp-ometrics.php:126
GET/wp-json/wp-ometrics/v1/pageswp-ometrics.php:132
GET/wp-json/wp-ometrics/v1/postswp-ometrics.php:138
GET/wp-json/wp-ometrics/v1/media/(?P<media_id>[\d]+)wp-ometrics.php:144
GET/wp-json/wp-ometrics/v1/categorieswp-ometrics.php:150
WordPress Hooks 12
actioninitincludes\class-wpometrics_reviews.php:48
actionadmin_noticesincludes\class-wpometrics_reviews.php:58
actionnetwork_admin_noticesincludes\class-wpometrics_reviews.php:59
actionuser_admin_noticesincludes\class-wpometrics_reviews.php:60
actionadmin_initwp-ometrics.php:78
actionadmin_menuwp-ometrics.php:79
actionadmin_noticeswp-ometrics.php:80
actionwp_headwp-ometrics.php:84
actionwoocommerce_thankyouwp-ometrics.php:87
actionrest_api_initwp-ometrics.php:90
filterwoocommerce_rest_check_permissionswp-ometrics.php:92
actionadmin_enqueue_scriptswp-ometrics.php:95
Maintenance & Trust

Ochatbot – AI Chatbot for eCommerce & Support Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 22, 2025
PHP min version7.0
Downloads12K

Community Trust

Rating100/100
Number of ratings7
Active installs60
Developer Profile

Ochatbot – AI Chatbot for eCommerce & Support Developer Profile

Ometrics, LLC

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ochatbot – AI Chatbot for eCommerce & Support

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ochatbot-and-ometrics-conversion-optimization-tools/assets/css/admin.css/wp-content/plugins/ochatbot-and-ometrics-conversion-optimization-tools/assets/js/ometrics-settings.js
Version Parameters
ochatbot-and-ometrics-conversion-optimization-tools/assets/css/admin.css?ver=ochatbot-and-ometrics-conversion-optimization-tools/assets/js/ometrics-settings.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-ometrics-iddata-ometrics-tokendata-ometrics-agent
JS Globals
window.WP_OMETRICS_VERSIONwindow.ometrics_settings
REST Endpoints
/wp-json/wp-ometrics/v1/order/(?P<order_id>.+)/wp-json/wp-ometrics/v1/conversion/wp-json/wp-ometrics/v1/products/wp-json/wp-ometrics/v1/products/(?P<product_id>[\d]+)/variations/wp-json/wp-ometrics/v1/pages/wp-json/wp-ometrics/v1/posts/wp-json/wp-ometrics/v1/media/(?P<media_id>[\d]+)/wp-json/wp-ometrics/v1/categories
FAQ

Frequently Asked Questions about Ochatbot – AI Chatbot for eCommerce & Support