AnswerForce Security & Risk Analysis

wordpress.org/plugins/answerforce

Add the AnswerForce plugin for quick and easy customer support. Chat with visitors, build relationships and improve customer satisfaction.

10 active installs v2.3 PHP + WP + Updated Unknown
chat-answeringchat-widgetlead-capturelive-chatonline-support
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AnswerForce Safe to Use in 2026?

Generally Safe

Score 100/100

AnswerForce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the provided static analysis and vulnerability history, the "answerforce" plugin v2.3 exhibits a seemingly strong security posture. The absence of any identified vulnerabilities in its history, coupled with the complete lack of critical or high-severity taint flows, suggests a developer who is mindful of common security pitfalls. The code analysis also indicates good practices such as the absence of dangerous functions, file operations, and external HTTP requests, and that all SQL queries utilize prepared statements. However, the analysis also reveals areas for improvement. A significant concern is the low percentage (47%) of properly escaped output, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities, especially given the absence of data from taint analysis which might otherwise flag such issues.

The plugin presents a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, which is commendable for reducing the potential entry points for attackers. The lack of vulnerability history is also a positive indicator. Despite these strengths, the substantial number of outputs that are not properly escaped warrants attention, as this is a common vector for attacks if user-supplied data is involved in generating these outputs. While no specific vulnerabilities are currently recorded or evident in the taint analysis, the unescaped outputs represent a latent risk that could be exploited under certain conditions. Therefore, while the plugin appears robust in many areas, the output escaping requires further investigation and remediation to ensure a truly secure product.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

AnswerForce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AnswerForce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

47% escaped19 total outputs
Attack Surface

AnswerForce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuAnswerForce.php:40
actionadmin_initAnswerForce.php:43
actioninitAnswerForce.php:65
actionplugins_loadedAnswerForce.php:66
Maintenance & Trust

AnswerForce Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

AnswerForce Developer Profile

answerforce

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AnswerForce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/answerforce/css/wordpress-style.css/wp-content/plugins/answerforce/images/chatsupport-white-logo-icon.svg/wp-content/plugins/answerforce/images/wordpress-logo.svg/wp-content/plugins/answerforce/images/link-icon.svg/wp-content/plugins/answerforce/images/answerforce-logo.svg/wp-content/plugins/answerforce/images/template-icon.png/wp-content/plugins/answerforce/images/cloud.svg
Script Paths
/wp-content/plugins/answerforce/script/chatSupportFormScript.js

HTML / DOM Fingerprints

CSS Classes
wordpress-plugin-wrpwordpress-plugin-setupdisplay-nonebtn-progressingwidget-installwordpress-project-clipssingle-widget-setupwidget-installed+3 more
HTML Comments
<!-- wordpress-loader --><!-- bg -->
Data Attributes
siteUrlid="cwa-login"id="projectId"id="widgetThemeColor"id="logoUrl"id="widgetName"+3 more
JS Globals
_lsChatSupportScript
FAQ

Frequently Asked Questions about AnswerForce