
Chative Live chat and Chatbot Security & Risk Analysis
wordpress.org/plugins/chative-live-chat-and-chatbotChat & sell directly on your store with AI and automation.
Is Chative Live chat and Chatbot Safe to Use in 2026?
Generally Safe
Score 91/100Chative Live chat and Chatbot has a strong security track record. Known vulnerabilities have been patched promptly.
The "chative-live-chat-and-chatbot" v1.2 plugin exhibits a generally positive security posture with several good practices in place. The static analysis shows a limited attack surface, with only one AJAX handler and no exposed REST API routes or shortcodes. Crucially, the AJAX handler appears to have an associated nonce check, and all SQL queries utilize prepared statements, which significantly mitigates common web vulnerabilities. The absence of dangerous functions and external HTTP requests is also a strong positive indicator. However, there are areas for improvement. The code only has a 60% output escaping rate, meaning some data displayed to users might not be properly sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the absence of capability checks on the AJAX handler, despite a nonce check, means that any authenticated user could potentially trigger this function, which could be a concern if the function performs sensitive actions.
The vulnerability history, while showing no currently unpatched CVEs, reveals a past critical vulnerability related to Cross-Site Request Forgery (CSRF). The fact that the last vulnerability was recently discovered and fixed (2025-01-06) suggests that the plugin, while addressing issues, has had significant security flaws in the past. The historical presence of CSRF, coupled with the lack of explicit capability checks on the AJAX handler in the current version, warrants a cautious approach. In conclusion, the plugin is moving in the right direction with secure coding practices for database interactions and entry points, but the partial output escaping and potential lack of robust authorization for the AJAX handler are weaknesses that need attention.
Key Concerns
- Output escaping is not fully implemented
- No capability checks on AJAX handler
- Past CSRF vulnerability history
Chative Live chat and Chatbot Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Chative Live chat and Chatbot <= 1.1 - Cross-Site Request Forgery via add_chative_widget_action Function
Chative Live chat and Chatbot Code Analysis
Output Escaping
Chative Live chat and Chatbot Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
Chative Live chat and Chatbot Maintenance & Trust
Maintenance Signals
Community Trust
Chative Live chat and Chatbot Alternatives
HappyFox Chat – Live Chat Plugin for WordPress Websites
happyfox-chat
Voted No.1 Live chat software on ProductHunt. Fully loaded with features like unlimited chats, fully customizable widget, app integrations & more.
Casengo Live Chat Support
the-casengo-chat-widget
Live Chat by Casengo, fully functional, easy to use and has great design! Install live chat support on your WordPress site today!
WSChat – WordPress Live Chat
wschat-live-chat
WordPress Live Chat Made Simple! Unlike other Live Chat plugins, this plugin works within WordPress with no external API calls.
PHP Live!
php-live-wordpress
Chat with your website visitors in real-time and provide winning customer service.Chat with your website visitors in real-time and provide winning cus …
Banckle Chat
banckle-live-chat-for-wordpress
Banckle.Chat provides you a feature rich, reliable, economical and highly customizable live chat platform, for effective communication with visitors.
Chative Live chat and Chatbot Developer Profile
1 plugin · 50 total installs
How We Detect Chative Live chat and Chatbot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/chative-live-chat-and-chatbot/include/css/index.css/wp-content/plugins/chative-live-chat-and-chatbot/include/js/chative.selection.js/wp-content/plugins/chative-live-chat-and-chatbot/include/js/chative.selection.jsHTML / DOM Fingerprints
ajaxurlchativeNonce/wp-json/chative/v1/widget