Chat life for telegram Security & Risk Analysis

wordpress.org/plugins/chat-life-telegram

Дозволяє зробити чат на сайті і відповідати в режимі онлайн через Телеграм чат

20 active installs v0.1.2 PHP 7.3+ WP 5.0+ Updated Apr 5, 2022
chat-wordpresschat-wptelegram-chat
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Chat life for telegram Safe to Use in 2026?

Generally Safe

Score 85/100

Chat life for telegram has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The 'chat-life-telegram' plugin version 0.1.2 exhibits a concerning security posture primarily due to a significant number of unprotected AJAX handlers. While the plugin shows positive signs with a high percentage of SQL queries using prepared statements and well-escaped output, the lack of authentication and capability checks on all its entry points creates a substantial attack surface. This means any unauthenticated user could potentially trigger these AJAX actions, leading to unintended consequences or exploitation if the underlying functionality is sensitive.

The static analysis did not reveal any dangerous functions, critical or high severity taint flows, or direct SQL injection vulnerabilities through raw SQL queries. The absence of known CVEs and a clean vulnerability history are positive indicators, suggesting the core logic might be relatively secure. However, the current version's unprotected AJAX handlers remain a critical weakness. The presence of file operations and external HTTP requests, while not inherently malicious, warrants careful review in conjunction with the unprotected entry points to ensure these operations are not misused.

In conclusion, the plugin has some good security practices in place, such as prepared statements and output escaping. Nevertheless, the complete lack of authorization checks on all identified AJAX entry points is a major security flaw that significantly elevates the risk. A proactive approach focusing on implementing robust authentication and capability checks for all AJAX handlers is essential to mitigate these risks and improve the plugin's overall security.

Key Concerns

  • AJAX handlers without auth checks
  • AJAX handlers without capability checks
  • File operations without explicit checks
  • External HTTP requests without explicit checks
Vulnerabilities
None known

Chat life for telegram Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Chat life for telegram Release Timeline

v0.1.1
Code Analysis
Analyzed Apr 16, 2026

Chat life for telegram Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
5 prepared
Unescaped Output
5
31 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
1
Bundled Libraries
0

SQL Query Safety

83% prepared6 total queries

Output Escaping

86% escaped36 total outputs
Attack Surface
5 unprotected

Chat life for telegram Attack Surface

Entry Points5
Unprotected5

AJAX Handlers 5

authwp_ajax_tcl_admin_actioninit.php:45
authwp_ajax_tcl_actioninit.php:53
noprivwp_ajax_tcl_actioninit.php:54
authwp_ajax_tcl_chat_webhookinit.php:56
noprivwp_ajax_tcl_chat_webhookinit.php:57
WordPress Hooks 5
actionadmin_menuinit.php:43
actionwp_footerinit.php:161
filtersanitize_option_tclsrc/ChatCore.php:23
filtertcl_theme_listsrc/ChatCore.php:24
actioninitsrc/ControllerForTelegram.php:46
Maintenance & Trust

Chat life for telegram Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedApr 5, 2022
PHP min version7.3
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

Chat life for telegram Developer Profile

pechenki

4 plugins · 5K total installs

80
trust score
Avg Security Score
88/100
Avg Patch Time
79 days
View full developer profile
Detection Fingerprints

How We Detect Chat life for telegram

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chat-life-telegram/admin/assets/css/css.css/wp-content/plugins/chat-life-telegram/admin/assets/js/admin-tcl.js/wp-content/plugins/chat-life-telegram/frontend/css/chat.css/wp-content/plugins/chat-life-telegram/frontend/js/vue.global.js/wp-content/plugins/chat-life-telegram/frontend/js/vanillaEmojiPicker.js/wp-content/plugins/chat-life-telegram/frontend/js/tcl_script.js
Script Paths
/wp-content/plugins/chat-life-telegram/admin/assets/js/admin-tcl.js/wp-content/plugins/chat-life-telegram/frontend/js/vue.global.js/wp-content/plugins/chat-life-telegram/frontend/js/vanillaEmojiPicker.js/wp-content/plugins/chat-life-telegram/frontend/js/tcl_script.js
Version Parameters
chat-life-telegram/admin/assets/css/css.css?ver=0.1chat-life-telegram/admin/assets/js/admin-tcl.js?ver=chat-life-telegram/frontend/css/chat.css?ver=chat-life-telegram/frontend/js/vue.global.js?ver=chat-life-telegram/frontend/js/vanillaEmojiPicker.js?ver=chat-life-telegram/frontend/js/tcl_script.js?ver=

HTML / DOM Fingerprints

JS Globals
Tcl
REST Endpoints
/wp-json/tcl_chat/v1/settings/wp-json/tcl_chat/v1/list/wp-json/tcl_chat/v1/get_chat/wp-json/tcl_chat/v1/get_user/wp-json/tcl_chat/v1/remove_chat/wp-json/tcl_chat/v1/get_messages/wp-json/tcl_chat/v1/get_messages_by_chat
Shortcode Output
[chat_life_telegram]
FAQ

Frequently Asked Questions about Chat life for telegram