사이드톡 AI Security & Risk Analysis

wordpress.org/plugins/sidetalk-ai

사이드톡은 AI 경험이 없어도 개인과 기업이 손쉽게 맞춤형 챗봇을 구축할 수 있는 AI 기반 챗봇 플랫폼입니다.

20 active installs v1.1 PHP 5.3+ WP 6.0+ Updated Oct 15, 2024
aichatchatbotgptlive-chat
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 사이드톡 AI Safe to Use in 2026?

Generally Safe

Score 92/100

사이드톡 AI has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The sidetalk-ai plugin, version 1.1, exhibits a generally strong security posture based on the provided static analysis. It has no identified CVEs, a clean vulnerability history, and its attack surface appears to be completely protected. The code adheres to good practices by using prepared statements for all SQL queries and includes nonce and capability checks. However, a significant concern arises from the output escaping. With 68 total outputs and only 37% properly escaped, there is a high probability of Cross-Site Scripting (XSS) vulnerabilities being present. The taint analysis also flagged two flows with unsanitized paths, which, although not classified as critical or high severity, warrant attention as they indicate potential for unintended data processing. These findings suggest that while the plugin is well-protected against external access and data manipulation through SQL, it has weaknesses in sanitizing output, which could lead to client-side vulnerabilities.

Key Concerns

  • Low percentage of properly escaped output
  • Taint flows with unsanitized paths
Vulnerabilities
None known

사이드톡 AI Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

사이드톡 AI Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
43
25 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

37% escaped68 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
update (class\Sidetalk_Option.class.php:37)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

사이드톡 AI Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_enqueue_scriptsclass\Sidetalk_AI.class.php:12
actionadmin_post_sidetalk_setting_saveclass\Sidetalk_Controller.class.php:10
actioninitsidetalk-ai.php:22
actionadmin_menusidetalk-ai.php:37
actionadmin_noticessidetalk-ai.php:48
Maintenance & Trust

사이드톡 AI Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 15, 2024
PHP min version5.3
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

사이드톡 AI Developer Profile

코스모스팜 - Cosmosfarm

3 plugins · 3K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 사이드톡 AI

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sidetalk-ai/images/icon.png
Script Paths
https://pages.sidetalk.ai/sidetalk.js

HTML / DOM Fingerprints

JS Globals
SidetalkAI
FAQ

Frequently Asked Questions about 사이드톡 AI