Chaport — Live Chat & Chatbots Security & Risk Analysis

wordpress.org/plugins/chaport

Modern live chat plugin for WordPress. Powerful features: multi-channel, chatbots, customization, etc. Free plan. Unlimited chats & websites.

2K active installs v1.1.9 PHP 5.2+ WP 2.8+ Updated Unknown
chat-pluginchat-widgetchatbotfree-live-chatlive-chat-widget
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 5, 2025
Download
Safety Verdict

Is Chaport — Live Chat & Chatbots Safe to Use in 2026?

Generally Safe

Score 99/100

Chaport — Live Chat & Chatbots has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 5, 2025
Risk Assessment

The "chaport" plugin v1.1.9 exhibits a generally positive security posture based on the static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a limited attack surface. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and having a high percentage of properly escaped output. The lack of dangerous functions, file operations, external HTTP requests, and critical or high-severity taint flows further contributes to its favorable security profile.

However, there are a few areas that warrant attention. The plugin has a history of known vulnerabilities, including a past Cross-site Scripting (XSS) issue. While there are currently no unpatched CVEs, this history suggests that thorough security auditing and prompt patching of future vulnerabilities will be crucial. The low number of capability checks (only 1) and the absence of nonce checks on any potential entry points (though the static analysis reported 0 entry points) could be a concern if functionality is added in the future that requires more robust access control or protection against CSRF attacks.

In conclusion, the "chaport" plugin v1.1.9 appears to be relatively secure for its current implementation, with a well-controlled attack surface and good coding practices. The main area for caution lies in its vulnerability history, emphasizing the need for ongoing vigilance and prompt updates. Addressing the limited capability checks and ensuring nonce protection on any new functionalities will further strengthen its security.

Key Concerns

  • Past critical XSS vulnerability
  • Low number of capability checks
  • No nonce checks on entry points
  • Some output not properly escaped
Vulnerabilities
1

Chaport — Live Chat & Chatbots Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-30977medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Live Chat + Chatbots Plugin for WordPress – Chaport <= 1.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jun 5, 2025 Patched in 1.1.7 (184d)
Code Analysis
Analyzed Mar 16, 2026

Chaport — Live Chat & Chatbots Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
23 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped28 total outputs
Attack Surface

Chaport — Live Chat & Chatbots Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedchaport.php:40
actionadmin_enqueue_scriptschaport.php:41
actionadmin_menuchaport.php:42
actionadmin_initchaport.php:43
actionwp_footerchaport.php:44
Maintenance & Trust

Chaport — Live Chat & Chatbots Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version5.2
Downloads39K

Community Trust

Rating80/100
Number of ratings4
Active installs2K
Developer Profile

Chaport — Live Chat & Chatbots Developer Profile

Chaport Live Chat

1 plugin · 2K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
184 days
View full developer profile
Detection Fingerprints

How We Detect Chaport — Live Chat & Chatbots

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chaport/assets/css/style.css/wp-content/plugins/chaport/assets/js/toggle.js
Script Paths
/wp-content/plugins/chaport/assets/js/toggle.js
Version Parameters
chaport/style.css?ver=chaport/toggle.js?ver=

HTML / DOM Fingerprints

CSS Classes
chaport-status-warningchaport-status-okchaport-status-error
FAQ

Frequently Asked Questions about Chaport — Live Chat & Chatbots