[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fn1e3u-eNkRkk9RLQjlmY9VUsopzNCPiB1f02qZeHvUM":3,"$fDtFfaviw1gTYHeHntjNGLj6hP-ZJsjmpWvdUGzOhsTQ":528,"$fQM-ODSGfLDkOGPQJUZqOB99ouzsY9epuoCRXoJs0x-g":531},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":24,"download_link":25,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"discovery_status":28,"vulnerabilities":29,"developer":30,"crawl_stats":26,"alternatives":35,"analysis":125,"fingerprints":497},"talktopc","TalkToPC Voice Widget","1.9.113","TTP GO LTD.","https:\u002F\u002Fprofiles.wordpress.org\u002Fyinon11\u002F","\u003Cp>\u003Cstrong>Try before you install!\u003C\u002Fstrong>\u003Cbr \u002F>\nLive Demo: https:\u002F\u002Ftalktopc.com\u002Fdemos\u002Fagent_1900570ad\u003C\u002Fp>\n\u003Cp>TalkToPC Voice Widget adds an AI-powered voice assistant to your WordPress website. Visitors can have natural voice conversations with your AI agent in over 40 languages — no coding or typing required.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>🚀 Quick Setup (Under 2 Minutes):\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Col>\n\u003Cli>Install the plugin\u003C\u002Fli>\n\u003Cli>Click “Connect to TalkToPC” \u003C\u002Fli>\n\u003Cli>Done! Your AI assistant is auto-created with content from your website\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>The plugin automatically scans your pages, posts, and products to create a personalized AI assistant that knows your business inside and out.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>✨ Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>One-Click Setup\u003C\u002Fstrong> – OAuth connection with automatic AI agent creation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>40+ Languages Supported\u003C\u002Fstrong> – Full support for English, Hebrew, Spanish, French, Arabic, and dozens more.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>AI-Powered Configuration\u003C\u002Fstrong> – System prompt auto-generated from your site content.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Voice & Text Modes\u003C\u002Fstrong> – Visitors can speak naturally or type.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Fully Customizable\u003C\u002Fstrong> – Match your brand with custom colors, icons, and positions.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>WooCommerce Support\u003C\u002Fstrong> – AI knows your products, prices, and availability.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Mobile Ready\u003C\u002Fstrong> – Optimized for all devices with microphone access.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Low Latency\u003C\u002Fstrong> – High-speed response for natural, flowing conversations.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>🎯 Use Cases:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Customer support automation\u003C\u002Fli>\n\u003Cli>Instant FAQ handling\u003C\u002Fli>\n\u003Cli>Product recommendations and sales\u003C\u002Fli>\n\u003Cli>Appointment scheduling\u003C\u002Fli>\n\u003Cli>Lead qualification\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>🔒 Security:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Secure OAuth 2.0 connection\u003C\u002Fli>\n\u003Cli>No passwords stored\u003C\u002Fli>\n\u003Cli>One-time secrets with automatic expiration\u003C\u002Fli>\n\u003Cli>All data transmitted over encrypted HTTPS\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin relies on the TalkToPC service (https:\u002F\u002Ftalktopc.com) to provide AI voice conversations.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What data is sent:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Site content (pages, posts, products) during initial setup for AI configuration.\u003Cbr \u002F>\n* Voice audio when visitors use the voice widget.\u003Cbr \u002F>\n* API credentials for authentication.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>External domains used:\u003C\u002Fstrong>\u003Cbr \u002F>\n* https:\u002F\u002Fcdn.talktopc.com – Widget JavaScript files.\u003Cbr \u002F>\n* https:\u002F\u002Fspeech.talktopc.com – Voice processing.\u003Cbr \u002F>\n* https:\u002F\u002Fbackend.talktopc.com – API requests.\u003Cbr \u002F>\n\u003Cstrong>Service policies:\u003C\u002Fstrong>\u003Cbr \u002F>\n* Terms of Service: https:\u002F\u002Ftalktopc.com\u002Fterms-of-service\u003Cbr \u002F>\n* Privacy Policy: https:\u002F\u002Ftalktopc.com\u002Fprivacy-agreement\u003C\u002Fp>\n","Voice AI agent for WordPress. 40+ languages, real-time conversations, 2-minute setup. Let visitors talk to your site—no typing needed.",0,382,100,1,"2026-03-24T01:15:00.000Z","6.9.4","5.0","7.4",[20,21,4,22,23],"ai-agent","chatbot","voice","voice-assistant","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Ftalktopc\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftalktopc.1.9.113.zip",null,"2026-04-16T10:56:18.058Z","no_bundle",[],{"slug":31,"display_name":7,"profile_url":8,"plugin_count":14,"total_installs":11,"avg_security_score":13,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},"yinon11",30,94,"2026-08-26T12:31:05.111Z",[36,60,78,93,109],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":13,"num_ratings":46,"last_updated":47,"tested_up_to":48,"requires_at_least":49,"requires_php":50,"tags":51,"homepage":57,"download_link":58,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":59},"vf2wp-simple-voiceflow-integration-by-tessa-ai","VF2WP – Simple Voiceflow Integration by TESSA AI","1.0.0","TESSA.tech – AI Voiceflow Integration for WordPress","https:\u002F\u002Fprofiles.wordpress.org\u002Ftessatech\u002F","\u003Cp>Add your Voiceflow AI agent into your WordPress site in minutes. VF2WP – Simple Voiceflow Integration by TESSA simplifies the process of adding a Voiceflow chatbot to WordPress.\u003Cbr \u002F>\nThis plugin offers an easy way to add interactive and intelligent chatbots to your website, improving user engagement and support.\u003C\u002Fp>\n\u003Cp>Note: This plugin connects to the external Voiceflow platform to deliver chatbot functionality. Please see the External Service Notice section for important details regarding data sent to third-party services.\u003C\u002Fp>\n\u003Cp>Key Features:\u003Cbr \u002F>\n* Seamless Integration: Connect your Voiceflow chatbot to WordPress with no code.\u003Cbr \u002F>\n* Flexible Display: Two modes—embedded inside a specific page section, or a sitewide floating chat widget.\u003Cbr \u002F>\n* Rich UI Support: Works with chat, text, cards, and other advanced chat interfaces.\u003Cbr \u002F>\n* Embed Targeting: Provide a section\u002Fdiv ID to render the bot only where that element exists; leave blank for a floating bot across the site.\u003C\u002Fp>\n\u003Cp>Development:\u003Cbr \u002F>\nVF2WP was developed by TESSA and utilized the Github repository: https:\u002F\u002Fgithub.com\u002FDanielRSnell\u002Fwordpress-voiceflow\u003C\u002Fp>\n\u003Cp>Why Choose VF2WP?