Sant Chat AI Security & Risk Analysis

wordpress.org/plugins/sant-chat-ai

AI chatbot for WordPress that trains on your content using RAG, captures leads, and supports visitors 24/7. Free sant.chat account required.

0 active installs v1.0.14 PHP 7.4+ WP 6.0+ Updated Apr 7, 2026
ai-chatbotchatbotcustomer-supportlead-generationlive-chat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sant Chat AI Safe to Use in 2026?

Generally Safe

Score 100/100

Sant Chat AI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "sant-chat-ai" plugin v1.0.14 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, critical taint flows, dangerous functions, or raw SQL queries indicates diligent development practices. Furthermore, the extensive use of prepared statements for SQL queries and proper output escaping for nearly all outputs are excellent security measures. The plugin also demonstrates good use of nonce and capability checks, particularly for its AJAX handlers. However, a minor concern could be the relatively high number of external HTTP requests (24), which, while not explicitly flagged as problematic in the static analysis, represent potential points of failure or introduction of vulnerabilities if not handled securely. The single file operation could also be a point to monitor, though its isolation and lack of taint flow suggest it's likely benign. Overall, the plugin appears to be well-secured, with its strengths significantly outweighing its minor potential weaknesses.

Vulnerabilities
None known

Sant Chat AI Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Sant Chat AI Release Timeline

v1.0.14Current
Code Analysis
Analyzed Apr 16, 2026

Sant Chat AI Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
89 prepared
Unescaped Output
38
2083 escaped
Nonce Checks
29
Capability Checks
44
File Operations
1
External Requests
24
Bundled Libraries
0

SQL Query Safety

100% prepared89 total queries

Output Escaping

98% escaped2121 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

10 flows
bulk_lead_action (includes/class-ajax-handlers.php:205)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sant Chat AI Attack Surface

Entry Points25
Unprotected0

AJAX Handlers 25

authwp_ajax_sant_chat_ai_start_syncincludes/class-ajax-handlers.php:35
authwp_ajax_sant_chat_ai_get_sync_progressincludes/class-ajax-handlers.php:36
authwp_ajax_sant_chat_ai_delete_synced_urlincludes/class-ajax-handlers.php:37
authwp_ajax_sant_chat_ai_add_manual_urlincludes/class-ajax-handlers.php:38
authwp_ajax_sant_chat_ai_validate_license_keyincludes/class-ajax-handlers.php:41
authwp_ajax_sant_chat_ai_capture_leadincludes/class-ajax-handlers.php:45
noprivwp_ajax_sant_chat_ai_capture_leadincludes/class-ajax-handlers.php:46
authwp_ajax_sant_chat_ai_export_settingsincludes/class-ajax-handlers.php:49
authwp_ajax_sant_chat_ai_import_settingsincludes/class-ajax-handlers.php:50
authwp_ajax_sant_save_faqsincludes/class-ajax-handlers.php:53
authwp_ajax_sant_chat_ai_update_lead_statusincludes/class-ajax-handlers.php:56
authwp_ajax_sant_chat_ai_bulk_lead_actionincludes/class-ajax-handlers.php:59
authwp_ajax_sant_chat_ai_save_lead_noteincludes/class-ajax-handlers.php:62
authwp_ajax_sant_chat_ai_send_test_emailincludes/class-ajax-handlers.php:65
authwp_ajax_sant_chat_ai_generate_titleincludes/class-ajax-handlers.php:68
noprivwp_ajax_sant_chat_ai_generate_titleincludes/class-ajax-handlers.php:69
authwp_ajax_sant_chat_ai_generate_lead_messageincludes/class-ajax-handlers.php:72
noprivwp_ajax_sant_chat_ai_generate_lead_messageincludes/class-ajax-handlers.php:73
authwp_ajax_sant_chat_ai_sync_knowledge_baseincludes/class-ajax-handlers.php:76
authwp_ajax_sant_chat_ai_add_correctionincludes/class-ajax-handlers.php:79
authwp_ajax_sant_chat_ai_list_correctionsincludes/class-ajax-handlers.php:80
authwp_ajax_sant_chat_ai_delete_correctionincludes/class-ajax-handlers.php:81
authwp_ajax_sant_chat_ai_wizard_save_stepincludes/class-ajax-handlers.php:84
authwp_ajax_sant_chat_ai_wizard_detect_sitemapincludes/class-ajax-handlers.php:85
authwp_ajax_sant_save_kb_contentsant-chat-ai.php:1197
WordPress Hooks 31
actionadmin_menuincludes/class-admin.php:42
actionadmin_headincludes/class-admin.php:43
actionadmin_initincludes/class-admin.php:44
actionadmin_initincludes/class-admin.php:45
actionadmin_initincludes/class-admin.php:46
actionadmin_enqueue_scriptsincludes/class-admin.php:47
actionadmin_noticesincludes/class-admin.php:48
actionadmin_noticesincludes/class-admin.php:49
actionadmin_bar_menuincludes/class-admin.php:50
actionwp_headincludes/class-admin.php:51
actionadmin_headincludes/class-admin.php:52
filteradmin_footer_textincludes/class-admin.php:53
actionwp_dashboard_setupincludes/class-admin.php:54
actionsant_chat_ai_knowledge_base_sync_cronincludes/class-knowledge-base.php:93
actionsant_chat_ai_do_syncincludes/class-knowledge-base.php:94
actionsave_postincludes/class-knowledge-base.php:97
actiondelete_postincludes/class-knowledge-base.php:98
actionupdate_option_sant_chat_ai_optionsincludes/class-knowledge-base.php:101
actionrest_api_initincludes/class-rest-api.php:51
actionadmin_initincludes/class-sant-chat-ai.php:91
actionplugins_loadedsant-chat-ai.php:57
filtercron_schedulessant-chat-ai.php:59
actionwp_enqueue_scriptssant-chat-ai.php:60
actionsant_chat_ai_health_check_cronsant-chat-ai.php:63
actionadmin_initsant-chat-ai.php:66
actionadmin_initsant-chat-ai.php:73
actionadmin_post_sant_save_license_keysant-chat-ai.php:3699
actionadmin_initsant-chat-ai.php:3818
actionadmin_noticessant-chat-ai.php:3889
actionadmin_noticessant-chat-ai.php:3896
actionwp_footersant-chat-ai.php:4854

Scheduled Events 5

sant_chat_ai_knowledge_base_sync_cron
sant_chat_ai_health_check_cron
sant_chat_ai_do_sync
sant_chat_ai_health_check_cron
sant_chat_ai_knowledge_base_sync_cron
Maintenance & Trust

Sant Chat AI Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 7, 2026
PHP min version7.4
Downloads54

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Sant Chat AI Developer Profile

santchat

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sant Chat AI

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sant-chat-ai/public/css/chat-widget.css/wp-content/plugins/sant-chat-ai/public/css/themes/classic.css/wp-content/plugins/sant-chat-ai/public/css/design-systems/
Version Parameters
sant-chat-ai/public/css/chat-widget.css?ver=sant-chat-ai/public/css/themes/classic.css?ver=sant-chat-ai/public/css/design-systems/

HTML / DOM Fingerprints

CSS Classes
sant-chat-ai-widget
Data Attributes
data-sant-chat-ai
JS Globals
santChatAiSettings
FAQ

Frequently Asked Questions about Sant Chat AI