
Support AI – AI Chatbot for WordPress Security & Risk Analysis
wordpress.org/plugins/supportaiCustom AI chatbot for WordPress. Easily train and integrate your AI chatbots to instantly answer your customers' questions.
Is Support AI – AI Chatbot for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Support AI – AI Chatbot for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'supportai' v1.2 plugin exhibits a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) and its code analysis shows no critical or high severity taint flows. All SQL queries utilize prepared statements, and there are no dangerous functions or file operations detected, which are strong indicators of good security practices.
However, there are notable areas of concern. The plugin exposes 12 AJAX handlers, with 2 of them lacking authentication checks. This represents a significant attack surface that could potentially be exploited by unauthenticated users. Additionally, while nonce checks are present, the capability checks are entirely missing, meaning that even authenticated users might be able to perform actions they shouldn't have access to. The output escaping is also inconsistent, with 59% of outputs properly escaped, leaving the remaining 41% potentially vulnerable to cross-site scripting (XSS) attacks if they handle user-supplied data.
In conclusion, 'supportai' v1.2 has a relatively clean vulnerability history, which is encouraging. The absence of SQL injection vulnerabilities and taint flow issues is a significant strength. Nevertheless, the unprotected AJAX endpoints and incomplete capability checks, combined with potentially unescaped output, present real security risks that require attention.
Key Concerns
- Unprotected AJAX handlers found
- Missing capability checks on entry points
- Inconsistent output escaping (41% unescaped)
Support AI – AI Chatbot for WordPress Security Vulnerabilities
Support AI – AI Chatbot for WordPress Code Analysis
Output Escaping
Data Flow Analysis
Support AI – AI Chatbot for WordPress Attack Surface
AJAX Handlers 12
WordPress Hooks 3
Maintenance & Trust
Support AI – AI Chatbot for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Support AI – AI Chatbot for WordPress Alternatives
MxChat – AI Chatbot & Content Generation for WordPress
mxchat-basic
The best free AI chatbot and content generation plugin for WordPress. Train ChatGPT, Claude, Gemini, or Grok on your website content.
Lime Connect (formerly Userlike) – WordPress Live Chat plugin
userlike
Free live chat plugin to chat with the visitors of your website. Integrate a beautiful and fully customizable chat box. Hosted in Europe.
AI Chatbot for WordPress by Customerly
customerly
AI Chatbot to support customers, create engaging messages and send automated emails.
Social Intents – Live Chat
live-chat-support-by-social-intents
AI Chatbot & Live Chat plugin for WordPress. Chat with visitors using ChatGPT, Claude, Gemini, Slack, Teams, and Google Chat.
Chatbot with ChatGPT WordPress
smartsearchwp
Turn your WordPress content into a ChatGPT-powered AI assistant with semantic search, contextual answers, and full control.
Support AI – AI Chatbot for WordPress Developer Profile
1 plugin · 100 total installs
How We Detect Support AI – AI Chatbot for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/supportai/css/admin.css/wp-content/plugins/supportai/css/toastify.min.css/wp-content/plugins/supportai/js/main.js/wp-content/plugins/supportai/js/toastify-js.jshttps://widget.supportai.com/supportai/css/admin.css?v=supportai/js/main.js?v=HTML / DOM Fingerprints
<!-- SupportAI.com --><!-- End of SupportAI.com -->data-supportai-ajax-urldata-supportai-noncedata-supportai-api-keysupportai_ajax_objectsupportai_ajax_urlsupportai_api_keysupportai_ajax_nonce/wp-json/supportai/