\u003Cbr \u002F>\nVF2WP by TESSA provides a no-code solution to integrating your Voiceflow agent into WordPress. Focus on creating rich conversational experiences without worrying about technical details. Whether you are a small business owner improving customer service or a developer enhancing site functionality, VF2WP brings Voiceflow AI chatbots into WordPress quickly.\u003C\u002Fp>\n\u003Cp>Get Started Today:\u003Cbr \u002F>\nDownload VF2WP – Simple Voiceflow Integration by TESSA and transform your WordPress site with intelligent chatbots. Enhance user experience, provide instant support, and engage your audience.\u003C\u002Fp>\n\u003Ch3>External Service Notice\u003C\u002Fh3>\n\u003Cp>This plugin connects to the Voiceflow platform to provide chatbot integration services.\u003C\u002Fp>\n\u003Cp>Service Domains Used:\u003Cbr \u002F>\n– https:\u002F\u002Fcdn.voiceflow.com\u002F (loads Voiceflow scripts)\u003Cbr \u002F>\n– https:\u002F\u002Fgeneral-runtime.voiceflow.com\u002F (handles chatbot interactions)\u003Cbr \u002F>\n– https:\u002F\u002Fruntime-api.voiceflow.com\u002F (voice features API endpoint)\u003C\u002Fp>\n\u003Cp>What data is sent:\u003Cbr \u002F>\n– When the chatbot loads and is used, data including conversation content, a user\u002Fsession identifier, and technical interaction information are sent to Voiceflow servers.\u003Cbr \u002F>\n– No personally identifiable information is sent by default, but any content provided by users in the chatbot may be transmitted to Voiceflow.\u003C\u002Fp>\n\u003Cp>Third-party Terms and Privacy:\u003Cbr \u002F>\n– Voiceflow Privacy Policy: https:\u002F\u002Fwww.voiceflow.com\u002Fprivacy-policy\u003Cbr \u002F>\n– Voiceflow Terms of Service: https:\u002F\u002Fwww.voiceflow.com\u002Fterms\u003C\u002Fp>\n\u003Cp>By activating and using this plugin, you agree that data may be transmitted to Voiceflow as described above. Please review their policies for more information.\u003C\u002Fp>\n","Integrate Voiceflow AI chatbots into WordPress effortlessly with VF2WP by TESSA, enhancing user engagement and customer support without coding.",10,355,2,"2025-08-28T07:03:00.000Z","6.8.6","6.4","7.4.30",[52,53,54,55,56],"chatgpt","voiceflow-ai-agent-plugin","voiceflow-ai-chatbot","voiceflow-wordpress-plugin","wordpress-ai-agent","","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fvf2wp-simple-voiceflow-integration-by-tessa-ai.1.0.0.zip","2026-07-22T17:31:50.256Z",{"slug":61,"name":62,"version":63,"author":64,"author_profile":65,"description":66,"short_description":67,"active_installs":11,"downloaded":68,"rating":13,"num_ratings":14,"last_updated":69,"tested_up_to":70,"requires_at_least":17,"requires_php":18,"tags":71,"homepage":76,"download_link":77,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":59},"babelbeez-voice-ai","Babelbeez Voice AI","1.2.0","Oliver Cheung","https:\u002F\u002Fprofiles.wordpress.org\u002Folivercheung\u002F","\u003Cp>Traditional contact forms, cold callbacks, and static text chatbots lose hot leads. Human website visitors no longer have the patience to click through menus or read blocks of text—if they don’t find what they want instantly, they leave.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Babelbeez\u003C\u002Fstrong> is the ultra-low latency AI voice assistant and digital receptionist for your WordPress site. It turns your storefront into an elite, conversational experience. Visitors can speak naturally directly through their browser, receive answers trained on your business content in real time, and take immediate action—including booking live appointments—during the conversation.\u003C\u002Fp>\n\u003Cp>This is not a rigid text-based chat widget. Babelbeez is a fully fluid, human-grade voice ambassador designed to capture intent, qualify traffic, and maximize conversions 24\u002F7.\u003C\u002Fp>\n\u003Ch4>Capture the Moment of Absolute Intent\u003C\u002Fh4>\n\u003Cp>When a prospect is ready to buy or book, any delay is a lost opportunity. Babelbeez provides an intelligent frontline for your business that can:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Answer Complex Questions instantly:\u003C\u002Fstrong> Utilizing your specific services, hours, policies, and pricing context.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Qualify Visitors in Real Time:\u003C\u002Fstrong> Naturally parsing customer intent, budgets, requirements, and contact details.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automate Scheduling and Bookings:\u003C\u002Fstrong> Integrating with your favorite calendar software via the Babelbeez App Directory to check availability and schedule meetings dynamically mid-call.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Recover After-Hours Traffic:\u003C\u002Fstrong> Turning passive late-night web browsing into structured booked meetings and high-value jobs.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Give your users a fluid, voice-first alternative to clunky navigation. Move them from discovery to result in seconds.\u003C\u002Fp>\n\u003Ch4>Why Babelbeez Is Different\u003C\u002Fh4>\n\u003Col>\n\u003Cli>\n\u003Cp>\u003Cstrong>True Speech-to-Speech Conversations\u003C\u002Fstrong> Built on hyper-advanced, real-time audio streams. Visitors can speak naturally, pause, or interrupt mid-sentence. The assistant responds instantly with realistic human-like pacing and speech dynamics.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Frictionless Zero-Code Training\u003C\u002Fstrong> Simply drop your website URL into the secure Babelbeez dashboard. Our intelligent crawler maps your existing documentation, blogs, and landing pages to build an authoritative knowledge base automatically.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Autonomous Live Actions\u003C\u002Fstrong> Through the Babelbeez App Directory, your voice assistant does more than talk—it acts. Connect native apps like your calendar scheduler or booking tool, giving the agent the authority to finalize bookings live on-call.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Structured CRM & Workflow Integration\u003C\u002Fstrong> What happens after the conversation is just as important. Babelbeez synthesizes calls into structured outcomes, effortlessly syncing transcripts, captured contact fields, and summaries directly to your CRM via Zapier, Make.com, or secure webhooks.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>AI Voice Receptionist:\u003C\u002Fstrong> Deploy a premium, floating voice interface across your entire WordPress theme.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automated Client Onboarding:\u003C\u002Fstrong> Qualify leads, evaluate requirements, and collect customer profiles naturally.