
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot Security & Risk Analysis
wordpress.org/plugins/hive-supportThe All-In-One Help Desk, Live Chat & AI Chat Bot Plugin for WordPress.
Is Hive Support | AI-Powered Help Desk, Live Chat and Chatbot Safe to Use in 2026?
Use With Caution
Score 66/100Hive Support | AI-Powered Help Desk, Live Chat and Chatbot has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "hive-support" plugin v1.2.11 presents a significant security risk due to a large number of unprotected AJAX handlers and a history of numerous vulnerabilities, including a currently unpatched high-severity issue. While the plugin demonstrates good practices in using prepared statements for SQL queries and proper output escaping, the extensive attack surface without authorization checks is a major concern. The taint analysis shows flows with unsanitized paths, though no critical or high severity issues were found in this analysis, this pattern, coupled with past vulnerabilities like SQL injection and cross-site scripting, suggests a high likelihood of exploitable weaknesses. The presence of 11 known CVEs, with one still unpatched, and common vulnerability types like missing authorization and exposure of sensitive information, strongly indicates recurring security flaws in the plugin's development. Overall, while some code quality aspects are positive, the plugin's vulnerability history and the substantial number of unprotected entry points make it a high-risk component for any WordPress installation.
Key Concerns
- Unprotected AJAX handlers
- Currently unpatched CVE
- High severity CVEs in history
- Flows with unsanitized paths
- Missing authorization vulnerability history
- SQL Injection vulnerability history
- Cross-site Scripting vulnerability history
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
Hive Support <= 1.2.5 - Authenticated (Subscriber+) Missing Authorization via hs_update_ai_chat_settings and hive_lite_support_get_all_binbox
Hive Support <= 1.2.5 - Cross-Site Request Forgery via hs_update_ai_chat_settings Function
Hive Support <= 1.2.5 - Reflected Cross-Site Scripting
Hive Support <= 1.2.6 - Unauthenticated Sensitive Information Exposure
Hive Support <= 1.2.7 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Hive Support <= 1.2.5 - Missing Authorization
Hive Support <= 1.2.5 - Missing Authorization
Hive Support – WordPress Help Desk <= 1.1.6 - Missing Authorization
Hive Support – WordPress Help Desk <= 1.1.2 - Cross-Site Request Forgery
Hive Support – WordPress Help Desk <= 1.1.2 - Authenticated (Subscriber+) SQL Injection
Hive Support – WordPress Help Desk <= 1.1.1 - Authenticated (Subscriber+) Arbitrary File Upload
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot Release Timeline
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot Attack Surface
AJAX Handlers 43
Shortcodes 2
WordPress Hooks 35
Maintenance & Trust
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot Maintenance & Trust
Maintenance Signals
Community Trust
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot Alternatives
REVE Chat – AI Chatbot, Live Chat, Helpdesk, Campaigns & More
revechat
A free all-in-one customer service and lead generation platform capable of engaging, retaining, and converting customers.
Paldesk – Live Chat & Helpdesk
paldesk-live-chat-helpdesk
Powerful live chat & helpdesk plugin made for your WordPress website. Convert leads to sales & help customers in real time - it's free!
Chatmoat AI Chatbot
chatmoat-ai-chatbot
Chatmoat AI Chatbot that instantly helps visitors with AI-generated answers. Get 24/7 support and happier visitors. Add a custom GPT to your website.
Ensoras – AI Customer Support & Live Chat Helpdesk for WooCommerce
ensoras-ai-chat
AI live chat and helpdesk for WooCommerce. Answers customer questions automatically using your real store data. Free plan included.
Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons
chatway-live-chat
AI chatbot agent & live chat for customer support, FAQ, chat buttons including WhatsApp with Chatway live chat. iOS & Android apps available 💬
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot Developer Profile
1 plugin · 40 total installs
How We Detect Hive Support | AI-Powered Help Desk, Live Chat and Chatbot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hive-support/assets/css/hive-support-frontend.css/wp-content/plugins/hive-support/assets/css/hive-support-admin.css/wp-content/plugins/hive-support/assets/js/hive-support-frontend.js/wp-content/plugins/hive-support/assets/js/hive-support-admin.js/wp-content/plugins/hive-support/assets/js/chat.js/wp-content/plugins/hive-support/assets/js/chatbot.js/wp-content/plugins/hive-support/assets/js/hive-support-frontend.js/wp-content/plugins/hive-support/assets/js/hive-support-admin.js/wp-content/plugins/hive-support/assets/js/chat.js/wp-content/plugins/hive-support/assets/js/chatbot.jshive-support/assets/css/hive-support-frontend.css?ver=hive-support/assets/css/hive-support-admin.css?ver=hive-support/assets/js/hive-support-frontend.js?ver=hive-support/assets/js/hive-support-admin.js?ver=hive-support/assets/js/chat.js?ver=hive-support/assets/js/chatbot.js?ver=HTML / DOM Fingerprints
hs-chat-widgeths-chat-iconhs-chatbot-bubblehs-support-ticket-formhive-support-dashboard-wraphive-support-widget-buttondata-hs-chat-iddata-hs-chatbot-iddata-hs-widget-idHiveSupportFrontendHiveSupportChatHiveSupportChatboths_chat_settingshs_chatbot_settings/wp-json/hive-support/v1/chat/wp-json/hive-support/v1/chatbot/wp-json/hive-support/v1/tickets[hive_customer_portal][hive_chat_widget][hive_chatbot]