GTChatPro Live Chat Plugin Security & Risk Analysis

wordpress.org/plugins/gtchatpro

Convert Your Leads To Customers Seamlessly

0 active installs v0.0.1 PHP 7.4+ WP 5.0+ Updated Nov 24, 2022
best-business-chat-appinstant-messaging-apps-for-businesslive-chat-for-businesswebsite-chatwebsite-chat-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GTChatPro Live Chat Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

GTChatPro Live Chat Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The gtchatpro v0.0.1 plugin exhibits a generally strong security posture based on the static analysis provided. There are no identified critical or high-severity taint flows, zero SQL queries that are not using prepared statements, and no direct file operations or external HTTP requests. The absence of known vulnerabilities in its history is also a positive indicator. The plugin demonstrates good practice by implementing two nonce checks, which help protect against certain types of cross-site request forgery attacks. However, the analysis does highlight areas of concern. A significant portion of output (45%) is not properly escaped, representing a potential risk for cross-site scripting (XSS) vulnerabilities. Furthermore, the lack of any capability checks on its entry points (AJAX, REST API, shortcodes, cron) means that any functionality exposed through these mechanisms is likely accessible to any logged-in user, regardless of their role or permissions, which is a notable weakness in access control.

Key Concerns

  • Significant unescaped output identified
  • No capability checks on entry points
Vulnerabilities
None known

GTChatPro Live Chat Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GTChatPro Live Chat Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
6 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

55% escaped11 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<gtchatpro> (gtchatpro.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GTChatPro Live Chat Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menugtchatpro.php:21
actionadmin_enqueue_scriptsgtchatpro.php:28
actioninitgtchatpro.php:30
actioninitgtchatpro.php:99
actionwp_enqueue_scriptsgtchatpro.php:104
Maintenance & Trust

GTChatPro Live Chat Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 24, 2022
PHP min version7.4
Downloads664

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

GTChatPro Live Chat Plugin Developer Profile

GlixenTechnologies

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GTChatPro Live Chat Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gtchatpro/css/switch-button.css
Script Paths
https://gtchatpro.com/code/widget

HTML / DOM Fingerprints

CSS Classes
gtchatpro-form
FAQ

Frequently Asked Questions about GTChatPro Live Chat Plugin