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Live Tool Integrations:\u003C\u002Fstrong> Connect native workflow tools through our specialized App Directory.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automated Page Crawling:\u003C\u002Fstrong> Train your AI on complex business data, local service areas, or FAQs in minutes.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-Language Detection:\u003C\u002Fstrong> Automatically senses, understands, and speaks back in the visitor’s preferred language.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Structured Data Export:\u003C\u002Fstrong> Sends clean, parseable lead summaries straight into your automation stack.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Human Handoff Safeguards:\u003C\u002Fstrong> Gracefully guides visitors to email or WhatsApp channels if a complex live human intervention is required.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Gutenberg Block & Shortcode Support:\u003C\u002Fstrong> Put the voice experience on every page sitewide, or target it surgically to specific high-intent landing pages.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>How It Works\u003C\u002Fh3>\n\u003Col>\n\u003Cli>\u003Cstrong>Install:\u003C\u002Fstrong> Click “Install Now” and activate the plugin on your WordPress site.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Connect:\u003C\u002Fstrong> Open the Babelbeez settings panel and link your secure account using your API key.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Train:\u003C\u002Fstrong> Paste your website link into your Babelbeez dashboard to build your assistant’s customized knowledge base.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Authorize Actions:\u003C\u002Fstrong> Connect your booking platforms or software via the integrated App Directory.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customize Style:\u003C\u002Fstrong> Set up your assistant’s tone, voice profile, and custom colors to align perfectly with your brand identity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Go Live:\u003C\u002Fstrong> Toggle site-wide activation or drop our custom block onto specific landing pages.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Third-Party Services\u003C\u002Fh3>\n\u003Cp>This plugin serves as a lightweight, secure connector for the cloud-based Babelbeez infrastructure. To provide high-performance audio handling, real-time context management, and external tooling actions, your site communicates directly with the following third-party services:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Cstrong>Babelbeez (https:\u002F\u002Fwww.babelbeez.com):\u003C\u002Fstrong> Orchestrates your voice configurations, knowledge base routing, App Directory bridges, and webhook delivery. Your secure API key is transmitted strictly for secure authentication.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.babelbeez.com\u002Fterms-of-service.html\" rel=\"nofollow ugc\">Terms of Service\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.babelbeez.com\u002Fprivacy-policy.html\" rel=\"nofollow ugc\">Privacy Policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>OpenAI (https:\u002F\u002Fopenai.com):\u003C\u002Fstrong> Powers the under-the-hood speech-to-speech engine. Active conversation audio streams are processed safely to maintain lightning-fast response times.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Cstrong>Your Connected Booking Provider (e.g., https:\u002F\u002Fcalendly.com):\u003C\u002Fstrong> If you actively enable appointment tools in the Babelbeez App Directory, our service securely interfaces with your scheduler to analyze open time slots and finalize calendar bookings on your behalf.\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>No consumer keys or personal data are exposed inside your local environment; your site simply stores the authorized API key and selected assistant ID in your standard options table.\u003C\u002Fp>\n\u003Ch3>Blocks\u003C\u002Fh3>\n\u003Cp>Use the custom \u003Cstrong>Babelbeez Voice Agent\u003C\u002Fstrong> block inside the block editor to render your assistant on individual posts, portfolio pieces, or high-intent checkout pages.\u003C\u002Fp>\n\u003Ch3>Shortcodes\u003C\u002Fh3>\n\u003Cp>For classic layouts or page builder environments, use our clean shortcode:\u003C\u002Fp>\n\u003Cp>Basic execution (loads your default saved profile):\u003Cbr \u002F>\n    [babelbeez_voice_ai]\u003C\u002Fp>\n\u003Cp>Targeted execution (overrides global options with a specific assistant ID):\u003Cbr \u002F>\n    [babelbeez_voice_ai id=”YOUR_CHATBOT_ID”]\u003C\u002Fp>\n","Transform your static pages into a live, real-time voice interface. Answer customer questions, qualify leads, and automate live scheduling instantly.",962,"2026-05-26T06:48:00.000Z","7.0.2",[72,73,74,75,23],"ai-chatbot","ai-receptionist","customer-support","lead-generation","https:\u002F\u002Fwww.babelbeez.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fbabelbeez-voice-ai.1.2.0.zip",{"slug":79,"name":80,"version":81,"author":82,"author_profile":83,"description":84,"short_description":85,"active_installs":11,"downloaded":86,"rating":11,"num_ratings":11,"last_updated":87,"tested_up_to":48,"requires_at_least":17,"requires_php":57,"tags":88,"homepage":91,"download_link":92,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":59},"chat-bot-alpha-interface","Chat Bot Alpha Interface","2.1.6","alphainterface","https:\u002F\u002Fprofiles.wordpress.org\u002Falphainterface\u002F","\u003Cp>\u003Cstrong>Chat Bot Alpha Interface\u003C\u002Fstrong> makes it simple to embed the \u003Ccode>\u003Chash-bot>\u003C\u002Fcode> widget directly into your WordPress site — no coding required.\u003C\u002Fp>\n\u003Cp>The plugin loads via a CDN, so you don’t have to worry about manual script embedding or performance issues. In just a few clicks, you’ll have an \u003Cstrong>AI voice chatbot\u003C\u002Fstrong> live on every page of your site, ready to engage visitors, answer questions, and capture leads.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003Cbr \u002F>\n– 🎙️ \u003Cstrong>Voice-enabled chatbot\u003C\u002Fstrong> — interactive conversations, not just text.\u003Cbr \u002F>\n– ⚡ \u003Cstrong>Lightweight & fast\u003C\u002Fstrong> — loads via CDN, minimal overhead.\u003Cbr \u002F>\n– 🎨 \u003Cstrong>Customizable design\u003C\u002Fstrong> — adjust chatbot width, height, icon size, and more.\u003Cbr \u002F>\n– 🔌 \u003Cstrong>Backend integration\u003C\u002Fstrong> — connect via Alpha Interface’s Agent UUID.\u003Cbr \u002F>\n– 🛠️ \u003Cstrong>Easy setup\u003C\u002Fstrong> — configure directly inside WordPress admin.