Chatra Live Chat + ChatBot + Cart Saver Security & Risk Analysis

wordpress.org/plugins/chatra-live-chat

Powerful chat / chatbot / Fb chat and cart saver app for WordPress and WooCommerce, free as long as you want.

2K active installs v1.0.13 PHP 5.6+ WP 4.5+ Updated Jul 9, 2026
chat-widgetchatbotcustomer-supportlive-chatlivechat
56
C · Use Caution
CVEs total2
Unpatched2
Last CVEJul 7, 2026
Safety Verdict

Is Chatra Live Chat + ChatBot + Cart Saver Safe to Use in 2026?

Use With Caution

Score 56/100

Chatra Live Chat + ChatBot + Cart Saver has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.

2 known CVEs 2 unpatched Last CVE: Jul 7, 2026Updated 1mo ago
Risk Assessment

The 'chatra-live-chat' plugin v1.0.11 exhibits a mixed security posture. While the static analysis shows a commendably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication, and all SQL queries utilizing prepared statements, there are significant concerns regarding output escaping and historical vulnerabilities. The fact that only 33% of output is properly escaped indicates a moderate risk of Cross-Site Scripting (XSS) vulnerabilities, especially since XSS is a common type of historical vulnerability for this plugin. The presence of one unpatched medium-severity CVE, last reported in 2025, is a critical weakness that directly exposes users to known exploits. This highlights a failure in timely patching and ongoing security maintenance. In conclusion, while the foundational code structure is relatively clean with respect to direct attack vectors, the plugin suffers from inadequate output sanitization and a lack of promptness in addressing security flaws, making it a moderate to high risk, primarily due to the unpatched CVE and XSS potential.

Key Concerns

  • Unpatched medium severity CVE
  • Low percentage of properly escaped output
Vulnerabilities
2 published

Chatra Live Chat + ChatBot + Cart Saver Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2026-12041medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Chatra Live Chat + ChatBot + Cart Saver <= 1.0.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'chatra-code' Setting

Jul 7, 2026Unpatched
CVE-2025-24735medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Chatra Live Chat + ChatBot + Cart Saver <= 1.0.11 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jul 4, 2025Unpatched
Version History

Chatra Live Chat + ChatBot + Cart Saver Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Chatra Live Chat + ChatBot + Cart Saver Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped3 total outputs
Attack Surface

Chatra Live Chat + ChatBot + Cart Saver Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninitchatra.php:16
actionadmin_menuchatra.php:23
actionwp_footerchatra.php:52
Maintenance & Trust

Chatra Live Chat + ChatBot + Cart Saver Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJul 9, 2026
PHP min version5.6
Downloads69K

Community Trust

Rating100/100
Number of ratings12
Active installs2K
Developer Profile

Chatra Live Chat + ChatBot + Cart Saver Developer Profile

Chatra

2 plugins · 2K total installs

74
trust score
Avg Security Score
71/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Chatra Live Chat + ChatBot + Cart Saver

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Chatra Live Chat + ChatBot + Cart Saver