YZ Chatbot – AI Powered Live Chat & Customer Support Security & Risk Analysis

wordpress.org/plugins/yz-chatbot-ai-powered-live-chat-customer-support

AI-powered chatbot widget for WordPress. Transform your website into a smart customer service agent in 30 seconds. Powered by Google Gemini AI.

0 active installs v1.0.0 PHP 7.4+ WP 5.8+ Updated Jan 24, 2026
ai-chatbotchatbotcustomer-supportlive-chatwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is YZ Chatbot – AI Powered Live Chat & Customer Support Safe to Use in 2026?

Generally Safe

Score 100/100

YZ Chatbot – AI Powered Live Chat & Customer Support has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "yz-chatbot-ai-powered-live-chat-customer-support" plugin v1.0.0 demonstrates a strong adherence to secure coding practices, with a commendably clean static analysis report. All identified entry points, including AJAX handlers, are properly secured with nonce and capability checks, and no critical or high-severity taint flows were detected. The plugin also excels in output escaping, with all outputs being properly sanitized, and has no history of known vulnerabilities. This indicates a responsible development approach.

However, the plugin's static analysis does reveal a minor area for potential improvement. The single SQL query executed is not using prepared statements, which, while not leading to a detected vulnerability in this version, represents a potential risk. If this query were to incorporate user-supplied data in future versions without proper sanitization, it could become an SQL injection vector. While the current record is excellent, this absence of prepared statements in the SQL query is the sole flag for attention, suggesting a focus on security but with one common SQL hardening technique overlooked.

Overall, this plugin presents a low-risk profile. Its robust authentication and authorization for entry points, coupled with perfect output escaping and zero historical vulnerabilities, are significant strengths. The only weakness lies in the use of a non-prepared SQL query. Given the current version's clean state and lack of known issues, the risk is minimal, but addressing the SQL query practice would further enhance its security posture.

Key Concerns

  • SQL queries not using prepared statements
Vulnerabilities
None known

YZ Chatbot – AI Powered Live Chat & Customer Support Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

YZ Chatbot – AI Powered Live Chat & Customer Support Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
35 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

100% escaped35 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ajax_save_wizard (yz-chatbot-ai-powered-live-chat-customer-support.php:464)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

YZ Chatbot – AI Powered Live Chat & Customer Support Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_yz_chatbot_verify_tenantyz-chatbot-ai-powered-live-chat-customer-support.php:115
authwp_ajax_yz_chatbot_save_wizardyz-chatbot-ai-powered-live-chat-customer-support.php:116
WordPress Hooks 6
actionadmin_menuyz-chatbot-ai-powered-live-chat-customer-support.php:101
actionadmin_inityz-chatbot-ai-powered-live-chat-customer-support.php:102
actionadmin_enqueue_scriptsyz-chatbot-ai-powered-live-chat-customer-support.php:103
actionadmin_inityz-chatbot-ai-powered-live-chat-customer-support.php:104
actionwp_enqueue_scriptsyz-chatbot-ai-powered-live-chat-customer-support.php:110
actionwp_footeryz-chatbot-ai-powered-live-chat-customer-support.php:111
Maintenance & Trust

YZ Chatbot – AI Powered Live Chat & Customer Support Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 24, 2026
PHP min version7.4
Downloads115

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

YZ Chatbot – AI Powered Live Chat & Customer Support Developer Profile

yapayzekachatbot

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect YZ Chatbot – AI Powered Live Chat & Customer Support

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yz-chatbot-ai-powered-live-chat-customer-support/build/yz-chatbot.css/wp-content/plugins/yz-chatbot-ai-powered-live-chat-customer-support/build/yz-chatbot.js
Version Parameters
/wp-content/plugins/yz-chatbot-ai-powered-live-chat-customer-support/build/yz-chatbot.css?ver=/wp-content/plugins/yz-chatbot-ai-powered-live-chat-customer-support/build/yz-chatbot.js?ver=

HTML / DOM Fingerprints

CSS Classes
yz-chatbot-widget
Data Attributes
data-yz-chatbot-tenant-iddata-yz-chatbot-enableddata-yz-chatbot-themedata-yz-chatbot-positiondata-yz-chatbot-primary-colordata-yz-chatbot-welcome-message+7 more
JS Globals
YZChatbotSettings
REST Endpoints
/wp-json/yz-chatbot/v1/verify-tenant/wp-json/yz-chatbot/v1/save-wizard
FAQ

Frequently Asked Questions about YZ Chatbot – AI Powered Live Chat & Customer Support