
Group Chat & Video Chat by AtomChat Security & Risk Analysis
wordpress.org/plugins/atomchatAtomChat helps you add group chat (or chatrooms), user to user chat, voice & video calling to your WordPress site.
Is Group Chat & Video Chat by AtomChat Safe to Use in 2026?
Mostly Safe
Score 72/100Group Chat & Video Chat by AtomChat is generally safe to use. 5 past CVEs were resolved.
The atomchat plugin exhibits a concerning security posture, marked by a significant number of unprotected entry points and a history of medium-severity vulnerabilities, including Cross-Site Scripting and Missing Authorization. While the plugin demonstrates good practices in SQL query handling and output escaping, the high percentage of unprotected AJAX handlers and REST API routes presents a substantial attack surface. The presence of the 'unserialize' function is a red flag, especially when combined with unsanitized input paths identified in the taint analysis. The vulnerability history, particularly the unpatched CVEs and recurring themes of XSS and authorization flaws, indicates a pattern of potential weaknesses that have been exploited in the past and may continue to be present.
Despite strengths in areas like SQL prepared statements and output escaping, the numerous unprotected entry points and the historical vulnerability data create a high-risk profile. The plugin's last reported vulnerability in 2026 suggests a recent or ongoing maintenance issue, which, coupled with unpatched CVEs, amplifies the risk. The plugin's security is compromised by its exposed functionalities and its historical tendency to harbor exploitable flaws. Users should exercise extreme caution and consider alternatives until these issues are fully addressed.
Key Concerns
- High number of unprotected AJAX handlers
- REST API route without permission callback
- Unpatched CVEs (2)
- History of Cross-Site Scripting
- History of Missing Authorization
- Unsanitized paths in taint analysis
- Dangerous function 'unserialize' used
- Only 2 capability checks found
- Only 1 nonce check found
Group Chat & Video Chat by AtomChat Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Group Chat & Video Chat by AtomChat <= 1.1.7 - Missing Authorization to Authenticated (Subscriber+) Plugin Options Update
AtomChat <= 1.1.7 - Missing Authorization
AtomChat <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
AtomChat <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via atomchat Shortcode
AtomChat <= 1.1.4 - Missing Authorization via credits REST API Endpoint
Group Chat & Video Chat by AtomChat Release Timeline
Group Chat & Video Chat by AtomChat Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Group Chat & Video Chat by AtomChat Attack Surface
AJAX Handlers 7
REST API Routes 2
Shortcodes 1
WordPress Hooks 10
Scheduled Events 2
Maintenance & Trust
Group Chat & Video Chat by AtomChat Maintenance & Trust
Maintenance Signals
Community Trust
Group Chat & Video Chat by AtomChat Alternatives
RumbleTalk Live Group Chat – HTML5
rumbletalk-chat-a-chat-with-themes
Live group chat plugin for WordPress. Integrate it into your website in minutes. Create one or multiple rooms effortlessly.
One to one user Chat by WPGuppy
wpguppy-lite
WPGuppy is a well thought and clinically designed and developed WordPress chat plugin which has been engineered to fulfill the market needs.
Group chat for WordPress – Minnit Chat
minnit-chat
Cloud-based chat using your WordPress accounts. Minnit uses SSO to allow you and your WordPress users to communicate with one another.
JivoChat Live Chat – WP live chat plugin for WordPress
jivochat
Omnichannel Live Chat and Help Desk plugin, optimized for WordPress. Free, fast, easy to install and to use. Turn your visitors into happy customers!
Pure Chat – Live Chat & More!
pure-chat
Pure Chat provides a Live Chat plugin with Unlimited Chats for your website!
Group Chat & Video Chat by AtomChat Developer Profile
1 plugin · 400 total installs
How We Detect Group Chat & Video Chat by AtomChat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/atomchat/includes/atomchat_cloud.php/wp-content/plugins/atomchat/includes/atomchat_selfhosted.php/wp-content/plugins/atomchat/includes/atomchat_requesthandler.php/wp-content/plugins/atomchat/api/v1/atomchatLogin.php/wp-content/plugins/atomchat/plugins/mycred/credits.php/wp-content/plugins/atomchat/images/atom_chat_white_ icon.pngatomchat/style.css?ver=atomchat/script.js?ver=HTML / DOM Fingerprints
Start: To change the default plugin load order to avoid buddypress plugin conflictEnd: To change the default plugin load order to avoid buddypress plugin conflictdata-atomchat-license-keydata-atomchat-client-idatomchat_clientidatomchat_old_clientid/wp-json/api/v1/atomchatLogin/wp-json/plugins/mycred/credits[atomchat][atomchat_chatbox]