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Admin Settings (WP Admin \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Chat Bot Alpha Interface Settings):\u003C\u002Fstrong>\u003Cbr \u002F>\n– Bot Name\u003Cbr \u002F>\n– Agent UUID\u003Cbr \u002F>\n– Welcome Message\u003Cbr \u002F>\n– Icon Size\u003Cbr \u002F>\n– Chatbot Width\u003Cbr \u002F>\n– Chatbot Height\u003C\u002Fp>\n\u003Ch3>Source Code\u003C\u002Fh3>\n\u003Cp>The uncompressed, human-readable source code for this plugin is available here:\u003Cbr \u002F>\nhttps:\u002F\u002Fgithub.com\u002Fclockhash-projects\u002Fhash-bot-fe\u003C\u002Fp>\n","Bring conversations to life with a modern AI-powered voice chatbot for WordPress. Lightweight, fast, and fully customizable.",665,"2025-09-26T11:23:00.000Z",[89,90,21,74,23],"ai","alpha-interface","https:\u002F\u002Fwww.npmjs.com\u002Fpackage\u002Falpha-interface","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fchat-bot-alpha-interface.2.1.6.zip",{"slug":94,"name":95,"version":96,"author":97,"author_profile":98,"description":99,"short_description":100,"active_installs":11,"downloaded":101,"rating":11,"num_ratings":11,"last_updated":102,"tested_up_to":103,"requires_at_least":104,"requires_php":18,"tags":105,"homepage":107,"download_link":108,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":59},"howsit","Howsit","1.0.3","howsitai","https:\u002F\u002Fprofiles.wordpress.org\u002Fhowsitai\u002F","\u003Cp>The Howsit WordPress plugin allows you to add an AI-powered Agent to your WordPress website without needing coding knowledge. It helps automate customer interactions, book appointments, and provide automated customer support and help capture leads.\u003C\u002Fp>\n\u003Ch3>Language Support\u003C\u002Fh3>\n\u003Cp>The agent supports multiple languages including:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>English\u003C\u002Fli>\n\u003Cli>French \u002F Français\u003C\u002Fli>\n\u003Cli>Spanish \u002F Español\u003C\u002Fli>\n\u003Cli>Italian \u002F Italiano\u003C\u002Fli>\n\u003Cli>German \u002F Deutsch\u003C\u002Fli>\n\u003Cli>Swedish \u002F Svenska\u003C\u002Fli>\n\u003Cli>Portuguese \u002F Português\u003C\u002Fli>\n\u003Cli>Hindi \u002F हिन्दी\u003C\u002Fli>\n\u003Cli>Japanese \u002F 日本語\u003C\u002Fli>\n\u003Cli>Russian \u002F Русский\u003C\u002Fli>\n\u003Cli>Persian \u002F فارسی\u003C\u002Fli>\n\u003Cli>Dutch \u002F Nederlands\u003C\u002Fli>\n\u003Cli>Arabic \u002F العربية\u003C\u002Fli>\n\u003Cli>Turkish \u002F Türkçe\u003C\u002Fli>\n\u003Cli>Hebrew \u002F עברית\u003C\u002Fli>\n\u003Cli>Croatian \u002F Hrvatski\u003C\u002Fli>\n\u003Cli>Albanian \u002F Shqiptare\u003C\u002Fli>\n\u003Cli>Chinese \u002F 中国人\u003C\u002Fli>\n\u003Cli>Indonesian \u002F Bahasa Indonesia\u003C\u002Fli>\n\u003Cli>Hungarian \u002F Magyar\u003C\u002Fli>\n\u003Cli>Welsh \u002F Cymraeg\u003C\u002Fli>\n\u003Cli>Chinese (Traditional) \u002F 繁體中文\u003C\u002Fli>\n\u003Cli>Polish \u002F Polski\u003C\u002Fli>\n\u003Cli>Thai \u002F ไทย\u003C\u002Fli>\n\u003Cli>Vietnamese \u002F Tiếng Việt\u003C\u002Fli>\n\u003Cli>Ukrainian \u002F Українська\u003C\u002Fli>\n\u003Cli>Romanian \u002F Română\u003C\u002Fli>\n\u003Cli>Venda \u002F Tshivenḓa\u003C\u002Fli>\n\u003Cli>Sotho \u002F Sesotho\u003C\u002Fli>\n\u003Cli>Xhosa \u002F Isixhosa\u003C\u002Fli>\n\u003Cli>Zulu \u002F Isizulu\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>This plugin relies on an external service to provide the chatbot interface and functionality. This service is offered via Content Delivery Network (CDN) at cdn.express-chat.com. By using this plugin, you enable the chatbot functionality on your website, which loads a JavaScript file (website-bot.js) from this CDN.\u003C\u002Fp>\n\u003Cp>Details of the external service:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Purpose\u003C\u002Fstrong>: To load and display the agent interface, and handle user interactions within the chat.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent\u003C\u002Fstrong>: When users interact with the agent, data related to their chat session, such as messages and possibly their IP address, may be sent.\u003C\u002Fli>\n\u003C\u002Ful>\n","Adds an AI-powered Agent to your WordPress site for customer interaction, lead capture, and support.",217,"2026-03-27T08:28:00.000Z","6.9.5","4.2",[89,20,21,52,106],"voice-agent","https:\u002F\u002Fhowsit.ai\u002Fwordpress\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhowsit.1.0.3.zip",{"slug":110,"name":111,"version":112,"author":113,"author_profile":114,"description":115,"short_description":116,"active_installs":11,"downloaded":117,"rating":11,"num_ratings":11,"last_updated":118,"tested_up_to":70,"requires_at_least":119,"requires_php":18,"tags":120,"homepage":123,"download_link":124,"security_score":13,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":59},"studiometa-voice-ai","StudioMeta Voice AI","1.3.82","stdmeta","https:\u002F\u002Fprofiles.wordpress.org\u002Fstdmeta\u002F","\u003Cp>\u003Cstrong>StudioMeta Voice AI\u003C\u002Fstrong> adds a natural, conversational voice and chat assistant to your WordPress site. Visitors can have a real spoken conversation with an AI agent trained on your content, or chat by typing — all from a small floating widget.\u003C\u002Fp>\n\u003Cp>The assistant understands context, answers in multiple languages, and can be customized to match your brand.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Every install includes a free trial — no signup, no credit card required.\u003C\u002Fstrong> Click “Start Free Trial” in the admin panel to activate 30 voice minutes and 100 chat messages before deciding on a paid plan.\u003C\u002Fp>\n\u003Ch4>Why StudioMeta Voice AI?\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Real voice, not just text\u003C\u002Fstrong> — most WordPress chatbot plugins only type back; your visitors can actually talk to this one and hear a spoken reply\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No API key to manage\u003C\u002Fstrong> — the AI runs on our hosted infrastructure, so there’s nothing to sign up for or configure outside this plugin\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No coding required\u003C\u002Fstrong> — install, click Start Free Trial, and the widget is live\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Try before you buy\u003C\u002Fstrong> — 30 voice minutes and 100 chat messages, no credit card\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Key features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>\u003Cstrong>Voice conversations\u003C\u002Fstrong> — visitors talk to your AI agent, the agent talks back (real-time, streaming)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Text chat\u003C\u002Fstrong> — classic chat widget for visitors who prefer typing\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-language\u003C\u002Fstrong> — English, Persian (فارسی), Arabic, French, Spanish, and more\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Knowledge base import\u003C\u002Fstrong> — auto-crawl your site to train the agent on your