UltraPress – AI Assistant, Chatbot & SEO Security & Risk Analysis

wordpress.org/plugins/ultrapress

The AI Brain for your WordPress site. Engage visitors with a smart chatbot and enhance your SEO with AI-powered tools.

1K active installs v3.0.1 PHP 7.4+ WP 5.8+ Updated Sep 25, 2025
aiassistantchatbotmarketingseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is UltraPress – AI Assistant, Chatbot & SEO Safe to Use in 2026?

Generally Safe

Score 100/100

UltraPress – AI Assistant, Chatbot & SEO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The ultrapress plugin v3.0.1 presents a mixed security posture. While it shows strengths in avoiding dangerous functions, file operations, and having a clean vulnerability history with no known CVEs, significant concerns arise from its attack surface and data handling. The presence of three AJAX handlers without authentication checks is a critical vulnerability, as it exposes these entry points to unauthorized access and potential exploitation. Furthermore, all SQL queries are executed without prepared statements, increasing the risk of SQL injection vulnerabilities, especially when combined with unsanitized input which is not explicitly ruled out by the taint analysis (though the analysis found no issues, it's a common place for such vulnerabilities to hide).

Despite a strong percentage of output escaping (87%), the unprotected AJAX endpoints and the complete lack of prepared statements for SQL queries are substantial weaknesses. The absence of any recorded vulnerabilities in its history is a positive sign, suggesting a potentially proactive development team or a lack of past scrutiny. However, this should not overshadow the immediate risks identified in the current code analysis. The plugin exhibits a concerning lack of security best practices in key areas, demanding immediate attention to mitigate the identified risks.

Key Concerns

  • AJAX handlers without auth checks
  • SQL queries without prepared statements
Vulnerabilities
None known

UltraPress – AI Assistant, Chatbot & SEO Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

UltraPress – AI Assistant, Chatbot & SEO Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
0 prepared
Unescaped Output
11
74 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared3 total queries

Output Escaping

87% escaped85 total outputs
Attack Surface
3 unprotected

UltraPress – AI Assistant, Chatbot & SEO Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_ultrapress_send_messageincludes\class-ultrapress-main.php:46
noprivwp_ajax_ultrapress_send_messageincludes\class-ultrapress-main.php:47
authwp_ajax_ultrapress_generate_seo_metaincludes\class-ultrapress-seo.php:45
WordPress Hooks 9
actioninitincludes\class-ultrapress-main.php:39
actionwp_enqueue_scriptsincludes\class-ultrapress-main.php:43
actionwp_footerincludes\class-ultrapress-main.php:44
actionadd_meta_boxesincludes\class-ultrapress-seo.php:40
actionsave_postincludes\class-ultrapress-seo.php:41
actionadmin_enqueue_scriptsincludes\class-ultrapress-seo.php:42
actionadmin_menuincludes\class-ultrapress-settings.php:25
actionadmin_initincludes\class-ultrapress-settings.php:26
actionadmin_enqueue_scriptsincludes\class-ultrapress-settings.php:27
Maintenance & Trust

UltraPress – AI Assistant, Chatbot & SEO Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 25, 2025
PHP min version7.4
Downloads65K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

UltraPress – AI Assistant, Chatbot & SEO Developer Profile

meedawi

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect UltraPress – AI Assistant, Chatbot & SEO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ultrapress/assets/css/style.css/wp-content/plugins/ultrapress/assets/css/themes.css/wp-content/plugins/ultrapress/assets/js/lib/marked.min.js/wp-content/plugins/ultrapress/assets/js/chatbot.js/wp-content/plugins/ultrapress/assets/js/admin-meta-box.js
Script Paths
/wp-content/plugins/ultrapress/assets/js/lib/marked.min.js/wp-content/plugins/ultrapress/assets/js/chatbot.js/wp-content/plugins/ultrapress/assets/js/admin-meta-box.js
Version Parameters
ultrapress/style.css?ver=ultrapress/themes.css?ver=marked.min.js?ver=chatbot.js?ver=admin-meta-box.js?ver=

HTML / DOM Fingerprints

CSS Classes
ultrapress-theme-custom
Data Attributes
data-noncedata-ajaxurldata-welcome-messagedata-error-generaldata-error-connection
JS Globals
ultrapressData
REST Endpoints
/wp-json/ultrapress/v1/generate-seo-meta
FAQ

Frequently Asked Questions about UltraPress – AI Assistant, Chatbot & SEO