Reqme – AI-Powered Service Management Security & Risk Analysis

wordpress.org/plugins/reqme

Turn client inquiries into organized requests, AI conversations, proposals, contracts, and invoices, with a Reqme request button for WordPress.

0 active installs v1.0.2 PHP 7.4+ WP 6.0+ Updated Jul 16, 2026
aiclient-requestslead-capturerequestsservice-business
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Reqme – AI-Powered Service Management Safe to Use in 2026?

Generally Safe

Score 100/100

Reqme – AI-Powered Service Management has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'reqme' plugin v1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not using dangerous functions, exclusively employing prepared statements for SQL queries, and having no recorded vulnerabilities. The plugin also correctly implements nonce checks on its single file operation and manages its external HTTP requests with at least some awareness of security implications.

However, significant concerns arise from the attack surface and taint analysis. With four AJAX handlers, two of which lack any authentication checks, there's a clear vulnerability to unauthorized execution of plugin functions. The taint analysis revealing two flows with unsanitized paths, even without critical or high severity, suggests a potential for code injection or other sensitive data manipulation if these paths can be exploited by an unauthenticated user. The lack of capability checks is also a notable weakness, as it fails to enforce user roles for critical operations.

Overall, while the absence of historical vulnerabilities and the use of prepared statements are strengths, the unprotected AJAX endpoints and the unsanitized paths present immediate and actionable risks. The plugin would benefit greatly from implementing robust authentication and authorization checks on all entry points and thoroughly sanitizing all user-supplied data.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths
  • Missing capability checks
Vulnerabilities
None known

Reqme – AI-Powered Service Management Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Reqme – AI-Powered Service Management Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Reqme – AI-Powered Service Management Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
18 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

78% escaped23 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
reqme_update_api_key_callback (core/includes/classes/class-reqme-plugin-run.php:235)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Reqme – AI-Powered Service Management Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 4

noprivwp_ajax_reqme_update_api_keycore/includes/classes/class-reqme-plugin-run.php:54
authwp_ajax_reqme_update_api_keycore/includes/classes/class-reqme-plugin-run.php:55
noprivwp_ajax_reqme_get_configscore/includes/classes/class-reqme-plugin-run.php:56
authwp_ajax_reqme_get_configscore/includes/classes/class-reqme-plugin-run.php:57
WordPress Hooks 5
actionadmin_enqueue_scriptscore/includes/classes/class-reqme-plugin-run.php:52
actionwp_enqueue_scriptscore/includes/classes/class-reqme-plugin-run.php:53
actionadmin_initcore/includes/classes/class-reqme-plugin-run.php:58
actionadmin_menucore/includes/classes/class-reqme-plugin-run.php:59
filterupload_mimesreqme.php:188
Maintenance & Trust

Reqme – AI-Powered Service Management Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJul 16, 2026
PHP min version7.4
Downloads483

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

Reqme – AI-Powered Service Management Developer Profile

Reqme

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Reqme – AI-Powered Service Management

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/reqme/core/includes/assets/img/button-styles/v1.png/wp-content/plugins/reqme/core/includes/assets/img/button-styles/v2.png/wp-content/plugins/reqme/core/includes/assets/img/button-styles/v3.png/wp-content/plugins/reqme/core/includes/assets/img/button-styles/v4.png/wp-content/plugins/reqme/core/includes/assets/img/button-styles/v5.png/wp-content/plugins/reqme/core/includes/assets/img/button-styles/v6.png/wp-content/plugins/reqme/core/includes/assets/img/button-styles/v7.png/wp-content/plugins/reqme/core/includes/assets/img/logo.svg+2 more
Version Parameters
reqme/1.0.1

HTML / DOM Fingerprints

JS Globals
reqme_api_base_urlreqme_ajax_urlreqme_nonce
REST Endpoints
/wp-json/reqme/v1/configs/wp-json/reqme/v1/update-api-key
FAQ

Frequently Asked Questions about Reqme – AI-Powered Service Management