Live Chat by Formilla – Real-time Chat & Chatbots Plugin Security & Risk Analysis

wordpress.org/plugins/formilla-live-chat

Live chat software with real-time visitor monitoring and chatbots! Live chat with your visitors for free or use a chatbot to automate self-help.

3K active installs v1.4 PHP + WP 2.7+ Updated Dec 1, 2025
chatchat-botchatbotlive-chatlivechat
100
A · Safe
CVEs total1
Unpatched0
Last CVEApr 21, 2023
Safety Verdict

Is Live Chat by Formilla – Real-time Chat & Chatbots Plugin Safe to Use in 2026?

Generally Safe

Score 100/100

Live Chat by Formilla – Real-time Chat & Chatbots Plugin has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 21, 2023Updated 4mo ago
Risk Assessment

The `formilla-live-chat` plugin version 1.4 exhibits a generally good security posture with strong adherence to modern WordPress security practices. The static analysis reveals a very limited attack surface, with a single AJAX handler that benefits from both nonce and capability checks, effectively mitigating direct unauthorized access. The absence of dangerous functions, file operations, and external HTTP requests is also a positive sign. Furthermore, all SQL queries are secured with prepared statements, and there are no identified taint flows indicating potential code injection vulnerabilities. The vulnerability history shows a single medium-severity CVE in the past, which is now patched, suggesting the developers address security issues promptly. However, the static analysis did identify that 29% of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered without adequate sanitization. While the existing CVEs are resolved, this unescaped output remains a potential area of concern that warrants attention.

Key Concerns

  • Output not properly escaped
Vulnerabilities
1

Live Chat by Formilla – Real-time Chat & Chatbots Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-23727medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Formilla Live Chat <= 1.3.0 - Authenticated (Administrator+) Cross-Site Scripting via 'FormillaID'

Apr 21, 2023 Patched in 1.3.1 (277d)
Code Analysis
Analyzed Mar 16, 2026

Live Chat by Formilla – Real-time Chat & Chatbots Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped7 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
save_formilla_settings (formilla-live-chat.php:31)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Live Chat by Formilla – Real-time Chat & Chatbots Plugin Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_save_formilla_settingsformilla-live-chat.php:16
WordPress Hooks 6
actioninitformilla-live-chat.php:14
actionwp_footerformilla-live-chat.php:15
filterplugin_action_linksformilla-live-chat.php:17
filterplugin_row_metaformilla-live-chat.php:18
actionadmin_menuformilla-live-chat.php:26
actionadmin_menuformilla-live-chat.php:27
Maintenance & Trust

Live Chat by Formilla – Real-time Chat & Chatbots Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version
Downloads193K

Community Trust

Rating96/100
Number of ratings116
Active installs3K
Developer Profile

Live Chat by Formilla – Real-time Chat & Chatbots Plugin Developer Profile

zgilyana

2 plugins · 3K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
277 days
View full developer profile
Detection Fingerprints

How We Detect Live Chat by Formilla – Real-time Chat & Chatbots Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/formilla-live-chat/main-logo.png
Script Paths
https://www.formilla.com/scripts/feedback.js

HTML / DOM Fingerprints

CSS Classes
formillachatformillawindowholder
Data Attributes
id="formillachat"id="formillawindowholder"name="FormillaID"id="FormillaID"name="formillaSettingsSubmit"id="formillaSettingsSubmit"+3 more
JS Globals
Formilla
REST Endpoints
/wp-admin/admin-ajax.php
FAQ

Frequently Asked Questions about Live Chat by Formilla – Real-time Chat & Chatbots Plugin