Chatnox Live Chat Plugin (Free & Paid Plans) Security & Risk Analysis

wordpress.org/plugins/chatnox-live-chat

Used by over 35000+ businesses world-wide, Chatnox is a popular Live Chat software. Try Live Chat for free!

70 active installs v2.0 PHP + WP 3.3.1+ Updated Jul 29, 2019
chatchat-pluginfree-chat-pluginlive-chatlive-chat-plugin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Chatnox Live Chat Plugin (Free & Paid Plans) Safe to Use in 2026?

Generally Safe

Score 85/100

Chatnox Live Chat Plugin (Free & Paid Plans) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'chatnox-live-chat' plugin version 2.0 exhibits a concerning security posture despite a lack of recorded historical vulnerabilities. The static analysis reveals no direct attack surface through AJAX, REST API, shortcodes, or cron events. However, the complete absence of capability checks and nonce checks across all potential entry points (even though there are currently zero) is a significant weakness. The plugin also fails to properly escape any of its 17 identified output points, presenting a substantial risk of Cross-Site Scripting (XSS) vulnerabilities should any code path be exposed. While SQL queries are safely prepared, the presence of two taint flows with unsanitized paths, even without a high severity classification, indicates potential for information disclosure or other unintended behavior if these flows are reachable. The plugin also makes an external HTTP request, the security implications of which are not detailed but represent a potential external attack vector. The lack of recorded vulnerabilities might be due to a very limited user base, infrequent audits, or a recent emergence of exploitable flaws. Overall, while the plugin avoids some common pitfalls like raw SQL and large attack surfaces, the critical lack of output escaping and potential for unsanitized taint flows, coupled with the absence of critical security checks, makes its current security status precarious.

Key Concerns

  • 0% output escaping
  • 2 flows with unsanitized paths
  • 0 capability checks
  • 0 nonce checks
  • External HTTP requests
Vulnerabilities
None known

Chatnox Live Chat Plugin (Free & Paid Plans) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Chatnox Live Chat Plugin (Free & Paid Plans) Release Timeline

v3.0
v2.0Current
v1.0
Code Analysis
Analyzed Apr 16, 2026

Chatnox Live Chat Plugin (Free & Paid Plans) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped17 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
chatnox_configuration (chatnoxconfig.php:3)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Chatnox Live Chat Plugin (Free & Paid Plans) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_enqueue_scriptschatnox.php:32
actionwp_print_scriptschatnox.php:72
actionadmin_menuchatnox.php:79
Maintenance & Trust

Chatnox Live Chat Plugin (Free & Paid Plans) Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJul 29, 2019
PHP min version
Downloads17K

Community Trust

Rating92/100
Number of ratings7
Active installs70
Developer Profile

Chatnox Live Chat Plugin (Free & Paid Plans) Developer Profile

ChatNox Live Chat

1 plugin · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Chatnox Live Chat Plugin (Free & Paid Plans)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chatnox-live-chat/chatnox.css/wp-content/plugins/chatnox-live-chat/chatnox.js
Script Paths
/wp-content/plugins/chatnox-live-chat/chatnox.js
Version Parameters
chatnox-live-chat/chatnox.css?ver=chatnox-live-chat/chatnox.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- ChatNox Widget --><!-- ChatNox Widget Ends -->
Data Attributes
data-popup="true"
JS Globals
var _chatnox = _chatnox || [];_chatnox.setAccount
FAQ

Frequently Asked Questions about Chatnox Live Chat Plugin (Free & Paid Plans)