Czater.pl – live chat i telefon Security & Risk Analysis

wordpress.org/plugins/czater

Czater.pl to darmowy live chat https://www.czater.pl, który możesz w prosty i szybki sposób zainstalować w swojej witrynie na Wordpress.

300 active installs v1.0.5 PHP + WP 3.0.1+ Updated Sep 4, 2020
czat-na-stroneczaterfree-livechatlive-chatlivechat
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEApr 9, 2025
Safety Verdict

Is Czater.pl – live chat i telefon Safe to Use in 2026?

Use With Caution

Score 63/100

Czater.pl – live chat i telefon has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Apr 9, 2025Updated 5yr ago
Risk Assessment

The "czater" plugin v1.0.5 exhibits a mixed security posture. On the positive side, the static analysis reveals a clean attack surface with no apparent entry points like AJAX handlers, REST API routes, or shortcodes that are exposed without authentication. Furthermore, the plugin demonstrates good practice by utilizing prepared statements for all its SQL queries, eliminating the risk of SQL injection through dynamic queries. There are also no file operations or external HTTP requests, which limits potential attack vectors.

However, several concerns arise from the analysis. A significant red flag is the low percentage of properly escaped output (22%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while not reporting critical or high severity flows, did identify two flows with unsanitized paths, which could potentially be exploited if an attacker can manipulate input that reaches these paths.

The vulnerability history is particularly concerning, with one unpatched medium severity CVE. The fact that this CVE is a Cross-Site Request Forgery (CSRF) vulnerability, and the plugin has a history of this type of issue, suggests a recurring pattern of insufficient CSRF protection. The presence of an unpatched medium vulnerability, coupled with the high rate of unescaped output, significantly elevates the risk associated with this plugin. While the plugin has a small attack surface and uses prepared statements, the potential for XSS and the existing unpatched CSRF vulnerability necessitate caution.

Key Concerns

  • Unpatched CVE: 1 Medium
  • Output escaping: 22% properly escaped
  • Taint flows with unsanitized paths: 2
  • Vulnerability history: Common CSRF, 1 unpatched
Vulnerabilities
1

Czater.pl – live chat i telefon Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32624medium · 6.1Cross-Site Request Forgery (CSRF)

Czater.pl – live chat i telefon <= 1.0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Apr 9, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Czater.pl – live chat i telefon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

22% escaped9 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
czater_settings_page (czater.php:97)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Czater.pl – live chat i telefon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_headczater.php:144
actionadmin_initczater.php:146
actionadmin_menuczater.php:147
Maintenance & Trust

Czater.pl – live chat i telefon Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedSep 4, 2020
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

Czater.pl – live chat i telefon Developer Profile

czater

2 plugins · 300 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Czater.pl – live chat i telefon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/czater/assets/iconC.png

HTML / DOM Fingerprints

Data Attributes
name="czaterCode"name="czaterAutoCompliteLogin"name="czaterAutoCompliteEmail"name="send"
JS Globals
window.$czater$czater
FAQ

Frequently Asked Questions about Czater.pl – live chat i telefon