EchBay Live Chat Security & Risk Analysis

wordpress.org/plugins/echbay-facebook-messenger

Add Facebook customerchat, Facebook messenger box or another widget chat to your website (tawk.to, subiz.vn). Easily custom your style for chat.

70 active installs v1.2.7 PHP + WP 4.8+ Updated Nov 28, 2025
facebook-commentfacebook-customerchatfacebook-messengermessengertawk
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EchBay Live Chat Safe to Use in 2026?

Generally Safe

Score 100/100

EchBay Live Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The static analysis of the echbay-facebook-messenger plugin v1.2.7 reveals a generally strong security posture, with no identified attack surface entries lacking authentication or permission checks. The absence of dangerous functions, external HTTP requests, and critical/high severity taint flows further contributes to this positive assessment. The plugin also demonstrates good practice by including nonce and capability checks. However, a significant concern arises from the sole SQL query not utilizing prepared statements, posing a potential SQL injection risk. Additionally, only 24% of output is properly escaped, leaving room for cross-site scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting a history of responsible development. Despite the lack of known CVEs, the identified code signals warrant attention to mitigate potential risks.

Key Concerns

  • SQL query not using prepared statements
  • Low percentage of properly escaped output
Vulnerabilities
None known

EchBay Live Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

EchBay Live Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
13
4 escaped
Nonce Checks
1
Capability Checks
1
File Operations
5
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

24% escaped17 total outputs
Attack Surface

EchBay Live Chat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuefm.php:376
actionwp_footerefm.php:382
Maintenance & Trust

EchBay Live Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version
Downloads15K

Community Trust

Rating100/100
Number of ratings1
Active installs70
Developer Profile

EchBay Live Chat Developer Profile

Dao Quoc Dai

8 plugins · 2K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect EchBay Live Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/echbay-facebook-messenger/js/efm-admin.js/wp-content/plugins/echbay-facebook-messenger/js/frontend.js/wp-content/plugins/echbay-facebook-messenger/css/efm-admin.css/wp-content/plugins/echbay-facebook-messenger/style.css
Script Paths
/wp-content/plugins/echbay-facebook-messenger/js/efm-admin.js/wp-content/plugins/echbay-facebook-messenger/js/frontend.js
Version Parameters
echbay-facebook-messenger/style.css?ver=echbay-facebook-messenger/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
efm-chat-widgetefm-livechat
HTML Comments
<!-- Start of EchBay Live Chat Script (by EchBay Live Chat) --><!-- EchBay Live Chat --><!-- End of EchBay Live Chat Script -->
Data Attributes
data-widget-iddata-plugin-version
JS Globals
efm_data
FAQ

Frequently Asked Questions about EchBay Live Chat