Pulse Chat AI Security & Risk Analysis

wordpress.org/plugins/pulse-chat-ai

AI-powered chat assistant for WordPress powered by an advanced ChatGPT 5 AI models. Zero configuration required - works immediately after installation …

20 active installs v2.2.7 PHP 7.4+ WP 5.0+ Updated Dec 2, 2025
assistantchataichatbotchatgptopenai
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Pulse Chat AI Safe to Use in 2026?

Generally Safe

Score 100/100

Pulse Chat AI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The plugin "pulse-chat-ai" v2.2.7 demonstrates a generally strong security posture with a significant number of security checks in place. The absence of known CVEs and its consistent use of prepared statements for SQL queries are positive indicators. However, there are areas for improvement. The static analysis revealed 2 flows with unsanitized paths, which, while not classified as critical or high severity, represent a potential risk if user-supplied data is not handled meticulously. Additionally, only 2 nonce checks are present across all entry points, and while there are 5 capability checks, the overall number of security validations (nonces and capabilities combined) against the total entry points is relatively low (7 checks vs. 8 entry points), suggesting potential gaps in robust authentication and authorization for all interactions.

The vulnerability history being clear of any recorded issues is a major strength, suggesting a history of relatively secure development or effective patching. Despite the lack of critical findings in the taint analysis, the presence of unsanitized paths warrants attention. The plugin's strengths lie in its avoidance of dangerous functions and its high percentage of prepared SQL statements. The main weakness identified is the potential for unsanitized input to lead to issues, even if not currently exploited or deemed critical. A balanced conclusion is that while the plugin is not actively vulnerable based on historical data and the current static analysis, further scrutiny of input sanitization and strengthening of authorization checks would enhance its overall security.

Key Concerns

  • Unsanitized paths found in taint analysis
  • Low number of nonce checks relative to entry points
  • Potential for minor output escaping gaps
Vulnerabilities
None known

Pulse Chat AI Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Pulse Chat AI Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
32 prepared
Unescaped Output
17
49 escaped
Nonce Checks
2
Capability Checks
5
File Operations
1
External Requests
2
Bundled Libraries
0

SQL Query Safety

89% prepared36 total queries

Output Escaping

74% escaped66 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ajax_save_options (pulse-chat-ai.php:1894)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Pulse Chat AI Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 1

authwp_ajax_pulse_chat_ai_save_optionspulse-chat-ai.php:63

REST API Routes 6

POST/wp-json/pulse-chat-ai/v1/chatpulse-chat-ai.php:233
GET/wp-json/pulse-chat-ai/v1/conversationspulse-chat-ai.php:255
DELETE/wp-json/pulse-chat-ai/v1/conversations/(?P<id>\d+)pulse-chat-ai.php:263
POST/wp-json/pulse-chat-ai/v1/usage/resetpulse-chat-ai.php:278
POST/wp-json/pulse-chat-ai/v1/license/validatepulse-chat-ai.php:287
GET/wp-json/pulse-chat-ai/v1/license/statuspulse-chat-ai.php:303

Shortcodes 1

[pulse_chat_ai] pulse-chat-ai.php:60
WordPress Hooks 14
filterscript_loader_tagincludes\class-asset-loader.php:135
filterscript_loader_tagincludes\class-asset-loader.php:171
filterscript_loader_tagincludes\class-asset-loader.php:218
filterscript_loader_tagincludes\class-asset-loader.php:254
actionadmin_initincludes\class-license-manager.php:31
actionplugins_loadedincludes\class-license-manager.php:34
actioninitpulse-chat-ai.php:53
actionrest_api_initpulse-chat-ai.php:54
actionwp_enqueue_scriptspulse-chat-ai.php:55
actionadmin_enqueue_scriptspulse-chat-ai.php:56
actionwp_footerpulse-chat-ai.php:57
actionadmin_menupulse-chat-ai.php:58
actionadmin_initpulse-chat-ai.php:59
actionadmin_footerpulse-chat-ai.php:1181
Maintenance & Trust

Pulse Chat AI Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 2, 2025
PHP min version7.4
Downloads433

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Pulse Chat AI Developer Profile

pulsechat

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Pulse Chat AI

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pulse-chat-ai/assets/css/chatbot.css/wp-content/plugins/pulse-chat-ai/assets/js/chatbot.js/wp-content/plugins/pulse-chat-ai/assets/css/admin.css/wp-content/plugins/pulse-chat-ai/assets/js/admin.js
Script Paths
/wp-content/plugins/pulse-chat-ai/assets/js/chatbot.js/wp-content/plugins/pulse-chat-ai/assets/js/admin.js
Version Parameters
pulse-chat-ai/assets/css/chatbot.css?ver=pulse-chat-ai/assets/js/chatbot.js?ver=pulse-chat-ai/assets/css/admin.css?ver=pulse-chat-ai/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
pulse-chat-ai-containerpulse-chat-ai-widgetpulse-chat-ai-messagepulse-chat-ai-user-messagepulse-chat-ai-bot-messagepulse-chat-ai-input-areapulse-chat-ai-send-buttonpulse-chat-ai-bubble+1 more
HTML Comments
<!-- Pulse Chat AI Floating Widget --><!-- Pulse Chat AI Shortcode Output -->
Data Attributes
data-plugin-name="pulse-chat-ai"data-plugin-version="2.2.7"
JS Globals
PulseChatAIpulse_chat_ai_ajax_objectPulseChatAIAdmin
REST Endpoints
/wp-json/pulse-chat-ai/v1/message/wp-json/pulse-chat-ai/v1/settings
Shortcode Output
[pulse_chat_ai]
FAQ

Frequently Asked Questions about Pulse Chat AI