Freshchat Security & Risk Analysis

wordpress.org/plugins/freshchat

Freshchat plugin is a seamless way to add your Chat to your website.

1K active installs v2.3.4 PHP 5.2.4+ WP 3.0.1+ Updated Dec 27, 2021
chatfreshchatfreshdeskfreshworks
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEDec 11, 2025
Download
Safety Verdict

Is Freshchat Safe to Use in 2026?

Use With Caution

Score 63/100

Freshchat has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Dec 11, 2025Updated 4yr ago
Risk Assessment

The Freshchat plugin v2.3.4 exhibits a concerning security posture due to its identified vulnerabilities and code analysis findings. While it demonstrates good practices in avoiding dangerous functions and utilizing prepared statements for SQL queries, significant weaknesses are present. The plugin has a single entry point via an AJAX handler that lacks any authentication checks, creating a direct and unprotected vector for potential exploitation. Furthermore, a substantial portion of its output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if malicious data is injected through the unprotected AJAX handler.

The vulnerability history reveals a pattern of past issues, including a medium-severity Cross-Site Request Forgery (CSRF) vulnerability. The presence of a currently unpatched medium-severity vulnerability, combined with the unprotected AJAX endpoint and unescaped output, indicates a tendency towards overlooking critical security implementations. This suggests that while some security aspects are considered, essential checks like authorization and output sanitization are not consistently applied, leaving the plugin vulnerable to common attack vectors. The overall security of this plugin version is therefore rated as low.

Key Concerns

  • Unprotected AJAX handler
  • Significant unescaped output
  • Unpatched medium severity CVE
  • Missing nonce checks on AJAX
  • Missing capability checks
Vulnerabilities
1 published

Freshchat Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-64240medium · 4.3Cross-Site Request Forgery (CSRF)

Freshchat <= 2.3.4 - Cross-Site Request Forgery

Dec 11, 2025Unpatched
Version History

Freshchat Release Timeline

v2.3.4Current1 CVE
v2.3.31 CVE
v2.3.21 CVE
v2.3.11 CVE
v2.3.01 CVE
v2.2.31 CVE
v2.2.21 CVE
v2.2.11 CVE
v2.2.01 CVE
v2.1.91 CVE
v2.1.81 CVE
v2.1.71 CVE
v2.1.61 CVE
v2.1.51 CVE
v2.1.4.11 CVE
v2.1.41 CVE
v2.1.3.11 CVE
v2.1.31 CVE
v2.1.21 CVE
v2.1.1.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Freshchat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped15 total outputs
Attack Surface
1 unprotected

Freshchat Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_update_restore_idfreshchat.php:31
WordPress Hooks 4
actionadmin_enqueue_scriptsfreshchat.php:20
actionwp_footerwidget-settings\add_to_page.php:4
actionadmin_initwidget-settings\main.php:8
actionadmin_menuwidget-settings\menu.php:4
Maintenance & Trust

Freshchat Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedDec 27, 2021
PHP min version5.2.4
Downloads48K

Community Trust

Rating58/100
Number of ratings9
Active installs1K
Developer Profile

Freshchat Developer Profile

freshchat

1 plugin · 1K total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Freshchat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/freshchat/css/freshchat_plugin.css

HTML / DOM Fingerprints

JS Globals
fcSettingsfcWidgetajaxurl
FAQ

Frequently Asked Questions about Freshchat