Click2Magic Live Chat Security & Risk Analysis

wordpress.org/plugins/click2magic-live-chat

Click2Magic Live chat and help desk software plugin for WordPress. Add Click2Magic LiveChat (live chat and help desk software) to your WordPress.

0 active installs v1.2.1 PHP + WP 3.1+ Updated Mar 10, 2020
chat-pluginclick2magic-live-chatclick2magic-live-chat-pluginclick2magic-live-supportwordpress-click2magic-live-chat
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Click2Magic Live Chat Safe to Use in 2026?

Generally Safe

Score 85/100

Click2Magic Live Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The click2magic-live-chat plugin version 1.2.1 presents a generally positive security posture based on the provided static analysis. The plugin exhibits no identified CVEs, indicating a good track record for security. Furthermore, the absence of a large attack surface, dangerous functions, or file operations suggests careful development. The code also shows a commitment to secure practices with all SQL queries using prepared statements and a capability check present.

However, there are areas for improvement. The low percentage of properly escaped output (33%) is a significant concern. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled securely before being displayed. The complete lack of nonce checks on AJAX handlers, while the attack surface is currently zero, means that if any AJAX handlers are introduced in the future without proper authorization and nonce validation, the plugin could become vulnerable to Cross-Site Request Forgery (CSRF) attacks.

In conclusion, while the plugin has strengths in its lack of known vulnerabilities and secure database interactions, the insufficient output escaping and potential future risks related to AJAX handlers warrant attention. Addressing these specific areas would significantly enhance the plugin's overall security.

Key Concerns

  • Low output escaping (33%)
  • No nonce checks on AJAX handlers
Vulnerabilities
None known

Click2Magic Live Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Click2Magic Live Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped3 total outputs
Attack Surface

Click2Magic Live Chat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initc2mlivechat.php:85
actionadmin_enqueue_scriptsc2mlivechat.php:86
actionadmin_menuc2mlivechat.php:87
actionwp_footerc2mlivechat.php:92
Maintenance & Trust

Click2Magic Live Chat Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedMar 10, 2020
PHP min version
Downloads917

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Click2Magic Live Chat Developer Profile

click2magic

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Click2Magic Live Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/click2magic-live-chat/includes/c2mlivechat-options.php

HTML / DOM Fingerprints

HTML Comments
<!-- Start Click2Magic Live Chat plugin for WordPress --><!-- Stop Click2Magic Live Chat plugin for WordPress -->
JS Globals
c2mApiJs
FAQ

Frequently Asked Questions about Click2Magic Live Chat