OutaiGate WebChat Installer Security & Risk Analysis

wordpress.org/plugins/outaigate-webchat-installer

お客様のサービスに合わせて使用できるカスタマイズチャットボットです。

0 active installs v1.0.3 PHP 7.0+ WP 5.0+ Updated Feb 7, 2023
chatbotecommercewebchat
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is OutaiGate WebChat Installer Safe to Use in 2026?

Generally Safe

Score 85/100

OutaiGate WebChat Installer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The outaigate-webchat-installer plugin version 1.0.3 demonstrates a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code signals indicate responsible development practices, with 100% of SQL queries using prepared statements and the presence of both nonce and capability checks, suggesting an awareness of common WordPress vulnerabilities.

However, a notable concern arises from the output escaping, where only 67% of outputs are properly escaped. This leaves a portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not adequately sanitized before being displayed. The lack of any recorded vulnerability history is a positive indicator, suggesting a history of secure development. Despite the limited attack surface and good use of security features, the incomplete output escaping warrants attention.

In conclusion, the plugin is built with several strong security foundations, particularly in its handling of data interactions and authentication. The primary weakness lies in the insufficient output escaping. While the current lack of historical vulnerabilities is reassuring, the identified output escaping issue represents a real, albeit potentially low-severity, risk that should be addressed to ensure a more robust security profile.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

OutaiGate WebChat Installer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

OutaiGate WebChat Installer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
18 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped27 total outputs
Attack Surface

OutaiGate WebChat Installer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuincludes\outaigate-admin-form.php:23
actionadmin_enqueue_scriptsincludes\outaigate-admin-form.php:25
actionadmin_post_outaigate_admin_saveincludes\outaigate-admin-form.php:27
actionwp_headincludes\outaigate-admin-form.php:244
Maintenance & Trust

OutaiGate WebChat Installer Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 7, 2023
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

OutaiGate WebChat Installer Developer Profile

leejaewon

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OutaiGate WebChat Installer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/outaigate-webchat-installer/assets/bootstrap.min.css/wp-content/plugins/outaigate-webchat-installer/assets/bootstrap.bundle.min.js
Version Parameters
outaigate-webchat-installer/assets/bootstrap.min.css?ver=outaigate-webchat-installer/assets/bootstrap.bundle.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
outaigate-admin-formsoutaigate-admin-data
Data Attributes
name="outaigate-admin-data"
JS Globals
outaigate_admin_current_viewoutaigate_admin_template_server_path
FAQ

Frequently Asked Questions about OutaiGate WebChat Installer