
GoSquared – Marketing Automation, CRM, Analytics and Live Chat for WordPress Security & Risk Analysis
wordpress.org/plugins/gosquared-officialThis is the official Wordpress plugin for GoSquared. The leading software platform for real-time analytics, live chat and lead capture.
Is GoSquared – Marketing Automation, CRM, Analytics and Live Chat for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100GoSquared – Marketing Automation, CRM, Analytics and Live Chat for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The goSquared official plugin v1.3.1 exhibits a generally good security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Crucially, the plugin avoids dangerous functions, performs no file operations, makes no external HTTP requests, and utilizes prepared statements for all SQL queries, indicating a strong adherence to secure coding practices in these areas. Furthermore, the lack of any recorded vulnerabilities, historical or current, suggests a history of stable and secure development.
However, a notable concern is the moderate percentage (38%) of properly escaped output. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if untrusted data is displayed without sufficient sanitization. While no taint analysis revealed specific issues, the unescaped outputs represent a potential vector. The complete absence of nonce checks and capability checks on entry points, while not explicitly problematic given the zero identified entry points, is a weakness that would be concerning if the attack surface were larger or if new entry points were introduced in future versions without corresponding security measures.
In conclusion, the plugin is currently in a strong security state due to its limited attack surface and adherence to several best practices, particularly regarding SQL injection and dangerous functions. The primary area for improvement lies in ensuring consistent and robust output escaping to mitigate potential XSS risks. The absence of vulnerabilities is a positive sign, but the unescaped outputs are a specific, actionable area of concern.
Key Concerns
- Moderate output escaping coverage
GoSquared – Marketing Automation, CRM, Analytics and Live Chat for WordPress Security Vulnerabilities
GoSquared – Marketing Automation, CRM, Analytics and Live Chat for WordPress Code Analysis
Output Escaping
GoSquared – Marketing Automation, CRM, Analytics and Live Chat for WordPress Attack Surface
WordPress Hooks 8
Maintenance & Trust
GoSquared – Marketing Automation, CRM, Analytics and Live Chat for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
GoSquared – Marketing Automation, CRM, Analytics and Live Chat for WordPress Alternatives
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
AnswerForce
answerforce
Add the AnswerForce plugin for quick and easy customer support. Chat with visitors, build relationships and improve customer satisfaction.
Shailesh LeadCapture Pro
shailesh-leadcapture-pro
Shailesh LeadCapture Pro is the ultimate WhatsApp Chat solution for WordPress. It features a professional chatbot to capture visitor name, phone, emai …
Snorkel
snorkel
Snorkel combines your sales data and chat transcripts to show you ROI on conversations as well as other crucial sales insights.
Tawk.To Live Chat
tawkto-live-chat
(OFFICIAL tawk.to plugin) Instantly chat with visitors on your website with the free tawk.to chat widget. Website: http://tawk.to
GoSquared – Marketing Automation, CRM, Analytics and Live Chat for WordPress Developer Profile
1 plugin · 200 total installs
How We Detect GoSquared – Marketing Automation, CRM, Analytics and Live Chat for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gosquared-official/css/goSquaredStyle.css//d1l6p2sc9645hc.cloudfront.net/gosquared.jsHTML / DOM Fingerprints
gsOptionsgsLabelgsGFformgsSignUpgsDashboardLinkname="GSOF_gosquared_site_token"name="GSOF_gosquared_identify"name="GSOF_gosquared_gravity_forms"id="GSOF_gosquared_identify"id="GSOF_gosquared_gravity_forms"_gs