ChatBot for eCommerce – WoowBot Security & Risk Analysis

wordpress.org/plugins/woowbot-woocommerce-chatbot

ChatBot for WooCommerce. Simple & native WooCommerce ChatBot helps shoppers find products easily & Increase Sales! AI, ChatGPT available with PRO

1K active installs v4.5.4 PHP 7.4+ WP 4.9+ Updated Mar 11, 2026
botchatbotlive-chatwoocommercewoocommerce-chatbot
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ChatBot for eCommerce – WoowBot Safe to Use in 2026?

Generally Safe

Score 100/100

ChatBot for eCommerce – WoowBot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 23d ago
Risk Assessment

The "woowbot-woocommerce-chatbot" plugin v4.5.4 exhibits a generally good security posture due to its extensive use of prepared statements for SQL queries and proper output escaping. The absence of known vulnerabilities and a clean taint analysis report are positive indicators. However, a significant concern lies in the substantial attack surface exposed through AJAX handlers, with a large proportion (8 out of 11) lacking authentication checks. This creates a potential entry point for attackers to trigger plugin functionality without proper authorization.

The presence of the "unserialize" function, while not directly exploited in the analyzed flows, represents a common vector for code injection vulnerabilities if user-controlled data is passed to it without strict validation. While the plugin demonstrates good practices in other areas, the unprotected AJAX endpoints are a notable weakness that could be exploited in conjunction with other vulnerabilities or misconfigurations.

Overall, the plugin benefits from a clean vulnerability history, suggesting a commitment to security from its developers. However, the significant number of unprotected AJAX handlers and the use of unserialize warrant attention. Addressing these points would substantially strengthen the plugin's security. The strengths in SQL handling and output escaping are commendable, but the identified weaknesses detract from an otherwise solid security profile.

Key Concerns

  • High number of unprotected AJAX handlers
  • Use of dangerous function (unserialize)
Vulnerabilities
None known

ChatBot for eCommerce – WoowBot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ChatBot for eCommerce – WoowBot Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
0 prepared
Unescaped Output
10
445 escaped
Nonce Checks
4
Capability Checks
19
File Operations
0
External Requests
0
Bundled Libraries
1

Dangerous Functions Found

unserialize$wp_chatbot_select_pages = unserialize(get_option('wp_chatbot_show_pages_list'));functions.php:235
unserialize$wp_chatbot_select_pages = unserialize(get_option('wp_chatbot_show_pages_list'));qcld-woowbot.php:484

Bundled Libraries

jQuery

Output Escaping

98% escaped455 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
goodbye_form_callback (class-plugin-deactivate-feedback.php:411)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

ChatBot for eCommerce – WoowBot Attack Surface

Entry Points11
Unprotected8

AJAX Handlers 11

authwp_ajax_goodbye_formclass-plugin-deactivate-feedback.php:62
authwp_ajax_qcld_woo_chatbot_keywordfunctions.php:81
noprivwp_ajax_qcld_woo_chatbot_keywordfunctions.php:82
authwp_ajax_qcld_woo_chatbot_categoryfunctions.php:139
noprivwp_ajax_qcld_woo_chatbot_categoryfunctions.php:140
authwp_ajax_qcld_woo_chatbot_category_productsfunctions.php:156
noprivwp_ajax_qcld_woo_chatbot_category_productsfunctions.php:157
authwp_ajax_qcld_woo_chatbot_emailfunctions.php:318
noprivwp_ajax_qcld_woo_chatbot_emailfunctions.php:319
authwp_ajax_qcld_wpbot_free_process_qc_promo_formqc-support-promo-page\class-qc-support-promo-page.php:143
authwp_ajax_qcld_recommend_support_function_ajaxqc-support-promo-page\qc-clr-recommendbot-support-plugin.php:8
WordPress Hooks 17
actionadmin_footer-plugins.phpclass-plugin-deactivate-feedback.php:61
filterwp_mail_content_typeclass-plugin-deactivate-feedback.php:97
actionadmin_headclass-qc-free-plugin-upgrade-notice.php:34
actionplugin_row_metaclass-qc-free-plugin-upgrade-notice.php:115
actionadmin_menuclass-qc-free-plugin-upgrade-notice.php:158
actionwp_footerfunctions.php:10
actionadmin_menuqc-support-promo-page\class-qc-support-promo-page.php:32
actionadmin_enqueue_scriptsqc-support-promo-page\class-qc-support-promo-page.php:62
actionadmin_menuqcld-woowbot-info-page.php:9
actionadmin_noticesqcld-woowbot.php:72
actionadmin_menuqcld-woowbot.php:78
actionadmin_initqcld-woowbot.php:82
actionadmin_enqueue_scriptsqcld-woowbot.php:85
actionwp_enqueue_scriptsqcld-woowbot.php:88
actionplugins_loadedqcld-woowbot.php:1475
actionplugins_loadedqcld-woowbot.php:1595
actionadmin_noticesqcld-woowbot.php:1647
Maintenance & Trust

