
Jheck Chat Security & Risk Analysis
wordpress.org/plugins/jheck-chatSimple worpdress chat plugin using ajax.
Is Jheck Chat Safe to Use in 2026?
Generally Safe
Score 85/100Jheck Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The jheck-chat plugin v1.4 presents a concerning security posture due to significant weaknesses identified in its static analysis. A prominent issue is the presence of an unprotected AJAX handler, creating a direct entry point for potential attacks without proper authentication or authorization. The plugin also exhibits poor data handling practices, with all SQL queries being executed without prepared statements, increasing the risk of SQL injection vulnerabilities. Furthermore, the extremely low percentage of properly escaped output (3%) suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities across numerous output points. The taint analysis confirms these concerns, revealing two high-severity flows with unsanitized paths, which are critical indicators of exploitable vulnerabilities. While the plugin has no recorded vulnerability history (CVEs), this absence does not negate the evident risks identified within the code itself. The plugin demonstrates some good practices by including nonce and capability checks in several places, and utilizing Select2, but these are overshadowed by the critical lack of input validation and secure coding practices in key areas.
Key Concerns
- Unprotected AJAX handler
- SQL queries without prepared statements
- Low percentage of properly escaped output
- High severity taint flows with unsanitized paths
- Use of create_function (deprecated and dangerous)
Jheck Chat Security Vulnerabilities
Jheck Chat Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Jheck Chat Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 32
Maintenance & Trust
Jheck Chat Maintenance & Trust
Maintenance Signals
Community Trust
Jheck Chat Alternatives
ChatSupport
chatsupport
The ChatSupport plugin enables you to easily add a live chat widget to your WordPress site and start providing support to your web visitors.
BigRadar – Free Chatbot, Live Chat, Email Marketing
bigradar
BigRadar is a free chat software used by 1000s of businesses worldwide to increase sales, conversions and better support in real-time from anywhere.
Joleado Live Chat Software
joleado-chat
Requires at least: 3.7 Tested up to: 4.9.x Stable tag: 18.9.3 Version: 18.9.3 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
Tawk.To Live Chat
tawkto-live-chat
(OFFICIAL tawk.to plugin) Instantly chat with visitors on your website with the free tawk.to chat widget. Website: http://tawk.to
Jheck Chat Developer Profile
1 plugin · 10 total installs
How We Detect Jheck Chat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jheck-chat/sources/css/style.css/wp-content/plugins/jheck-chat/sources/font-awesome/css/font-awesome.min.css/wp-content/plugins/jheck-chat/template/default/jc_template-style.css/wp-content/plugins/jheck-chat/sources/css/custom-style.css/wp-content/plugins/jheck-chat/sources/js/custom-scripts.js/wp-content/plugins/jheck-chat/template/default/jc_template-script.js/wp-content/plugins/jheck-chat/sources/js/custom-scripts.js/wp-content/plugins/jheck-chat/template/default/jc_template-script.jsjheck-chat/style.css?ver=jheck-chat/font-awesome/css/font-awesome.min.css?ver=jheck-chat/template/default/jc_template-style.css?ver=jheck-chat/sources/css/custom-style.css?ver=jheck-chat/sources/js/custom-scripts.js?ver=20141105jheck-chat/template/default/jc_template-script.js?ver=20141105HTML / DOM Fingerprints
JC_URLJC_URL_PATHJC_MYSQL_INBOXJC_ENCRYPTION_KEYJC_TEMPLATE_NAME