
Live Chat with Messenger Customer Chat Security & Risk Analysis
wordpress.org/plugins/fb-messenger-live-chatSupport your customers via Facebook Messenger Live Chat conveniently from your own website.
Is Live Chat with Messenger Customer Chat Safe to Use in 2026?
Generally Safe
Score 99/100Live Chat with Messenger Customer Chat has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "fb-messenger-live-chat" v1.5.0 exhibits a generally good security posture based on the static analysis. It has a small attack surface, with all identified entry points (AJAX handlers) protected by nonce checks. Crucially, it avoids dangerous functions, uses prepared statements for all SQL queries, and has no file operations or external HTTP requests, which are common sources of vulnerabilities. The lack of critical or high-severity taint flows further indicates careful handling of input data.
However, there are areas for improvement. While the plugin has a low number of outputs, one-third of them are not properly escaped, introducing a potential risk of Cross-Site Scripting (XSS). Furthermore, the absence of capability checks on the AJAX handlers, despite the presence of nonce checks, could still allow unauthorized users to trigger actions if the nonce check were bypassed or if the actions themselves are sensitive. The plugin's vulnerability history, while dated, shows a past high-severity XSS vulnerability, suggesting a need for continued vigilance in input sanitization and output escaping.
In conclusion, the plugin demonstrates strong defensive coding practices in many areas. The primary concerns are the unescaped outputs and the lack of capability checks on AJAX endpoints. While the past vulnerability is a concern, its age and the current analysis suggest it may have been addressed. The plugin is reasonably secure but could be further hardened.
Key Concerns
- Unescaped output detected (33% of outputs)
- AJAX handlers lack capability checks
Live Chat with Messenger Customer Chat Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Live Chat with Messenger Customer Chat <= 1.4.6 - Unauthenticated Stored Cross-Site Scripting
Live Chat with Messenger Customer Chat Code Analysis
Output Escaping
Data Flow Analysis
Live Chat with Messenger Customer Chat Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
Live Chat with Messenger Customer Chat Maintenance & Trust
Maintenance Signals
Community Trust
Live Chat with Messenger Customer Chat Alternatives
Cresta Social Messenger
cresta-facebook-messenger
Allow your users and customers to contact you via Facebook Messenger with a single click.
Replain
replain
Be in touch with your clients through Telegram, WhatsApp or Facebook Messenger. Fast, functional and free live-chat service for your website.
Re:amaze Helpdesk & Live Chat
reamaze
Boost sales conversions, loyalty, and engagement. Manage your social, email, sms, live chat, FAQ for your WordPress or WooCommerce store.
Wpmethods Social Chat Floating Icons
wpmethods-social-chat-floating-icons
Display live chat floating icons of any social media like WhatsApp, Messenger, Telegram, etc on your WordPress website.
Leaddevs Messenger Live Chatbot
leaddevs-chatbot
Leaddevs Messenger Live Chatbot
Live Chat with Messenger Customer Chat Developer Profile
12 plugins · 4K total installs
How We Detect Live Chat with Messenger Customer Chat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fb-messenger-live-chat/assets/css/style.css/wp-content/plugins/fb-messenger-live-chat/assets/js/main.js/wp-content/plugins/fb-messenger-live-chat/zotabox.png/wp-content/plugins/fb-messenger-live-chat/assets/images/logo-zotabox.png/wp-content/plugins/fb-messenger-live-chat/assets/js/main.jsfb-messenger-live-chat/assets/js/main.js?v=HTML / DOM Fingerprints
ztb-register-formztb-submit-buttonztb-wrapperztb-logoztb-code-wrapperztb-titleaccount-inputztb-buttonzb-plugin="zb_fbc"ZBT_WP_ADMIN_URLZTB_BASE_URL