
Cnvrse Security & Risk Analysis
wordpress.org/plugins/cnvrseAdd live chat to WordPress in seconds. Reply from your dashboard or Telegram. No external accounts, no monthly fees, 100% privacy-focused.
Is Cnvrse Safe to Use in 2026?
Mostly Safe
Score 78/100Cnvrse is generally safe to use. 1 past CVE were resolved. Keep it updated.
The cnvrse plugin v026.02.10.20 exhibits a mixed security posture. On the positive side, it demonstrates good practices by implementing nonce checks and capability checks on its identified entry points, and the vast majority of its SQL queries utilize prepared statements, which is a significant strength. However, several concerns warrant attention. The presence of the `shell_exec` function is a critical red flag, as it can be a vector for remote code execution if not handled with extreme caution and proper sanitization.
Taint analysis reveals two high-severity flows with unsanitized paths, indicating potential vulnerabilities where user-supplied data could be manipulated to affect file paths or other sensitive operations. While the overall attack surface of AJAX handlers is small and appears to be protected by checks, these taint flows suggest that the sanitization within those handlers or related functions might be insufficient. Furthermore, the plugin has a known CVE history, including a currently unpatched medium-severity vulnerability related to Authorization Bypass Through User-Controlled Key. This pattern suggests a historical weakness in how user input is validated for authorization purposes.
In conclusion, while cnvrse implements some robust security measures, the use of dangerous functions like `shell_exec`, the high-severity unsanitized taint flows, and the existing unpatched CVE point to significant areas of risk that require immediate attention and remediation.
Key Concerns
- Unpatched CVE exists (medium severity)
- High severity taint flows with unsanitized paths
- Dangerous function detected (shell_exec)
- Output escaping only 69% properly escaped
- SQL queries with prepared statements < 100%
Cnvrse Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Cnvrse <= 026.02.10.20 - Unauthenticated Insecure Direct Object Reference
Cnvrse Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Cnvrse Attack Surface
AJAX Handlers 2
WordPress Hooks 47
Scheduled Events 16
Maintenance & Trust
Cnvrse Maintenance & Trust
Maintenance Signals
Community Trust
Cnvrse Alternatives
LiveChat – Live Chat Plugin for WP Websites
wp-live-chat-software-for-wordpress
Best live chat and help desk plugin for WordPress websites. Add the LiveChat widget to engage visitors and provide real‑time customer support! 🚀
Lime Connect (formerly Userlike) – WordPress Live Chat plugin
userlike
Free live chat plugin to chat with the visitors of your website. Integrate a beautiful and fully customizable chat box. Hosted in Europe.
Chat Bro Live Group Chat
chatbro
Chat Bro - live Chat for your website. Turns your Telegram Chat or VK Chat into Live Chat on your website. Allows your visitors to Chat in live group …
Chatlio Live Chat for Slack
chatlio
Chatlio lets you talk with your customers using Slack directly from your WordPress site.
EngageBay Live Chat Support
engagebay-livechat
Add real-time live chat support to your WordPress site with EngageBay. Connect instantly with visitors, boost engagement, and grow your business.
Cnvrse Developer Profile
1 plugin · 0 total installs
How We Detect Cnvrse
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cnvrse/assets/css/cnvrse-admin.css/wp-content/plugins/cnvrse/assets/js/cnvrse-admin-telegram.js/wp-content/plugins/cnvrse/assets/js/cnvrse-core.js/wp-content/plugins/cnvrse/assets/js/cnvrse-admin.js/wp-content/plugins/cnvrse/assets/css/cnvrse.css/wp-content/plugins/cnvrse/assets/js/cnvrse.js/wp-content/plugins/cnvrse/assets/js/cnvrse-admin-telegram.js/wp-content/plugins/cnvrse/assets/js/cnvrse-core.js/wp-content/plugins/cnvrse/assets/js/cnvrse-admin.js/wp-content/plugins/cnvrse/assets/js/cnvrse.jscnvrse-admin.css?ver=cnvrse-admin-telegram.js?ver=cnvrse-core.js?ver=cnvrse-admin.js?ver=cnvrse.css?ver=cnvrse.js?ver=HTML / DOM Fingerprints
cnvrse-admin-pagecnvrse-chat-widgetcnvrse-chat-widget-init<!-- Cnvrse Chat Widget --><!-- Do not edit directly. This file is automatically generated by Cnvrse. --><!-- Copyright (C) 2010-2025, Renzo Johnson (email: renzo at cnvrse.com) -->data-cnvrse-widget-optionsdata-cnvrse-chat-idcnvrseAdminParamscnvrseDashboardV2cnvrseChatWidgetConfig/wp-json/cnvrse/v1/messages/wp-json/cnvrse/v1/settings[cnvrse_chat]