
Chatra Live Chat + ChatBot + Cart Saver Security & Risk Analysis
wordpress.org/plugins/chatra-live-chatPowerful chat / chatbot / Fb chat and cart saver app for Wordpress and WooCommerce, free as long as you want.
Is Chatra Live Chat + ChatBot + Cart Saver Safe to Use in 2026?
Use With Caution
Score 63/100Chatra Live Chat + ChatBot + Cart Saver has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'chatra-live-chat' plugin v1.0.11 exhibits a mixed security posture. While the static analysis shows a commendably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication, and all SQL queries utilizing prepared statements, there are significant concerns regarding output escaping and historical vulnerabilities. The fact that only 33% of output is properly escaped indicates a moderate risk of Cross-Site Scripting (XSS) vulnerabilities, especially since XSS is a common type of historical vulnerability for this plugin. The presence of one unpatched medium-severity CVE, last reported in 2025, is a critical weakness that directly exposes users to known exploits. This highlights a failure in timely patching and ongoing security maintenance. In conclusion, while the foundational code structure is relatively clean with respect to direct attack vectors, the plugin suffers from inadequate output sanitization and a lack of promptness in addressing security flaws, making it a moderate to high risk, primarily due to the unpatched CVE and XSS potential.
Key Concerns
- Unpatched medium severity CVE
- Low percentage of properly escaped output
Chatra Live Chat + ChatBot + Cart Saver Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Chatra Live Chat + ChatBot + Cart Saver <= 1.0.11 - Authenticated (Administrator+) Stored Cross-Site Scripting
Chatra Live Chat + ChatBot + Cart Saver Code Analysis
Output Escaping
Chatra Live Chat + ChatBot + Cart Saver Attack Surface
WordPress Hooks 3
Maintenance & Trust
Chatra Live Chat + ChatBot + Cart Saver Maintenance & Trust
Maintenance Signals
Community Trust
Chatra Live Chat + ChatBot + Cart Saver Alternatives
Tidio – Live Chat & AI Chatbots
tidio-live-chat
Add Tidio Live Chat to your WordPress for free to answer customers’ questions, engage website visitors, generate leads, and increase sales.
Crisp – Live Chat and Chatbot
crisp
A Free, one-click-to-install, Live Chat and chatbot plugin. No coding skills are required. Used by more than 30 000 customers on WordPress.
Zoho SalesIQ – Live chat, chatbots, and visitor tracking
zoho-salesiq
Identify, engage and convert website visitors with live chat and visitor analytics.
LiveChat – Live Chat Plugin for WP Websites
wp-live-chat-software-for-wordpress
Best live chat and help desk plugin for WordPress websites. Add the LiveChat widget to engage visitors and provide real‑time customer support! 🚀
Live Chat by Formilla – Real-time Chat & Chatbots Plugin
formilla-live-chat
Live chat software with real-time visitor monitoring and chatbots! Live chat with your visitors for free or use a chatbot to automate self-help.
Chatra Live Chat + ChatBot + Cart Saver Developer Profile
2 plugins · 3K total installs
How We Detect Chatra Live Chat + ChatBot + Cart Saver
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.