
Crisp – Live Chat and Chatbot Security & Risk Analysis
wordpress.org/plugins/crispA Free, one-click-to-install, Live Chat and chatbot plugin. No coding skills are required. Used by more than 30 000 customers on WordPress.
Is Crisp – Live Chat and Chatbot Safe to Use in 2026?
Generally Safe
Score 99/100Crisp – Live Chat and Chatbot has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'crisp' version 0.48 exhibits a generally good security posture based on static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points indicates a minimal attack surface. The code also demonstrates strong adherence to secure coding practices, with 100% of SQL queries using prepared statements, a high percentage of output escaping, and the presence of nonce and capability checks. The lack of dangerous functions, file operations, and external HTTP requests further bolsters its security. However, the plugin has a history of two known CVEs, one of high and one of medium severity, which were reportedly addressed. While no current unpatched vulnerabilities are listed, this history, along with the past presence of Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerabilities, suggests a need for continued vigilance and thorough testing with future updates. The static analysis did not reveal any critical or high-severity taint flows, which is a positive sign. Overall, the current version appears relatively secure, but the historical vulnerability pattern warrants cautious management.
Key Concerns
- Known high severity vulnerability in history
- Known medium severity vulnerability in history
- Some output not properly escaped (11%)
Crisp – Live Chat and Chatbot Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Crisp <= 0.44 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Crisp Live Chat <= 0.31 Cross-Site Request Forgery to Stored Cross-Site Scripting
Crisp – Live Chat and Chatbot Code Analysis
Output Escaping
Data Flow Analysis
Crisp – Live Chat and Chatbot Attack Surface
WordPress Hooks 10
Maintenance & Trust
Crisp – Live Chat and Chatbot Maintenance & Trust
Maintenance Signals
Community Trust
Crisp – Live Chat and Chatbot Alternatives
Tidio – Live Chat & AI Chatbots
tidio-live-chat
Add Tidio Live Chat to your WordPress for free to answer customers’ questions, engage website visitors, generate leads, and increase sales.
Support Board Cloud
support-board-cloud
A Free one-click-to-install Live Chat plugin. No coding skills required. Used by more than 2000 customers on WordPress.
SaleSmartly – Live Chat & Chat Bot Integrate
salesmartly-chat
Smart Sales Human service for your customers
Kimiyi AI – AI Chatbot with Digital Human, ChatGPT
kimiyiai-chatbot
Enhance your WordPress site with Free ChatGPT AI Chatbot. Easily create lifelike digital humans to Answer Questions with Voice, Provide 24/7 Support, …
MsgSmartly By Digidopt
msgsmartly-by-digidopt
A Free one-click-to-install Live Chat plugin. No coding skills required. Used by more than 2000 customers on WordPress.
Crisp – Live Chat and Chatbot Developer Profile
1 plugin · 20K total installs
How We Detect Crisp – Live Chat and Chatbot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/crisp/assets/stylesheets/style.css/wp-content/plugins/crisp/assets/images/icon-favicon.svgHTML / DOM Fingerprints
notice-crispcrisp