ZupportDesk Live Chat Plugin (Free & Paid Plans) Security & Risk Analysis

wordpress.org/plugins/free-live-chat-support

ZupportDesk is a cloud-based Live Chat tool that allows your business to provide amazing customer support.

10 active installs v2.4 PHP + WP 3.0.1+ Updated Mar 12, 2018
chatchatslive-chatlivechatlivechat-online
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ZupportDesk Live Chat Plugin (Free & Paid Plans) Safe to Use in 2026?

Generally Safe

Score 85/100

ZupportDesk Live Chat Plugin (Free & Paid Plans) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "free-live-chat-support" plugin v2.4 exhibits a mixed security posture. On the positive side, the plugin reports zero known CVEs and zero unpatched vulnerabilities, suggesting a history of responsible patching or a lack of discovered exploitable flaws. The static analysis also indicates a complete absence of dangerous functions and 100% usage of prepared statements for SQL queries, which are strong indicators of good coding practices in these areas.

However, significant concerns arise from the analysis of output escaping and taint flows. A mere 25% of output escaping being proper indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied or dynamic data could be rendered without adequate sanitization. Furthermore, the taint analysis reveals three flows with unsanitized paths, which, while not classified as critical or high severity in this report, represent potential injection or information disclosure vectors. The complete lack of nonce and capability checks across all identified entry points (even though the reported attack surface is zero) also leaves the plugin susceptible to Cross-Site Request Forgery (CSRF) or unauthorized actions if any entry points were to be introduced or remain hidden.

In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL practices, the weaknesses in output escaping and taint sanitization, coupled with a lack of robust authentication and authorization checks on potential entry points, present notable risks. The user should be aware that while known vulnerabilities are absent, the code's structure suggests potential for undiscovered flaws, particularly related to XSS and potentially other injection attacks. The absence of any reported attack surface is encouraging but should be verified.

Key Concerns

  • Low percentage of properly escaped output
  • Taint flows with unsanitized paths
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

ZupportDesk Live Chat Plugin (Free & Paid Plans) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ZupportDesk Live Chat Plugin (Free & Paid Plans) Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

ZupportDesk Live Chat Plugin (Free & Paid Plans) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
3
Bundled Libraries
0

Output Escaping

25% escaped16 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
zupport_generateAcctPage (zupport.php:106)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ZupportDesk Live Chat Plugin (Free & Paid Plans) Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuzupport.php:17
actionadmin_enqueue_scriptszupport.php:339
actionwp_enqueue_scriptszupport.php:361
Maintenance & Trust

ZupportDesk Live Chat Plugin (Free & Paid Plans) Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 12, 2018
PHP min version
Downloads9K

Community Trust

Rating90/100
Number of ratings21
Active installs10
Developer Profile

ZupportDesk Live Chat Plugin (Free & Paid Plans) Developer Profile

dennis19814

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ZupportDesk Live Chat Plugin (Free & Paid Plans)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/free-live-chat-support/css/chat.css/wp-content/plugins/free-live-chat-support/css/style.css/wp-content/plugins/free-live-chat-support/js/chat.js/wp-content/plugins/free-live-chat-support/js/script.js
Script Paths
/wp-content/plugins/free-live-chat-support/js/chat.js/wp-content/plugins/free-live-chat-support/js/script.js
Version Parameters
free-live-chat-support/css/chat.css?ver=free-live-chat-support/css/style.css?ver=free-live-chat-support/js/chat.js?ver=free-live-chat-support/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
fls-chat-containerfls-chat-messagefls-chat-inputfls-chat-send-button
HTML Comments
<!-- Free Live Chat Support Chatbox Start --><!-- Free Live Chat Support Chatbox End --><!-- Free Live Chat Support Widget HTML -->
Data Attributes
data-chat-iddata-api-url
JS Globals
window.free_live_chat_settingswindow.FLS_Chat
REST Endpoints
/wp-json/free-live-chat-support/v1/messages/wp-json/free-live-chat-support/v1/send
Shortcode Output
[free_live_chat]
FAQ

Frequently Asked Questions about ZupportDesk Live Chat Plugin (Free & Paid Plans)