Sommelier Chatbox – Wine Recommendation Widget for WooCommerce Security & Risk Analysis

wordpress.org/plugins/sommelier-chatbox-wine-recommendation-widget-for-woocommerce

A floating WooCommerce chat widget that guides shoppers to 2-3 wines using your catalog data.

0 active installs v1.0.9 PHP 7.4+ WP 6.0+ Updated Jan 6, 2026
sommelierwinewine-pairingwine-recommendationwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Sommelier Chatbox – Wine Recommendation Widget for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Sommelier Chatbox – Wine Recommendation Widget for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "sommelier-chatbox-wine-recommendation-widget-for-woocommerce" plugin v1.0.9 demonstrates a generally good security posture based on the static analysis. It has a small attack surface consisting of only two AJAX handlers, and importantly, all identified entry points appear to have authentication and capability checks in place. The code also exhibits strong practices with 100% of SQL queries utilizing prepared statements and a reasonable 80% output escaping, along with three nonce checks. There are no identified dangerous functions, file operations, external HTTP requests, or bundled libraries, which further contributes to its security.

The taint analysis shows no identified flows with unsanitized paths, indicating a lack of readily exploitable data injection vulnerabilities. Furthermore, the plugin has no recorded historical vulnerabilities (CVEs), suggesting a consistent track record of secure development or a lack of past scrutiny.

While the static analysis results are positive, the presence of 20% unescaped output (2 out of 10 total outputs) represents a minor concern that could potentially lead to cross-site scripting (XSS) vulnerabilities if the unescaped data is user-controlled or sensitive. Overall, the plugin is well-developed from a security perspective, with its main weakness being the small proportion of unescaped output.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Sommelier Chatbox – Wine Recommendation Widget for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Sommelier Chatbox – Wine Recommendation Widget for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
8 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped10 total outputs
Attack Surface

Sommelier Chatbox – Wine Recommendation Widget for WooCommerce Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_wcsomm_chatincludes\class-frontend.php:151
noprivwp_ajax_wcsomm_chatincludes\class-frontend.php:152
WordPress Hooks 7
actionadmin_menuincludes\class-admin.php:24
actionadmin_post_wcsomm_save_settingsincludes\class-admin.php:25
actionwp_enqueue_scriptsincludes\class-frontend.php:149
actionwp_footerincludes\class-frontend.php:150
actionadmin_initincludes\class-init.php:41
actionadmin_noticesincludes\class-init.php:49
actionplugins_loadedsommelier-chatbox-wine-recommendation-widget-for-woocommerce.php:65
Maintenance & Trust

Sommelier Chatbox – Wine Recommendation Widget for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 6, 2026
PHP min version7.4
Downloads112

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Sommelier Chatbox – Wine Recommendation Widget for WooCommerce Developer Profile

winechatbox

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sommelier Chatbox – Wine Recommendation Widget for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sommelier-chatbox-wine-recommendation-widget-for-woocommerce/assets/css/theme-blossom.css/wp-content/plugins/sommelier-chatbox-wine-recommendation-widget-for-woocommerce/assets/css/theme-luxury.css/wp-content/plugins/sommelier-chatbox-wine-recommendation-widget-for-woocommerce/assets/css/theme-vinaccia.css/wp-content/plugins/sommelier-chatbox-wine-recommendation-widget-for-woocommerce/assets/js/chat-modern.js
Script Paths
/wp-content/plugins/sommelier-chatbox-wine-recommendation-widget-for-woocommerce/assets/js/chat-modern.js
Version Parameters
sommelier-chatbox-wine-recommendation-widget-for-woocommerce/assets/css/theme-blossom.css?ver=sommelier-chatbox-wine-recommendation-widget-for-woocommerce/assets/css/theme-luxury.css?ver=sommelier-chatbox-wine-recommendation-widget-for-woocommerce/assets/css/theme-vinaccia.css?ver=sommelier-chatbox-wine-recommendation-widget-for-woocommerce/assets/js/chat-modern.js?ver=

HTML / DOM Fingerprints

CSS Classes
wcsomm-chat-widget
HTML Comments
<!-- Sommelier Chatbox -->
Data Attributes
data-wcsomm-ajax-url
JS Globals
window.wcsommPayload
FAQ

Frequently Asked Questions about Sommelier Chatbox – Wine Recommendation Widget for WooCommerce