
11Sight – Video, Audio calls and text chat Security & Risk Analysis
wordpress.org/plugins/11sight-video-audio-calls-and-text-chatAdd your 11Sight button easily on your website, download our application on your phone and start connecting with your customers.
Is 11Sight – Video, Audio calls and text chat Safe to Use in 2026?
Generally Safe
Score 85/10011Sight – Video, Audio calls and text chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "11sight-video-audio-calls-and-text-chat" plugin version 1.4 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and critically, no taint flows with unsanitized paths are significant strengths. The plugin also demonstrates good practices by utilizing prepared statements for its SQL queries and has a single capability check, indicating some level of access control is in place. The vulnerability history showing zero known CVEs further supports this positive assessment.
However, there are areas that warrant attention. The most significant concern is the extremely low percentage of properly escaped output (10% of 20 total outputs). This suggests a high potential for Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be rendered without proper sanitization. The lack of nonce checks on the single shortcode entry point, while not directly flagged as an issue in the taint analysis, could be a vector for certain types of attacks if the shortcode handles user input in a sensitive manner. The presence of external HTTP requests also introduces a minor risk, as these could potentially be intercepted or manipulated, although without more context on what these requests are for, it's difficult to assess the severity.
In conclusion, the plugin's core functionality appears to be built with security in mind, particularly regarding database interactions and avoiding known dangerous code patterns. Nevertheless, the significant oversight in output escaping represents a critical weakness that could expose users to XSS attacks. Addressing the output escaping and considering nonce checks for the shortcode would greatly improve the plugin's overall security.
Key Concerns
- Low percentage of properly escaped output
- Lack of nonce check on shortcode
11Sight – Video, Audio calls and text chat Security Vulnerabilities
11Sight – Video, Audio calls and text chat Code Analysis
Output Escaping
11Sight – Video, Audio calls and text chat Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
11Sight – Video, Audio calls and text chat Maintenance & Trust
Maintenance Signals
Community Trust
11Sight – Video, Audio calls and text chat Alternatives
Intellacall – Instant One Click Live Video Calls
intellacall-video-audio-calls-and-text-chat
Put your team in a face to face online interaction with the customer instantly from your existing webpage.
UrLive Chat widget by UrLive
urlive-call-widget
A plugin powered by urLive that allows people to instantly communicate with each other in the browser
The Ultimate Video Player For WordPress – by Presto Player
presto-player
The Ultimate WordPress Video Player.
Mixed Media Gallery Blocks
simply-gallery-block
Create mixed media galleries with images, HTML5 video, YouTube, Vimeo, and VideoPress — all in one gallery by Simply Gallery.
WP Photo Album Plus
wp-photo-album-plus
This plugin is more than just a photo album plugin, it is a complete, highly customizable multimedia cms and display system.
11Sight – Video, Audio calls and text chat Developer Profile
1 plugin · 30 total installs
How We Detect 11Sight – Video, Audio calls and text chat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/11sight-video-audio-calls-and-text-chat/style.css?ver=1.4/11sight-video-audio-calls-and-text-chat/script.js?ver=1.4HTML / DOM Fingerprints
iisight_rowlabel_for="iisight_field_html"