content\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Customizable widget\u003C\u002Fstrong> — color, position (bottom-left\u002Fright), style (FAB or pill)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Suggested questions\u003C\u002Fstrong> — chips that prompt visitors with common questions\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Agent customization\u003C\u002Fstrong> — name, voice, response style, system prompt, timezone\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Custom tools\u003C\u002Fstrong> — connect your agent to external APIs via webhooks (n8n, Make, Zapier)\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Usage dashboard\u003C\u002Fstrong> — see voice minutes used, sessions, and remaining quota\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Smart fallback\u003C\u002Fstrong> — when one quota is exhausted, the other stays available\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How the trial works\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Activate the plugin, then click \u003Cstrong>Start Free Trial\u003C\u002Fstrong> in the admin panel\u003C\u002Fli>\n\u003Cli>Use 30 voice minutes and 100 chat messages on real visitor conversations\u003C\u002Fli>\n\u003Cli>When the voice quota is exhausted, the chat widget keeps working (and vice versa)\u003C\u002Fli>\n\u003Cli>When both are exhausted, the widget shows an upgrade button linking to our pricing page\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Upgrading to a paid plan\u003C\u002Fh4>\n\u003Cp>If you want unlimited or higher quotas, visit \u003Ca href=\"https:\u002F\u002Fstudiometa.io\u002Fpricing\u002F\" rel=\"nofollow ugc\">studiometa.io\u002Fpricing\u003C\u002Fa>. After purchase, your widget reactivates automatically within 5 minutes — no need to copy and paste a license key.\u003C\u002Fp>\n\u003Ch3>External services\u003C\u002Fh3>\n\u003Cp>\u003Cstrong>This plugin connects to external services provided by StudioMeta to function.\u003C\u002Fstrong> This is required because the plugin is an interface to a hosted AI assistant. The following services are used:\u003C\u002Fp>\n\u003Ch4>1. StudioMeta Voice AI API (api2.studiometa.io)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>What it does:\u003C\u002Fstrong> Hosts the AI agent. Handles license validation, quota tracking, knowledge base storage, agent configuration, voice\u002Fchat session orchestration, and dashboard analytics.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When it is contacted:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>On plugin activation: to issue a free trial license (sends site URL, admin email, business name, site fingerprint, WordPress version, plugin version, language preference)\u003C\u002Fli>\n\u003Cli>When you save settings or agent configuration: to sync your changes to the hosted agent\u003C\u002Fli>\n\u003Cli>When you click “Import KB from Website”: to crawl your public pages and build a knowledge base\u003C\u002Fli>\n\u003Cli>When you click “Optimize with AI”: to improve your system prompt\u003C\u002Fli>\n\u003Cli>When the admin Dashboard loads: to fetch usage statistics\u003C\u002Fli>\n\u003Cli>Every 5 minutes (cached): to check current quota status (decides whether the widget shows voice, chat, both, or an upgrade button)\u003C\u002Fli>\n\u003Cli>When a visitor uses the voice or chat widget: a WebSocket connection is opened to \u003Ccode>wss:\u002F\u002Fapi2.studiometa.io\u002Fvoice\u003C\u002Fcode> to stream audio and messages\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Data sent:\u003C\u002Fstrong> site URL, admin email, business name, your custom agent configuration (name, voice, system prompt, knowledge base text, suggested questions, custom tools), and during sessions: visitor audio and chat messages (processed only for the duration of the conversation).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data NOT sent:\u003C\u002Fstrong> WordPress user passwords, post content (unless you explicitly import it via “Import KB”), visitor IP addresses, visitor names or accounts.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Service homepage: \u003Ca href=\"https:\u002F\u002Fstudiometa.io\" rel=\"nofollow ugc\">https:\u002F\u002Fstudiometa.io\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Terms of Service: \u003Ca href=\"https:\u002F\u002Fstudiometa.io\u002Fterms\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fstudiometa.io\u002Fterms\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Privacy Policy: \u003Ca href=\"https:\u002F\u002Fstudiometa.io\u002Fprivacy-policy-2\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fstudiometa.io\u002Fprivacy-policy-2\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>2. StudioMeta Workflow Webhooks (n8n.studiometa.io)\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>What it does:\u003C\u002Fstrong> Sends transactional emails (welcome email on activation, license key email after purchase, usage alerts at 80% and 100%, monthly usage report).\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When it is contacted:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Once on plugin activation: to trigger the welcome email\u003C\u002Fli>\n\u003Cli>When usage thresholds are crossed (server-side): to trigger usage alert emails\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Data sent:\u003C\u002Fstrong> admin email, site URL, business name, current plan, usage percentages.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Service homepage: \u003Ca href=\"https:\u002F\u002Fstudiometa.io\" rel=\"nofollow ugc\">https:\u002F\u002Fstudiometa.io\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Terms of Service: \u003Ca href=\"https:\u002F\u002Fstudiometa.io\u002Fterms\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fstudiometa.io\u002Fterms\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Privacy Policy: \u003Ca href=\"https:\u002F\u002Fstudiometa.io\u002Fprivacy-policy-2\u002F\" rel=\"nofollow ugc\">https:\u002F\u002Fstudiometa.io\u002Fprivacy-policy-2\u002F\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>3. HubSpot (api.hubapi.com) — optional, only if you connect it\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>What it does:\u003C\u002Fstrong> Syncs leads captured by the voice\u002Fchat widget (name, email, phone, notes) into your own HubSpot CRM as contacts.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When it is contacted:\u003C\u002Fstrong> Only if you explicitly connect HubSpot under \u003Cstrong>Voice AI \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Integrations\u003C\u002Fstrong> by entering your own HubSpot Private App Token. If you never connect it, the plugin never contacts HubSpot.