Chative Live chat and Chatbot Security & Risk Analysis

wordpress.org/plugins/chative-live-chat-and-chatbot

Chat & sell directly on your store with AI and automation.

50 active installs v1.2 PHP 5.6+ WP 2.7+ Updated Jan 7, 2025
ai-chatbotchat-onlinechat-softwarelive-supportwordpress-chat
91
A · Safe
CVEs total1
Unpatched0
Last CVEJan 6, 2025
Safety Verdict

Is Chative Live chat and Chatbot Safe to Use in 2026?

Generally Safe

Score 91/100

Chative Live chat and Chatbot has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 6, 2025Updated 1yr ago
Risk Assessment

The "chative-live-chat-and-chatbot" v1.2 plugin exhibits a generally positive security posture with several good practices in place. The static analysis shows a limited attack surface, with only one AJAX handler and no exposed REST API routes or shortcodes. Crucially, the AJAX handler appears to have an associated nonce check, and all SQL queries utilize prepared statements, which significantly mitigates common web vulnerabilities. The absence of dangerous functions and external HTTP requests is also a strong positive indicator. However, there are areas for improvement. The code only has a 60% output escaping rate, meaning some data displayed to users might not be properly sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the absence of capability checks on the AJAX handler, despite a nonce check, means that any authenticated user could potentially trigger this function, which could be a concern if the function performs sensitive actions.

The vulnerability history, while showing no currently unpatched CVEs, reveals a past critical vulnerability related to Cross-Site Request Forgery (CSRF). The fact that the last vulnerability was recently discovered and fixed (2025-01-06) suggests that the plugin, while addressing issues, has had significant security flaws in the past. The historical presence of CSRF, coupled with the lack of explicit capability checks on the AJAX handler in the current version, warrants a cautious approach. In conclusion, the plugin is moving in the right direction with secure coding practices for database interactions and entry points, but the partial output escaping and potential lack of robust authorization for the AJAX handler are weaknesses that need attention.

Key Concerns

  • Output escaping is not fully implemented
  • No capability checks on AJAX handler
  • Past CSRF vulnerability history
Vulnerabilities
1

Chative Live chat and Chatbot Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-12541medium · 5.4Cross-Site Request Forgery (CSRF)

Chative Live chat and Chatbot <= 1.1 - Cross-Site Request Forgery via add_chative_widget_action Function

Jan 6, 2025 Patched in 1.2 (3d)
Code Analysis
Analyzed Mar 16, 2026

Chative Live chat and Chatbot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
3 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped5 total outputs
Attack Surface

Chative Live chat and Chatbot Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_chative_setwidgetchative-plugin.php:38
WordPress Hooks 4
actionadmin_menuchative-plugin.php:14
actionwp_headchative-plugin.php:28
actionwp_footerchative-plugin.php:84
actionwp_loadedchative-plugin.php:108
Maintenance & Trust

Chative Live chat and Chatbot Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 7, 2025
PHP min version5.6
Downloads3K

Community Trust

Rating86/100
Number of ratings6
Active installs50
Developer Profile

Chative Live chat and Chatbot Developer Profile

Chative - Live chat and Chatbot

1 plugin · 50 total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
3 days
View full developer profile
Detection Fingerprints

How We Detect Chative Live chat and Chatbot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chative-live-chat-and-chatbot/include/css/index.css/wp-content/plugins/chative-live-chat-and-chatbot/include/js/chative.selection.js
Script Paths
/wp-content/plugins/chative-live-chat-and-chatbot/include/js/chative.selection.js

HTML / DOM Fingerprints

JS Globals
ajaxurlchativeNonce
REST Endpoints
/wp-json/chative/v1/widget
FAQ

Frequently Asked Questions about Chative Live chat and Chatbot