Chatwing Live Group Chat – HTML5 + Chat Apps Security & Risk Analysis

wordpress.org/plugins/chatwing

Chatwing offers an unlimited live website/blog chat experience.This chat widget specializes in delivering real-time communication at any given time

10 active installs v2.4.5 PHP + WP 3.0.1+ Updated Aug 13, 2018
adminchatchatboxchatwingcommunity
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Chatwing Live Group Chat – HTML5 + Chat Apps Safe to Use in 2026?

Generally Safe

Score 85/100

Chatwing Live Group Chat – HTML5 + Chat Apps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "chatwing" v2.4.5 plugin presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has no recorded critical vulnerabilities or CVEs. The plugin also correctly utilizes nonces for some entry points and performs external HTTP requests which can be a security concern if not handled properly, but there are no explicit indications of misuse here. However, there are significant areas of concern. The presence of a REST API route without a permission callback creates a direct unprotected entry point, which is a serious security risk. Additionally, the taint analysis reveals a high number of flows with unsanitized paths, indicating a potential for vulnerabilities if these paths are ever exposed to user input. The low percentage of properly escaped output further exacerbates this risk, as it could lead to cross-site scripting (XSS) vulnerabilities.

Key Concerns

  • REST API route without permission callback
  • High number of unsanitized paths in taint flows
  • Low percentage of properly escaped output
  • No capability checks
Vulnerabilities
None known

Chatwing Live Group Chat – HTML5 + Chat Apps Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Chatwing Live Group Chat – HTML5 + Chat Apps Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
42
19 escaped
Nonce Checks
2
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

31% escaped61 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

9 flows8 with unsanitized paths
my_login_form (oauth.php:28)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Chatwing Live Group Chat – HTML5 + Chat Apps Attack Surface

Entry Points2
Unprotected1

REST API Routes 1

POST/wp-json/chatwing/v1/oauth/authenticateclasses\Application.php:37

Shortcodes 1

[chatwing] classes\Application.php:22
WordPress Hooks 14
actioninitchatwing.php:70
actionadmin_menuclasses\Admin.php:21
actionadmin_action_chatwing_save_tokenclasses\Admin.php:22
actionadmin_action_chatwing_save_settingsclasses\Admin.php:23
actionwidgets_initclasses\Application.php:29
actionrest_api_initclasses\Application.php:32
filterlogin_redirectclasses\Application.php:116
actionlogin_enqueue_scriptsoauth.php:101
actionlogin_footeroauth.php:102
actionlogin_formoauth.php:103
actionwp_loginoauth.php:104
actionregister_formregistration.php:92
filterregistration_errorsregistration.php:93
actionuser_registerregistration.php:94
Maintenance & Trust

Chatwing Live Group Chat – HTML5 + Chat Apps Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedAug 13, 2018
PHP min version
Downloads26K

Community Trust

Rating88/100
Number of ratings18
Active installs10
Developer Profile

Chatwing Live Group Chat – HTML5 + Chat Apps Developer Profile

ChatWingTeam

3 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Chatwing Live Group Chat – HTML5 + Chat Apps

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chatwing/chatwing-sdk/build/chatwing-sdk.css/wp-content/plugins/chatwing/chatwing-sdk/build/chatwing-sdk.js/wp-content/plugins/chatwing/classes/css/chatwing-admin.css/wp-content/plugins/chatwing/classes/css/chatwing-widget.css
Script Paths
/wp-content/plugins/chatwing/chatwing-sdk/build/chatwing-sdk.js
Version Parameters
chatwing/chatwing-sdk/build/chatwing-sdk.css?ver=chatwing/chatwing-sdk/build/chatwing-sdk.js?ver=

HTML / DOM Fingerprints

CSS Classes
chatwing-widget-containerchatwing-widget-messagechatwing-input-groupchatwing-send-messagechatwing-usernamechatwing-avatar
HTML Comments
<!-- Chatwing Integration Plugins * @package Chatwing\IntegrationPlugins\Wordpress * @author chatwing -->
Data Attributes
data-chatwing-iddata-chatwing-app-iddata-chatwing-user-id
JS Globals
window.ChatwingSDKChatwingSDK.init
REST Endpoints
/wp-json/chatwing/v1/oauth/authenticate
Shortcode Output
[chatwing]
FAQ

Frequently Asked Questions about Chatwing Live Group Chat – HTML5 + Chat Apps