Storebird AI Chat for WooCommerce Security & Risk Analysis

wordpress.org/plugins/storebird-ai-chat-for-woocommerce

AI-powered customer support chatbot for WooCommerce. Automate product questions, order tracking, and lead capture — 24/7.

10 active installs v1.3.7 PHP 7.4+ WP 5.8+ Updated Mar 12, 2026
aichatbotcustomer-supportlive-chatwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Storebird AI Chat for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Storebird AI Chat for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 22d ago
Risk Assessment

The storebird-ai-chat-for-woocommerce plugin version 1.3.7 exhibits a generally strong security posture based on the static analysis. It demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output. The absence of dangerous functions, file operations, and bundled libraries further contributes to its positive security profile. However, a significant concern arises from the presence of one REST API route without permission callbacks, creating an unprotected entry point that could be exploited by unauthorized users. While the plugin has no recorded vulnerability history, this lack of past issues combined with the identified unprotected route suggests a potential for future vulnerabilities if not addressed. The overall risk is moderate, with the primary area of focus being the unauthenticated REST API endpoint.

Key Concerns

  • REST API route without permission callbacks
Vulnerabilities
None known

Storebird AI Chat for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Storebird AI Chat for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
0
39 escaped
Nonce Checks
8
Capability Checks
10
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

100% escaped39 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
maybe_handle_connect_token (includes\class-storebird-connect-handler.php:116)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Storebird AI Chat for WooCommerce Attack Surface

Entry Points10
Unprotected1

AJAX Handlers 8

authwp_ajax_storebird_verify_connectionincludes\class-storebird-admin.php:20
authwp_ajax_storebird_save_settingsincludes\class-storebird-admin.php:21
authwp_ajax_storebird_sync_productsincludes\class-storebird-admin.php:22
authwp_ajax_storebird_sync_products_initincludes\class-storebird-admin.php:23
authwp_ajax_storebird_sync_products_batchincludes\class-storebird-admin.php:24
authwp_ajax_storebird_get_sync_statusincludes\class-storebird-admin.php:25
authwp_ajax_storebird_get_sync_progressincludes\class-storebird-admin.php:26
authwp_ajax_storebird_clear_sync_lockincludes\class-storebird-admin.php:27

REST API Routes 2

GET/wp-json/storebird/v1/pingstorebird.php:84
POST/wp-json/storebird/v1/order/lookupstorebird.php:95
WordPress Hooks 17
actionadmin_menuincludes\class-storebird-admin.php:18
actionadmin_enqueue_scriptsincludes\class-storebird-admin.php:19
actionadmin_initincludes\class-storebird-connect-handler.php:30
actionadmin_initincludes\class-storebird-connect-handler.php:33
actionlogin_initincludes\class-storebird-connect-handler.php:36
filterlogin_redirectincludes\class-storebird-connect-handler.php:37
actionwoocommerce_update_productincludes\class-storebird-sync.php:16
actionwoocommerce_new_productincludes\class-storebird-sync.php:17
actionbefore_delete_postincludes\class-storebird-sync.php:18
actionwp_trash_postincludes\class-storebird-sync.php:19
actionwp_after_insert_postincludes\class-storebird-sync.php:22
actionbefore_delete_postincludes\class-storebird-sync.php:23
actionwp_trash_postincludes\class-storebird-sync.php:24
actionwp_footerincludes\class-storebird.php:38
actionwoocommerce_order_status_completedstorebird.php:72
actionplugins_loadedstorebird.php:76
actionrest_api_initstorebird.php:79
Maintenance & Trust

Storebird AI Chat for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 12, 2026
PHP min version7.4
Downloads414

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Storebird AI Chat for WooCommerce Developer Profile

velocityplugins

4 plugins · 50 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Storebird AI Chat for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/storebird-ai-chat-for-woocommerce/assets/css/storebird-chat.css/wp-content/plugins/storebird-ai-chat-for-woocommerce/assets/js/storebird-chat.js
Script Paths
/wp-content/plugins/storebird-ai-chat-for-woocommerce/assets/js/storebird-chat.js
Version Parameters
storebird-ai-chat-for-woocommerce/assets/css/storebird-chat.css?ver=storebird-ai-chat-for-woocommerce/assets/js/storebird-chat.js?ver=

HTML / DOM Fingerprints

JS Globals
STOREBIRD_API_URLSTOREBIRD_BASE_URLSTOREBIRD_DASHBOARD_URLstorebird_is_woocommerce_active
REST Endpoints
/storebird/v1/ping/storebird/v1/order/lookup
FAQ

Frequently Asked Questions about Storebird AI Chat for WooCommerce