
Customer Support Software, Live Chat, & Marketing Automation Security & Risk Analysis
wordpress.org/plugins/formilla-chat-and-marketingCustomer Support Software for WooCommerce with live chat, real-time cart information, email, and in-app messaging using Formilla Edge marketing automa …
Is Customer Support Software, Live Chat, & Marketing Automation Safe to Use in 2026?
Generally Safe
Score 100/100Customer Support Software, Live Chat, & Marketing Automation has a strong security track record. Known vulnerabilities have been patched promptly.
The formilla-chat-and-marketing plugin version 1.3 exhibits a mixed security posture. While it demonstrates good practices by not utilizing raw SQL queries and appears to have addressed its past vulnerabilities, there are significant concerns regarding its attack surface. The presence of three AJAX handlers, with two lacking authentication checks, creates an immediate risk. This means that unauthorized users could potentially interact with these endpoints, leading to unintended actions or information disclosure.
The static analysis reveals a moderate level of output escaping, with 50% of outputs not being properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of this vulnerability type. Fortunately, the taint analysis did not reveal any critical or high-severity unsanitized flows, which is a positive sign. The plugin's vulnerability history shows one past medium-severity issue related to XSS, which has since been patched. The absence of currently unpatched vulnerabilities is encouraging, but the pattern of past XSS issues, coupled with incomplete output escaping, warrants vigilance.
In conclusion, the plugin has strengths in its SQL handling and its responsiveness to past vulnerabilities. However, the significant number of unprotected AJAX endpoints and the incomplete output escaping are notable weaknesses. These areas represent the most immediate risks and should be prioritized for remediation. Users should be aware of these potential weaknesses and ensure they are running the latest version of the plugin, as well as any other security measures they have in place.
Key Concerns
- AJAX handlers without authentication checks
- Output escaping is not consistently applied
- One past medium vulnerability for XSS
Customer Support Software, Live Chat, & Marketing Automation Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Formilla Chat and Marketing Automation <= 1.0 - Authenticated (Administrator+) Cross-Site Scripting via 'FormillaToolsID'
Customer Support Software, Live Chat, & Marketing Automation Code Analysis
Output Escaping
Data Flow Analysis
Customer Support Software, Live Chat, & Marketing Automation Attack Surface
AJAX Handlers 3
WordPress Hooks 6
Maintenance & Trust
Customer Support Software, Live Chat, & Marketing Automation Maintenance & Trust
Maintenance Signals
Community Trust
Customer Support Software, Live Chat, & Marketing Automation Alternatives
Output Desk Live Chat
output-desk-live-chat
Free powerful Live Chat to engage your website visitors / customers in real-time and improve your sales.
Tawk.To Live Chat
tawkto-live-chat
(OFFICIAL tawk.to plugin) Instantly chat with visitors on your website with the free tawk.to chat widget. Website: http://tawk.to
3CX Free Live Chat, Calls & Messaging
wp-live-chat-support
Chat with your website visitors in real-time for free! Engage with your customers and increase sales.
Tidio – Live Chat & AI Chatbots
tidio-live-chat
Add Tidio Live Chat to your WordPress for free to answer customers’ questions, engage website visitors, generate leads, and increase sales.
Crisp – Live Chat and Chatbot
crisp
A Free, one-click-to-install, Live Chat and chatbot plugin. No coding skills are required. Used by more than 30 000 customers on WordPress.
Customer Support Software, Live Chat, & Marketing Automation Developer Profile
1 plugin · 40 total installs
How We Detect Customer Support Software, Live Chat, & Marketing Automation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formilla-chat-and-marketing/main-logo.png/wp-content/plugins/formilla-chat-and-marketing/formilla-chat-and-marketing.phpHTML / DOM Fingerprints
settings-errorFormillaToolsIDformillaSettingsSubmitFormillaformillaUpdateWcCartfcmSaveFormillaToolsSettingsfcmVerifyFormillaToolsID/wp-json/formilla-chat-and-marketing