SupBot.Ai Security & Risk Analysis

wordpress.org/plugins/supbotai

SupBot.Ai has a powerful node editor to create a conversation tree chatbot that can easily engage your passive visitors in a good conversation.

0 active installs v0.1.2 PHP 7.2+ WP 5.2+ Updated Unknown
chatbotcustomer-supportengagementinteractivesupport-chat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SupBot.Ai Safe to Use in 2026?

Generally Safe

Score 100/100

SupBot.Ai has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'supbotai' plugin v0.1.2 exhibits a strong security posture. The code demonstrates excellent adherence to security best practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and all output properly escaped. Furthermore, the presence of nonce and capability checks on its single AJAX entry point significantly mitigates common web vulnerabilities. The absence of any recorded vulnerabilities (CVEs) in its history further reinforces this positive assessment.

While the static analysis did not reveal any taint flows or specific code-level risks, and the vulnerability history is clean, the plugin's attack surface, though small, is entirely reliant on its single AJAX handler having proper authorization. However, the report explicitly states this handler has a nonce check and a capability check, indicating it's protected. The plugin also has no file operations or external HTTP requests, which are common sources of vulnerabilities. Overall, 'supbotai' v0.1.2 appears to be a well-secured plugin with no immediate, exploitable risks identified in this analysis.

Vulnerabilities
None known

SupBot.Ai Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SupBot.Ai Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped7 total outputs
Attack Surface

SupBot.Ai Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_supbotai_save_jsonadmin-page.php:105
WordPress Hooks 4
actionadmin_menuadmin-page.php:16
actioninitcustom-post-type.php:28
actionadmin_enqueue_scriptsenqueue.php:54
actionwp_enqueue_scriptsenqueue.php:75
Maintenance & Trust

SupBot.Ai Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedUnknown
PHP min version7.2
Downloads695

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SupBot.Ai Developer Profile

supbotai

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SupBot.Ai

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/supbotai/assets/css/admin-page.css/wp-content/plugins/supbotai/assets/js/admin-page.js/wp-content/plugins/supbotai/assets/css/chat.css/wp-content/plugins/supbotai/assets/js/chat.js
Script Paths
/wp-content/plugins/supbotai/assets/js/admin-page.js/wp-content/plugins/supbotai/assets/js/chat.js
Version Parameters
supbotai/assets/js/admin-page.js?ver=supbotai/assets/js/chat.js?ver=

HTML / DOM Fingerprints

CSS Classes
supbotai-chat-containersupbotai-chat-messagesupbotai-chat-inputsupbotai-chat-send-button
Data Attributes
data-supbotai-post-iddata-supbotai-post-json
JS Globals
supbotaisupbotaiAjax
FAQ

Frequently Asked Questions about SupBot.Ai