Quidget – AI Chatbot & Live Chat Security & Risk Analysis

wordpress.org/plugins/quidget-chat

Quidget is an AI chatbot and live chat plugin for WordPress that automates support and connects visitors with real agents.

10 active installs v1.1.6 PHP 7.4+ WP 5.0+ Updated Dec 2, 2025
ai-chatbotchat-supportchatbotcustomer-supportlive-chat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Quidget – AI Chatbot & Live Chat Safe to Use in 2026?

Generally Safe

Score 100/100

Quidget – AI Chatbot & Live Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The static analysis of the "quidget-chat" v1.1.6 plugin reveals a seemingly strong security posture. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions identified, all SQL queries using prepared statements, and all output properly escaped. The lack of file operations, external HTTP requests, and the absence of any taint analysis findings also contribute to a low-risk profile based on the provided static analysis. The plugin's vulnerability history is also clear, with zero recorded CVEs, suggesting a lack of publicly known security flaws.

However, the complete absence of nonce checks and capability checks on all entry points (even though the entry points are zero) is a notable concern. While there are currently no entry points to exploit, if any are introduced in future versions without proper authentication and authorization mechanisms, the plugin would be highly vulnerable. The lack of vulnerability history is a positive indicator, but it doesn't guarantee future immunity, especially if the development practices around security checks are not consistently applied. Overall, while the current version appears secure due to its limited functionality and robust code practices, the lack of fundamental security checks on potential future entry points represents a latent risk.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
Vulnerabilities
None known

Quidget – AI Chatbot & Live Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Quidget – AI Chatbot & Live Chat Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Quidget – AI Chatbot & Live Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped13 total outputs
Attack Surface

Quidget – AI Chatbot & Live Chat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initincludes\settings.php:8
actionadmin_menuincludes\settings.php:21
filterscript_loader_tagquidget-chat.php:34
actionwp_enqueue_scriptsquidget-chat.php:42
actionwp_footerquidget-chat.php:67
actionadmin_enqueue_scriptsquidget-chat.php:75
Maintenance & Trust

Quidget – AI Chatbot & Live Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Quidget – AI Chatbot & Live Chat Developer Profile

Quidget

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Quidget – AI Chatbot & Live Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quidget-chat/assets/styles.css
Script Paths
https://quidget.ai/webchat/quidget.loader.js
Version Parameters
quidget-chat/assets/styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
no-lazyno-lazyloadskip-lazya3-notlazylazyload-disabled
Data Attributes
data-id
FAQ

Frequently Asked Questions about Quidget – AI Chatbot & Live Chat