Chatra Live Chat + ChatBot + Cart Saver Security & Risk Analysis

wordpress.org/plugins/chatra-live-chat

Powerful chat / chatbot / Fb chat and cart saver app for Wordpress and WooCommerce, free as long as you want.

3K active installs v1.0.11 PHP + WP 3.0.1+ Updated Jun 20, 2022
chatbotfacebook-chatlive-chatlivechat%d1%81hat
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEJul 4, 2025
Safety Verdict

Is Chatra Live Chat + ChatBot + Cart Saver Safe to Use in 2026?

Use With Caution

Score 63/100

Chatra Live Chat + ChatBot + Cart Saver has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jul 4, 2025Updated 3yr ago
Risk Assessment

The 'chatra-live-chat' plugin v1.0.11 exhibits a mixed security posture. While the static analysis shows a commendably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication, and all SQL queries utilizing prepared statements, there are significant concerns regarding output escaping and historical vulnerabilities. The fact that only 33% of output is properly escaped indicates a moderate risk of Cross-Site Scripting (XSS) vulnerabilities, especially since XSS is a common type of historical vulnerability for this plugin. The presence of one unpatched medium-severity CVE, last reported in 2025, is a critical weakness that directly exposes users to known exploits. This highlights a failure in timely patching and ongoing security maintenance. In conclusion, while the foundational code structure is relatively clean with respect to direct attack vectors, the plugin suffers from inadequate output sanitization and a lack of promptness in addressing security flaws, making it a moderate to high risk, primarily due to the unpatched CVE and XSS potential.

Key Concerns

  • Unpatched medium severity CVE
  • Low percentage of properly escaped output
Vulnerabilities
1

Chatra Live Chat + ChatBot + Cart Saver Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-24735medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Chatra Live Chat + ChatBot + Cart Saver <= 1.0.11 - Authenticated (Administrator+) Stored Cross-Site Scripting

Jul 4, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Chatra Live Chat + ChatBot + Cart Saver Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped3 total outputs
Attack Surface

Chatra Live Chat + ChatBot + Cart Saver Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninitchatra.php:16
actionadmin_menuchatra.php:23
actionwp_footerchatra.php:52
Maintenance & Trust

Chatra Live Chat + ChatBot + Cart Saver Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 20, 2022
PHP min version
Downloads64K

Community Trust

Rating100/100
Number of ratings12
Active installs3K
Developer Profile

Chatra Live Chat + ChatBot + Cart Saver Developer Profile

Chatra

2 plugins · 3K total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Chatra Live Chat + ChatBot + Cart Saver

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Chatra Live Chat + ChatBot + Cart Saver