ChatBot for eCommerce – WoowBot Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.4
Downloads104K

Community Trust

Rating96/100
Number of ratings19
Active installs1K
Developer Profile

ChatBot for eCommerce – WoowBot Developer Profile

QuantumCloud

29 plugins · 26K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
255 days
View full developer profile
Detection Fingerprints

How We Detect ChatBot for eCommerce – WoowBot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/woowbot-woocommerce-chatbot/css/admin-style.css/wp-content/plugins/woowbot-woocommerce-chatbot/css/font-awesome.min.css/wp-content/plugins/woowbot-woocommerce-chatbot/css/woo-chatbot-tabs.css/wp-content/plugins/woowbot-woocommerce-chatbot/js/cbpFWTabs.js/wp-content/plugins/woowbot-woocommerce-chatbot/js/modernizr.custom.js/wp-content/plugins/woowbot-woocommerce-chatbot/js/bootstrap.js/wp-content/plugins/woowbot-woocommerce-chatbot/css/bootstrap.min.css/wp-content/plugins/woowbot-woocommerce-chatbot/js/jquery.repeatable.js+6 more
Script Paths
plugins/woowbot-woocommerce-chatbot/js/cbpFWTabs.jsplugins/woowbot-woocommerce-chatbot/js/modernizr.custom.jsplugins/woowbot-woocommerce-chatbot/js/bootstrap.jsplugins/woowbot-woocommerce-chatbot/js/jquery.repeatable.jsplugins/woowbot-woocommerce-chatbot/js/qcld-woo-chatbot-admin.jsplugins/woowbot-woocommerce-chatbot/js/woowbot.js+1 more
Version Parameters
woowbot-woocommerce-chatbot/css/admin-style.css?ver=woowbot-woocommerce-chatbot/css/font-awesome.min.css?ver=woowbot-woocommerce-chatbot/css/woo-chatbot-tabs.css?ver=woowbot-woocommerce-chatbot/js/cbpFWTabs.js?ver=woowbot-woocommerce-chatbot/js/modernizr.custom.js?ver=woowbot-woocommerce-chatbot/js/bootstrap.js?ver=woowbot-woocommerce-chatbot/css/bootstrap.min.css?ver=woowbot-woocommerce-chatbot/js/jquery.repeatable.js?ver=woowbot-woocommerce-chatbot/js/qcld-woo-chatbot-admin.js?ver=woowbot-woocommerce-chatbot/js/woowbot.js?ver=woowbot-woocommerce-chatbot/css/woowbot.css?ver=woowbot-woocommerce-chatbot/css/slick.css?ver=woowbot-woocommerce-chatbot/js/slick.js?ver=

HTML / DOM Fingerprints

CSS Classes
woowbot-chatbot-containerwoowbot-close-btnwoowbot-open-btnwoowbot-message-container
HTML Comments
<!-- woowbot-close --><!-- woowbot-widget --><!-- START: woowbot-chat-conversation --><!-- END: woowbot-chat-conversation -->
Data Attributes
data-wc-prod-iddata-woowbot-user-iddata-woowbot-chat-id
JS Globals
woowbot_datawoowbot_admin_data
FAQ

Frequently Asked Questions about ChatBot for eCommerce – WoowBot