Live Chat with Messenger Customer Chat Security & Risk Analysis

wordpress.org/plugins/fb-messenger-live-chat

Support your customers via Facebook Messenger Live Chat conveniently from your own website.

3K active installs v1.5.0 PHP 7.0+ WP 3.0.1+ Updated Apr 14, 2025
customer-supportfacebookhelp-desklive-chatmessenger
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 17, 2019
Safety Verdict

Is Live Chat with Messenger Customer Chat Safe to Use in 2026?

Generally Safe

Score 99/100

Live Chat with Messenger Customer Chat has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 17, 2019Updated 11mo ago
Risk Assessment

The plugin "fb-messenger-live-chat" v1.5.0 exhibits a generally good security posture based on the static analysis. It has a small attack surface, with all identified entry points (AJAX handlers) protected by nonce checks. Crucially, it avoids dangerous functions, uses prepared statements for all SQL queries, and has no file operations or external HTTP requests, which are common sources of vulnerabilities. The lack of critical or high-severity taint flows further indicates careful handling of input data.

However, there are areas for improvement. While the plugin has a low number of outputs, one-third of them are not properly escaped, introducing a potential risk of Cross-Site Scripting (XSS). Furthermore, the absence of capability checks on the AJAX handlers, despite the presence of nonce checks, could still allow unauthorized users to trigger actions if the nonce check were bypassed or if the actions themselves are sensitive. The plugin's vulnerability history, while dated, shows a past high-severity XSS vulnerability, suggesting a need for continued vigilance in input sanitization and output escaping.

In conclusion, the plugin demonstrates strong defensive coding practices in many areas. The primary concerns are the unescaped outputs and the lack of capability checks on AJAX endpoints. While the past vulnerability is a concern, its age and the current analysis suggest it may have been addressed. The plugin is reasonably secure but could be further hardened.

Key Concerns

  • Unescaped output detected (33% of outputs)
  • AJAX handlers lack capability checks
Vulnerabilities
1

Live Chat with Messenger Customer Chat Security Vulnerabilities

CVEs by Year

1 CVE in 2019
2019
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

WF-465f29c0-99b9-4f7d-9817-3d3a49a2d943-fb-messenger-live-chathigh · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Live Chat with Messenger Customer Chat <= 1.4.6 - Unauthenticated Stored Cross-Site Scripting

May 17, 2019 Patched in 1.4.7 (1712d)
Code Analysis
Analyzed Mar 16, 2026

Live Chat with Messenger Customer Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
4 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped6 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
update_zb_fbc_code (fb-messenger-live-chat.php:181)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Live Chat with Messenger Customer Chat Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_update_zb_fbc_codefb-messenger-live-chat.php:178
noprivwp_ajax_update_zb_fbc_codefb-messenger-live-chat.php:179
WordPress Hooks 4
actionadmin_initfb-messenger-live-chat.php:15
actionadmin_noticesfb-messenger-live-chat.php:46
actionadmin_menufb-messenger-live-chat.php:82
actionwp_headfb-messenger-live-chat.php:175
Maintenance & Trust

Live Chat with Messenger Customer Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 14, 2025
PHP min version7.0
Downloads416K

Community Trust

Rating90/100
Number of ratings212
Active installs3K
Developer Profile

Live Chat with Messenger Customer Chat Developer Profile

Zotabox

12 plugins · 4K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
1712 days
View full developer profile
Detection Fingerprints

How We Detect Live Chat with Messenger Customer Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fb-messenger-live-chat/assets/css/style.css/wp-content/plugins/fb-messenger-live-chat/assets/js/main.js/wp-content/plugins/fb-messenger-live-chat/zotabox.png/wp-content/plugins/fb-messenger-live-chat/assets/images/logo-zotabox.png
Script Paths
/wp-content/plugins/fb-messenger-live-chat/assets/js/main.js
Version Parameters
fb-messenger-live-chat/assets/js/main.js?v=

HTML / DOM Fingerprints

CSS Classes
ztb-register-formztb-submit-buttonztb-wrapperztb-logoztb-code-wrapperztb-titleaccount-inputztb-button
Data Attributes
zb-plugin="zb_fbc"
JS Globals
ZBT_WP_ADMIN_URLZTB_BASE_URL
FAQ

Frequently Asked Questions about Live Chat with Messenger Customer Chat