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>When you click “Connect”: one test request to \u003Ccode>api.hubapi.com\u003C\u002Fcode> to verify your token\u003C\u002Fli>\n\u003Cli>When the widget captures a lead: the lead’s name, email, phone, and notes are sent to \u003Ccode>api.hubapi.com\u003C\u002Fcode> to create\u002Fupdate a contact in \u003Cstrong>your\u003C\u002Fstrong> HubSpot account\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Data sent:\u003C\u002Fstrong> your HubSpot Private App Token (stored in your WordPress database, sent only to HubSpot), and captured lead fields (name, email, phone, notes).\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Service homepage: \u003Ca href=\"https:\u002F\u002Fwww.hubspot.com\" rel=\"nofollow ugc\">https:\u002F\u002Fwww.hubspot.com\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Terms of Service: \u003Ca href=\"https:\u002F\u002Flegal.hubspot.com\u002Fterms-of-service\" rel=\"nofollow ugc\">https:\u002F\u002Flegal.hubspot.com\u002Fterms-of-service\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Privacy Policy: \u003Ca href=\"https:\u002F\u002Flegal.hubspot.com\u002Fprivacy-policy\" rel=\"nofollow ugc\">https:\u002F\u002Flegal.hubspot.com\u002Fprivacy-policy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>4. Google Gemini Live (indirectly, via api2.studiometa.io)\u003C\u002Fh4>\n\u003Cp>The AI capabilities are powered by Google’s Gemini Live API. The plugin does \u003Cstrong>not\u003C\u002Fstrong> contact Google directly — all requests go through \u003Ccode>api2.studiometa.io\u003C\u002Fcode>, which forwards them to Google. You do not need a Google account or API key.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Google Gemini Terms: \u003Ca href=\"https:\u002F\u002Fai.google.dev\u002Fterms\" rel=\"nofollow ugc\">https:\u002F\u002Fai.google.dev\u002Fterms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>Google Privacy Policy: \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>How to opt out\u003C\u002Fh4>\n\u003Cp>If you do not want the plugin to contact these services, simply deactivate and uninstall the plugin. The plugin cannot function without the hosted services because the AI assistant runs on our infrastructure (similar to how an Akismet plugin needs the Akismet service, or a Mailchimp plugin needs Mailchimp).\u003C\u002Fp>\n\u003Ch3>Source Code\u003C\u002Fh3>\n\u003Cp>The full source code of this plugin, including the unminified version of widget.js and all build tools, is publicly available on GitHub:\u003C\u002Fp>\n\u003Cp>https:\u002F\u002Fgithub.com\u002FPejvak2001\u002Fstudiometa-voice-ai\u003C\u002Fp>\n","AI voice & chat widget for your site. Free trial included: 30 voice minutes + 100 chat messages, no credit card required.",179,"2026-07-22T04:52:00.000Z","6.0",[72,121,21,122,23],"chat-widget","live-chat","https:\u002F\u002Fstudiometa.io\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fstudiometa-voice-ai.1.3.82.zip",{"attackSurface":126,"codeSignals":301,"taintFlows":325,"riskAssessment":485,"analyzedAt":496},{"hooks":127,"ajaxHandlers":231,"restRoutes":297,"shortcodes":298,"cronEvents":299,"entryPointCount":236,"unprotectedCount":300},[128,134,138,143,147,151,155,159,162,166,169,172,175,178,181,184,187,190,193,196,199,203,207,211,216,220,223,225,229],{"type":129,"name":130,"callback":131,"priority":14,"file":132,"line":133},"action","admin_head","closure","includes\\admin-page.php",26,{"type":129,"name":135,"callback":136,"file":132,"line":137},"admin_notices","settings_errors",33,{"type":129,"name":139,"callback":140,"file":141,"line":142},"admin_enqueue_scripts","talktopc_enqueue_agent_settings_styles","includes\\admin-pages\\dashboard.php",721,{"type":129,"name":139,"callback":144,"file":145,"line":146},"talktopc_enqueue_common_scripts","includes\\admin-scripts\\common.js.php",90,{"type":129,"name":139,"callback":148,"file":149,"line":150},"talktopc_enqueue_dashboard_scripts","includes\\admin-scripts\\dashboard.js.php",1071,{"type":129,"name":139,"callback":152,"file":153,"line":154},"talktopc_enqueue_page_rules_scripts","includes\\admin-scripts\\page-rules.js.php",340,{"type":129,"name":156,"callback":131,"file":157,"line":158},"admin_menu","includes\\admin-settings.php",17,{"type":129,"name":160,"callback":131,"file":157,"line":161},"admin_init",37,{"type":129,"name":163,"callback":164,"priority":44,"file":157,"line":165},"update_option_talktopc_override_prompt","talktopc_sync_agent_to_backend",393,{"type":129,"name":167,"callback":164,"priority":44,"file":157,"line":168},"update_option_talktopc_override_first_message",394,{"type":129,"name":170,"callback":164,"priority":44,"file":157,"line":171},"update_option_talktopc_override_voice",395,{"type":129,"name":173,"callback":164,"priority":44,"file":157,"line":174},"update_option_talktopc_override_voice_speed",396,{"type":129,"name":176,"callback":164,"priority":44,"file":157,"line":177},"update_option_talktopc_override_language",397,{"type":129,"name":179,"callback":164,"priority":44,"file":157,"line":180},"update_option_talktopc_override_temperature",398,{"type":129,"name":182,"callback":164,"priority":44,"file":157,"line":183},"update_option_talktopc_override_max_tokens",399,{"type":129,"name":185,"callback":164,"priority":44,"file":157,"line":186},"update_option_talktopc_override_max_call_duration",400,{"type":129,"name":188,"callback":164,"priority":44,"file":157,"line":189},"update_option_talktopc_record_call",401,{"type":129,"name":191,"callback":164,"priority":44,"file":157,"line":192},"update_option_talktopc_enable_leave_message",402,{"type":129,"name":194,"callback":164,"priority":44,"file":157,"line":195},"update_option_talktopc_enable_visual_tools",403,{"type":129,"name":197,"callback":164,"priority":44,"file":157,"line":198},"update_option_talktopc_visual_tools_selection",404,{"type":129,"name":139,"callback":200,"file":201,"line":202},"talktopc_enqueue_admin_styles","includes\\admin-styles.php",1566,{"type":129,"name":204,"callback":131,"file":205,"line":206},"wp_enqueue_scripts","includes\\frontend-widget.php",15,{"type":129,"name":156,"callback":131,"priority":208,"file":209,"line":210},999,"includes\\migration.php",302,{"type":129,"name":212,"callback":213,"file":214,"line":215},"admin_post_talktopc_connect","talktopc_handle_connect","includes\\oauth.php",25,{"type":217,"name":218,"callback":131,"file":214,"line":219},"filter","allowed_redirect_hosts",58,{"type":129,"name":160,"callback":221,"file":214,"line":222},"talktopc_handle_oauth_callback",72,{"type":129,"name":160,"callback":131,"file":214,"line":224},347,{"type":129,"name":160,"callback":226,"file":227,"line":228},"talktopc_check_and_run_migration","talktopc.php",56,{"type":129,"name":135,"callback":131,"file":227,"line":230},107,[232,237,240,243,246,249,252,254,256,259,263,267,270,272,275,278,282,285,288,291,294],{"action":233,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":236},"talktopc_fetch_agents",false,"includes\\ajax-handlers.php",21,{"action":238,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":239},"talktopc_fetch_voices",52,{"action":241,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":242},"talktopc_fetch_credits",83,{"action":244,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":245},"talktopc_get_setup_status",116,{"action":247,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":248},"talktopc_create_agent",137,{"action":250,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":251},"talktopc_update_agent",228,{"action":253,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":154},"talktopc_generate_prompt",{"action":255,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":195},"talktopc_save_agent_selection",{"action":257,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":258},"talktopc_save_agent_settings_local",426,{"action":260,"nopriv":234,"callback":260,"hasNonce":261,"hasCapCheck":261,"file":235,"line":262},"talktopc_dismiss_feature_banner",true,488,{"action":264,"nopriv":234,"callback":265,"hasNonce":261,"hasCapCheck":261,"file":235,"line":266},"talktopc_review_action","talktopc_handle_review_action",506,{"action":268,"nopriv":234,"callback":268,"hasNonce":261,"hasCapCheck":234,"file":235,"line":269},"talktopc_get_signed_url",603,{"action":268,"nopriv":261,"callback":268,"hasNonce":261,"hasCapCheck":234,"file":235,"line":271},604,{"action":273,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":274},"talktopc_get_pages_list",676,{"action":276,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":277},"talktopc_save_page_rules",712,{"action":279,"nopriv":234,"callback":280,"hasNonce":261,"hasCapCheck":261,"file":235,"line":281},"talktopc_auto_setup_agent","talktopc_ajax_auto_setup_agent",725,{"action":283,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":284},"talktopc_test_handler",730,{"action":286,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":287},"talktopc_save_widget_customization",748,{"action":289,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":290},"talktopc_save_widget_customization2",992,{"action":292,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":293},"talktopc_get_widget_config",1194,{"action":295,"nopriv":234,"callback":131,"hasNonce":234,"hasCapCheck":234,"file":235,"line":296},"talktopc_save_ecommerce",1513,[],[],[],16,{"dangerousFunctions":302,"sqlUsage":303,"outputEscaping":313,"fileOperations":14,"externalRequests":322,"nonceChecks":133,"capabilityChecks":323,"bundledLibraries":324},[],{"prepared":304,"raw":305,"locations":306},5,3,[307,309,311],{"file":209,"line":219,"context":308},"$wpdb->get_results() with variable interpolation",{"file":209,"line":310,"context":308},79,{"file":209,"line":312,"context":308},357,{"escaped":314,"rawEcho":305,"locations":315},380,[316,319,321],{"file":141,"line":317,"context":318},430,"raw output",{"file":235,"line":320,"context":318},974,{"file":209,"line":317,"context":318},11,22,[],[326,420,449,465,476],{"entryPoint":327,"graph":328,"unsanitizedCount":11,"severity":419},"\u003Cajax-handlers> (includes\\ajax-handlers.php:0)",{"nodes":329,"edges":407},[330,335,341,345,350,354,356,360,362,366,368,372,374,378,380,384,386,390,392,396,398,402],{"id":331,"type":332,"label":333,"file":235,"line":334},"n0","source","$_POST",236,{"id":336,"type":337,"label":338,"file":235,"line":339,"wp_function":340},"n1","sink","wp_remote_request() [SSRF]",316,"wp_remote_request",{"id":342,"type":332,"label":343,"file":235,"line":344},"n2","$_POST (x11)",409,{"id":346,"type":337,"label":347,"file":235,"line":348,"wp_function":349},"n3","update_option() [Settings Manipulation]",417,"update_option",{"id":351,"type":332,"label":352,"file":235,"line":353},"n4","$_POST['system_prompt']",434,{"id":355,"type":337,"label":347,"file":235,"line":353,"wp_function":349},"n5",{"id":357,"type":332,"label":358,"file":235,"line":359},"n6","$_POST['first_message']",437,{"id":361,"type":337,"label":347,"file":235,"line":359,"wp_function":349},"n7",{"id":363,"type":332,"label":364,"file":235,"line":365},"n8","$_POST['voice_id']",440,{"id":367,"type":337,"label":347,"file":235,"line":365,"wp_function":349},"n9",{"id":369,"type":332,"label":370,"file":235,"line":371},"n10","$_POST['voice_speed']",443,{"id":373,"type":337,"label":347,"file":235,"line":371,"wp_function":349},"n11",{"id":375,"type":332,"label":376,"file":235,"line":377},"n12","$_POST['language']",446,{"id":379,"type":337,"label":347,"file":235,"line":377,"wp_function":349},"n13",{"id":381,"type":332,"label":382,"file":235,"line":383},"n14","$_POST['temperature']",449,{"id":385,"type":337,"label":347,"file":235,"line":383,"wp_function":349},"n15",{"id":387,"type":332,"label":388,"file":235,"line":389},"n16","$_POST['max_tokens']",452,{"id":391,"type":337,"label":347,"file":235,"line":389,"wp_function":349},"n17",{"id":393,"type":332,"label":394,"file":235,"line":395},"n18","$_POST['max_call_duration']",455,{"id":397,"type":337,"label":347,"file":235,"line":395,"wp_function":349},"n19",{"id":399,"type":332,"label":400,"file":235,"line":401},"n20","$_POST (x2)",871,{"id":403,"type":337,"label":404,"file":235,"line":405,"wp_function":406},"n21","call_user_func() [RCE]",923,"call_user_func",[408,409,410,411,412,413,414,415,416,417,418],{"from":331,"to":336,"sanitized":261},{"from":342,"to":346,"sanitized":261},{"from":351,"to":355,"sanitized":261},{"from":357,"to":361,"sanitized":261},{"from":363,"to":367,"sanitized":261},{"from":369,"to":373,"sanitized":261},{"from":375,"to":379,"sanitized":261},{"from":381,"to":385,"sanitized":261},{"from":387,"to":391,"sanitized":261},{"from":393,"to":397,"sanitized":261},{"from":399,"to":403,"sanitized":261},"low",{"entryPoint":421,"graph":422,"unsanitizedCount":14,"severity":419},"talktopc_render_migration_page (includes\\migration.php:318)",{"nodes":423,"edges":444},[424,427,431,434,437,439,442],{"id":331,"type":332,"label":425,"file":209,"line":426},"$_GET",344,{"id":336,"type":337,"label":428,"file":209,"line":429,"wp_function":430},"get_var() [SQLi]",350,"get_var",{"id":342,"type":332,"label":432,"file":209,"line":433},"$_POST (x3)",384,{"id":346,"type":337,"label":435,"file":209,"line":192,"wp_function":436},"echo() [XSS]","echo",{"id":351,"type":332,"label":333,"file":209,"line":438},386,{"id":355,"type":440,"label":441,"file":209,"line":438},"transform","→ talktopc_migrate_from_json()",{"id":357,"type":337,"label":347,"file":209,"line":443,"wp_function":349},285,[445,446,447,448],{"from":331,"to":336,"sanitized":261},{"from":342,"to":346,"sanitized":261},{"from":351,"to":355,"sanitized":234},{"from":355,"to":357,"sanitized":234},{"entryPoint":450,"graph":451,"unsanitizedCount":14,"severity":419},"\u003Cmigration> (includes\\migration.php:0)",{"nodes":452,"edges":460},[453,454,455,456,457,458,459],{"id":331,"type":332,"label":425,"file":209,"line":426},{"id":336,"type":337,"label":428,"file":209,"line":429,"wp_function":430},{"id":342,"type":332,"label":432,"file":209,"line":433},{"id":346,"type":337,"label":435,"file":209,"line":192,"wp_function":436},{"id":351,"type":332,"label":333,"file":209,"line":438},{"id":355,"type":440,"label":441,"file":209,"line":438},{"id":357,"type":337,"label":347,"file":209,"line":443,"wp_function":349},[461,462,463,464],{"from":331,"to":336,"sanitized":261},{"from":342,"to":346,"sanitized":261},{"from":351,"to":355,"sanitized":234},{"from":355,"to":357,"sanitized":234},{"entryPoint":466,"graph":467,"unsanitizedCount":11,"severity":419},"talktopc_handle_oauth_callback (includes\\oauth.php:74)",{"nodes":468,"edges":474},[469,472],{"id":331,"type":332,"label":470,"file":214,"line":471},"$_GET (x3)",95,{"id":336,"type":337,"label":347,"file":214,"line":473,"wp_function":349},115,[475],{"from":331,"to":336,"sanitized":261},{"entryPoint":477,"graph":478,"unsanitizedCount":11,"severity":419},"\u003Coauth> (includes\\oauth.php:0)",{"nodes":479,"edges":483},[480,482],{"id":331,"type":332,"label":481,"file":214,"line":471},"$_GET (x5)",{"id":336,"type":337,"label":347,"file":214,"line":473,"wp_function":349},[484],{"from":331,"to":336,"sanitized":261},{"summary":486,"deductions":487},"The 'talktopc' plugin v1.9.112 presents a mixed security posture. On the positive side, it demonstrates excellent practices in output escaping, with 99% of outputs being properly escaped, and a healthy number of nonce and capability checks are in place.  Furthermore, the plugin has no recorded vulnerability history (CVEs), suggesting a relatively stable and well-maintained codebase.\n\nHowever, significant concerns arise from the substantial attack surface exposed through AJAX handlers. A large proportion (16 out of 21) of these handlers lack authentication checks, creating a direct pathway for unauthorized actions if exploited. While the taint analysis did not reveal critical or high-severity unsanitized flows, the presence of two flows with unsanitized paths warrants caution, especially when combined with the unprotected AJAX endpoints. The plugin also performs external HTTP requests, which, while common, can be a vector for vulnerabilities if not handled securely.\n\nIn conclusion, the plugin's strengths lie in its output sanitization and lack of historical vulnerabilities. The primary weakness is the significant number of unprotected AJAX entry points, which represent a considerable risk.  While critical code-level vulnerabilities are not immediately apparent from the static analysis and taint data, the potential for exploitation through the exposed AJAX handlers is the most pressing concern.",[488,491,494],{"reason":489,"points":490},"Large attack surface without auth",8,{"reason":492,"points":493},"Flows with unsanitized paths",6,{"reason":495,"points":46},"External HTTP requests","2026-03-17T06:05:38.030Z",{"wat":498,"direct":509},{"assetPaths":499,"generatorPatterns":503,"scriptPaths":505,"versionParams":506},[500,501,502],"\u002Fwp-content\u002Fplugins\u002Ftalktopc\u002Fassets\u002Fcss\u002Ftalktopc-frontend.css","\u002Fwp-content\u002Fplugins\u002Ftalktopc\u002Fassets\u002Fjs\u002Ftalktopc-frontend.js","\u002Fwp-content\u002Fplugins\u002Ftalktopc\u002Fassets\u002Fjs\u002Fvendor\u002Fmarked.min.js",[504],"TalkToPC Voice Widget 1.9.112",[501],[507,508],"talktopc-frontend.css?ver=","talktopc-frontend.js?ver=",{"cssClasses":510,"htmlComments":517,"htmlAttributes":518,"restEndpoints":522,"jsGlobals":524,"shortcodeOutput":526},[511,512,513,514,515,516],"talktopc-widget-wrapper","talktopc-widget-container","talktopc-button","talktopc-header","talktopc-message-bubble-user","talktopc-message-bubble-agent",[],[519,520,521],"data-talktopc-api-url","data-talktopc-app-id","data-talktopc-agent-id",[523],"\u002Fwp-json\u002Ftalktopc\u002Fv1\u002Fsend_message",[525],"TalkToPCFrontend",[527],"[talktopc_chat_widget]",{"error":261,"url":529,"statusCode":198,"statusMessage":530,"message":530},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Ftalktopc\u002Fbundle","no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":493,"versions":532},[533,538,545,552,559,566],{"version":6,"download_url":25,"svn_tag_url":534,"released_at":26,"has_diff":234,"diff_files_changed":535,"diff_lines":26,"trac_diff_url":536,"vulnerabilities":537,"is_current":261},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftalktopc\u002Ftags\u002F1.9.113\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Ftalktopc%2Ftags%2F1.9.112&new_path=%2Ftalktopc%2Ftags%2F1.9.113",[],{"version":539,"download_url":540,"svn_tag_url":541,"released_at":26,"has_diff":234,"diff_files_changed":542,"diff_lines":26,"trac_diff_url":543,"vulnerabilities":544,"is_current":234},"1.9.112","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftalktopc.1.9.112.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftalktopc\u002Ftags\u002F1.9.112\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Ftalktopc%2Ftags%2F1.9.111&new_path=%2Ftalktopc%2Ftags%2F1.9.112",[],{"version":546,"download_url":547,"svn_tag_url":548,"released_at":26,"has_diff":234,"diff_files_changed":549,"diff_lines":26,"trac_diff_url":550,"vulnerabilities":551,"is_current":234},"1.9.111","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftalktopc.1.9.111.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftalktopc\u002Ftags\u002F1.9.111\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Ftalktopc%2Ftags%2F1.9.108&new_path=%2Ftalktopc%2Ftags%2F1.9.111",[],{"version":553,"download_url":554,"svn_tag_url":555,"released_at":26,"has_diff":234,"diff_files_changed":556,"diff_lines":26,"trac_diff_url":557,"vulnerabilities":558,"is_current":234},"1.9.108","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftalktopc.1.9.108.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftalktopc\u002Ftags\u002F1.9.108\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Ftalktopc%2Ftags%2F1.9.97&new_path=%2Ftalktopc%2Ftags%2F1.9.108",[],{"version":560,"download_url":561,"svn_tag_url":562,"released_at":26,"has_diff":234,"diff_files_changed":563,"diff_lines":26,"trac_diff_url":564,"vulnerabilities":565,"is_current":234},"1.9.97","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftalktopc.1.9.97.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftalktopc\u002Ftags\u002F1.9.97\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Ftalktopc%2Ftags%2F1.9.79&new_path=%2Ftalktopc%2Ftags%2F1.9.97",[],{"version":567,"download_url":568,"svn_tag_url":569,"released_at":26,"has_diff":234,"diff_files_changed":570,"diff_lines":26,"trac_diff_url":26,"vulnerabilities":571,"is_current":234},"1.9.79","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Ftalktopc.1.9.79.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Ftalktopc\u002Ftags\u002F1.9.79\u002F",[],[]]