Customer Support Software, Live Chat, & Marketing Automation Security & Risk Analysis

wordpress.org/plugins/formilla-chat-and-marketing

Customer Support Software for WooCommerce with live chat, real-time cart information, email, and in-app messaging using Formilla Edge marketing automa …

40 active installs v1.3 PHP + WP 2.7+ Updated Dec 1, 2025
chatcustomer-support-softwarefree-live-chatlive-chatlive-chat-software
100
A · Safe
CVEs total1
Unpatched0
Last CVEApr 21, 2023
Safety Verdict

Is Customer Support Software, Live Chat, & Marketing Automation Safe to Use in 2026?

Generally Safe

Score 100/100

Customer Support Software, Live Chat, & Marketing Automation has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 21, 2023Updated 4mo ago
Risk Assessment

The formilla-chat-and-marketing plugin version 1.3 exhibits a mixed security posture. While it demonstrates good practices by not utilizing raw SQL queries and appears to have addressed its past vulnerabilities, there are significant concerns regarding its attack surface. The presence of three AJAX handlers, with two lacking authentication checks, creates an immediate risk. This means that unauthorized users could potentially interact with these endpoints, leading to unintended actions or information disclosure.

The static analysis reveals a moderate level of output escaping, with 50% of outputs not being properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of this vulnerability type. Fortunately, the taint analysis did not reveal any critical or high-severity unsanitized flows, which is a positive sign. The plugin's vulnerability history shows one past medium-severity issue related to XSS, which has since been patched. The absence of currently unpatched vulnerabilities is encouraging, but the pattern of past XSS issues, coupled with incomplete output escaping, warrants vigilance.

In conclusion, the plugin has strengths in its SQL handling and its responsiveness to past vulnerabilities. However, the significant number of unprotected AJAX endpoints and the incomplete output escaping are notable weaknesses. These areas represent the most immediate risks and should be prioritized for remediation. Users should be aware of these potential weaknesses and ensure they are running the latest version of the plugin, as well as any other security measures they have in place.

Key Concerns

  • AJAX handlers without authentication checks
  • Output escaping is not consistently applied
  • One past medium vulnerability for XSS
Vulnerabilities
1

Customer Support Software, Live Chat, & Marketing Automation Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-a5436d14-cbb5-420f-9f3a-698ce59c1e1e-formilla-chat-and-marketingmedium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Formilla Chat and Marketing Automation <= 1.0 - Authenticated (Administrator+) Cross-Site Scripting via 'FormillaToolsID'

Apr 21, 2023 Patched in 1.1 (277d)
Code Analysis
Analyzed Mar 16, 2026

Customer Support Software, Live Chat, & Marketing Automation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped10 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
fcm_save_formilla_tools_settings (formilla-chat-and-marketing.php:35)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Customer Support Software, Live Chat, & Marketing Automation Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 3

authwp_ajax_fcm_save_formilla_tools_settingsformilla-chat-and-marketing.php:17
authwp_ajax_formilla_tools_get_wc_cart_ajax_actionformilla-chat-and-marketing.php:22
noprivwp_ajax_formilla_tools_get_wc_cart_ajax_actionformilla-chat-and-marketing.php:23
WordPress Hooks 6
actioninitformilla-chat-and-marketing.php:15
actionwp_footerformilla-chat-and-marketing.php:16
filterplugin_action_linksformilla-chat-and-marketing.php:18
filterplugin_row_metaformilla-chat-and-marketing.php:19
actionadmin_menuformilla-chat-and-marketing.php:30
actionadmin_menuformilla-chat-and-marketing.php:31
Maintenance & Trust

Customer Support Software, Live Chat, & Marketing Automation Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

Customer Support Software, Live Chat, & Marketing Automation Developer Profile

formilla-live-chat

1 plugin · 40 total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
277 days
View full developer profile
Detection Fingerprints

How We Detect Customer Support Software, Live Chat, & Marketing Automation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/formilla-chat-and-marketing/main-logo.png
Script Paths
/wp-content/plugins/formilla-chat-and-marketing/formilla-chat-and-marketing.php

HTML / DOM Fingerprints

CSS Classes
settings-error
Data Attributes
FormillaToolsIDformillaSettingsSubmit
JS Globals
FormillaformillaUpdateWcCartfcmSaveFormillaToolsSettingsfcmVerifyFormillaToolsID
REST Endpoints
/wp-json/formilla-chat-and-marketing
FAQ

Frequently Asked Questions about Customer Support Software, Live Chat, & Marketing Automation