
SlashPress Security & Risk Analysis
wordpress.org/plugins/slashpressA conduit between your chat service and your WordPress sites.
Is SlashPress Safe to Use in 2026?
Generally Safe
Score 100/100SlashPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the SlashPress v1.2.0 plugin exhibits a generally good security posture. The absence of any known CVEs, critical taint flows, dangerous functions, or file operations is highly positive. The plugin also demonstrates good practices in its handling of SQL queries, using prepared statements exclusively, and a high percentage of properly escaped output. However, there are areas that warrant caution. The lack of nonce checks and capability checks on any entry points is a significant concern, as this leaves the plugin vulnerable to various cross-site request forgery (CSRF) and privilege escalation attacks if any entry points were to be discovered or introduced in the future. The single external HTTP request, while not inherently risky, should be monitored for potential vulnerabilities if the target endpoint is not secured or if the plugin handles the response insecurely. The complete lack of entry points (AJAX, REST API, shortcodes, cron) is unusual and could indicate either a very simple plugin or a potential oversight in the static analysis. If there are intended functionalities that were missed in the analysis, this could represent a hidden attack surface.
Key Concerns
- No nonce checks found
- No capability checks found
- External HTTP request without context
- High output escaping percentage, but still 18% unescaped
SlashPress Security Vulnerabilities
SlashPress Release Timeline
SlashPress Code Analysis
Output Escaping
SlashPress Attack Surface
WordPress Hooks 6
Maintenance & Trust
SlashPress Maintenance & Trust
Maintenance Signals
Community Trust
SlashPress Alternatives
Social Intents – Live Chat
live-chat-support-by-social-intents
AI Chatbot & Live Chat plugin for WordPress. Chat with visitors using ChatGPT, Claude, Gemini, Slack, Teams, and Google Chat.
Chatlio Live Chat for Slack
chatlio
Chatlio lets you talk with your customers using Slack directly from your WordPress site.
Hey Notify
hey-notify
Get notified when things happen in WordPress.
Init Live Search – AI-Powered, Related Posts, Slash Commands
init-live-search
Fast, modern live search powered by REST API — with AI-powered Related Posts Engine, slash commands, SEO-aware, ACF, Woo, and custom UI presets.
Rock The Slackbot
rock-the-slackbot
Rock The Slackbot helps you stay on top of changes by sending notifications straight to you and your team inside your Slack account.
SlashPress Developer Profile
8 plugins · 3K total installs
How We Detect SlashPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
/slashpress/v1/(?P<service_id>[^\s/]+)/(?P<auth_method>token|sig)