
Live Chat by Formilla – Real-time Chat & Chatbots Plugin Security & Risk Analysis
wordpress.org/plugins/formilla-live-chatLive chat software with real-time visitor monitoring and chatbots! Live chat with your visitors for free or use a chatbot to automate self-help.
Is Live Chat by Formilla – Real-time Chat & Chatbots Plugin Safe to Use in 2026?
Generally Safe
Score 100/100Live Chat by Formilla – Real-time Chat & Chatbots Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The `formilla-live-chat` plugin version 1.4 exhibits a generally good security posture with strong adherence to modern WordPress security practices. The static analysis reveals a very limited attack surface, with a single AJAX handler that benefits from both nonce and capability checks, effectively mitigating direct unauthorized access. The absence of dangerous functions, file operations, and external HTTP requests is also a positive sign. Furthermore, all SQL queries are secured with prepared statements, and there are no identified taint flows indicating potential code injection vulnerabilities. The vulnerability history shows a single medium-severity CVE in the past, which is now patched, suggesting the developers address security issues promptly. However, the static analysis did identify that 29% of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered without adequate sanitization. While the existing CVEs are resolved, this unescaped output remains a potential area of concern that warrants attention.
Key Concerns
- Output not properly escaped
Live Chat by Formilla – Real-time Chat & Chatbots Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Formilla Live Chat <= 1.3.0 - Authenticated (Administrator+) Cross-Site Scripting via 'FormillaID'
Live Chat by Formilla – Real-time Chat & Chatbots Plugin Code Analysis
Output Escaping
Data Flow Analysis
Live Chat by Formilla – Real-time Chat & Chatbots Plugin Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Live Chat by Formilla – Real-time Chat & Chatbots Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Live Chat by Formilla – Real-time Chat & Chatbots Plugin Alternatives
Tidio – Live Chat & AI Chatbots
tidio-live-chat
Add Tidio Live Chat to your WordPress for free to answer customers’ questions, engage website visitors, generate leads, and increase sales.
Crisp – Live Chat and Chatbot
crisp
A Free, one-click-to-install, Live Chat and chatbot plugin. No coding skills are required. Used by more than 30 000 customers on WordPress.
Zoho SalesIQ – Live chat, chatbots, and visitor tracking
zoho-salesiq
Identify, engage and convert website visitors with live chat and visitor analytics.
LiveChat – Live Chat Plugin for WP Websites
wp-live-chat-software-for-wordpress
Best live chat and help desk plugin for WordPress websites. Add the LiveChat widget to engage visitors and provide real‑time customer support! 🚀
Chatra Live Chat + ChatBot + Cart Saver
chatra-live-chat
Powerful chat / chatbot / Fb chat and cart saver app for Wordpress and WooCommerce, free as long as you want.
Live Chat by Formilla – Real-time Chat & Chatbots Plugin Developer Profile
2 plugins · 3K total installs
How We Detect Live Chat by Formilla – Real-time Chat & Chatbots Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formilla-live-chat/main-logo.pnghttps://www.formilla.com/scripts/feedback.jsHTML / DOM Fingerprints
formillachatformillawindowholderid="formillachat"id="formillawindowholder"name="FormillaID"id="FormillaID"name="formillaSettingsSubmit"id="formillaSettingsSubmit"+3 moreFormilla/wp-admin/admin-ajax.php