
Cheerlink Livechat, AI Chatbot Security & Risk Analysis
wordpress.org/plugins/cheerlink-ai-chatCheerlink Livechat, an AI Chatbot, effortlessly integrates with your site to enhance customer service and sales.
Is Cheerlink Livechat, AI Chatbot Safe to Use in 2026?
Generally Safe
Score 92/100Cheerlink Livechat, AI Chatbot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cheerlink-ai-chat plugin v1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and a high percentage of properly escaped output, minimizing risks of SQL injection and XSS from typical data handling.
However, there are significant concerns, primarily stemming from its attack surface. The presence of a REST API route without permission callbacks represents a critical vulnerability. This means any unauthenticated user could potentially interact with this endpoint, leading to unintended actions or information disclosure depending on its functionality. The absence of nonce checks on any entry points further exacerbates this, as it bypasses a fundamental WordPress security mechanism designed to prevent CSRF attacks.
The plugin's vulnerability history is clean, with no recorded CVEs. While this is a positive indicator, it does not negate the inherent risks identified in the static analysis. The lack of past vulnerabilities could be due to its limited adoption, lack of rigorous historical auditing, or simply good fortune. The overall conclusion is that while the plugin appears to handle data and SQL responsibly, its unprotected REST API route and lack of nonce checks present a significant, exploitable risk.
Key Concerns
- REST API route without permission callback
- 0 Nonce checks for entry points
Cheerlink Livechat, AI Chatbot Security Vulnerabilities
Cheerlink Livechat, AI Chatbot Code Analysis
Output Escaping
Cheerlink Livechat, AI Chatbot Attack Surface
REST API Routes 1
WordPress Hooks 7
Maintenance & Trust
Cheerlink Livechat, AI Chatbot Maintenance & Trust
Maintenance Signals
Community Trust
Cheerlink Livechat, AI Chatbot Alternatives
SendPulse – Live Chat and Chatbot
sendpulse-live-chat-and-chatbot
Free live chat and chatbot plugin by SendPulse. Add live chats to your website to engage your site visitors and help solve their issues in real time.
Tidio – Live Chat & AI Chatbots
tidio-live-chat
Add Tidio Live Chat to your WordPress for free to answer customers’ questions, engage website visitors, generate leads, and increase sales.
Buttonizer – Live Chat, AI Chatbot, & Chat Widgets
button-contact-vr
Powerful platform with Live Chat, AI Chatbots, and Real-Time Visitor Monitoring! Also, create Call, Email, SMS, & Contact buttons to increase conv …
Crisp – Live Chat and Chatbot
crisp
A Free, one-click-to-install, Live Chat and chatbot plugin. No coding skills are required. Used by more than 30 000 customers on WordPress.
Zoho SalesIQ – Live chat, chatbots, and visitor tracking
zoho-salesiq
Identify, engage and convert website visitors with live chat and visitor analytics.
Cheerlink Livechat, AI Chatbot Developer Profile
1 plugin · 0 total installs
How We Detect Cheerlink Livechat, AI Chatbot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cheerlink-ai-chat/src/cheerlink.jshttps://cdn.cheerlink.app/widget/cheerlink.jscheerlink-ai-chat/src/cheerlink.js?ver=cheerlink.js?appId=&source=WORDPRESSHTML / DOM Fingerprints
data-cheerlink-appidwindow.cheerlinkSettingswindow.CheerlinkWidget/wp-json/cheerlink-ai-chat/v1/messages