
JivoChat Live Chat – WP live chat plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/jivochatOmnichannel Live Chat and Help Desk plugin, optimized for WordPress. Free, fast, easy to install and to use. Turn your visitors into happy customers!
Is JivoChat Live Chat – WP live chat plugin for WordPress Safe to Use in 2026?
Mostly Safe
Score 84/100JivoChat Live Chat – WP live chat plugin for WordPress is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The JivoChat plugin version 1.3.6.1 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good security practices by utilizing prepared statements for all SQL queries, properly escaping the vast majority of its output, and implementing nonce and capability checks where applicable. The absence of a significant attack surface through entry points like AJAX handlers, REST API routes, and shortcodes is also a positive indicator. Taint analysis revealing no unsanitized paths further strengthens this assessment.
However, the presence of one historical high-severity Cross-Site Request Forgery (CSRF) vulnerability, even though currently patched, warrants attention. While the static analysis shows no immediate critical or high risks in the current code, historical patterns of vulnerabilities, particularly CSRF, suggest potential areas where input validation or state-changing operations might have been less robust in the past. This historical context, combined with the plugin's reliance on external HTTP requests which can sometimes be vectors for certain attacks if not handled carefully, means a degree of caution is still advised.
In conclusion, JivoChat v1.3.6.1 appears to be well-secured in its current iteration with excellent adherence to core security principles like prepared statements and output escaping. The primary concern lies in the past vulnerability history, which implies that while the current code is likely safe, continuous vigilance and thorough review of any future updates are recommended to maintain this strong security stance.
Key Concerns
- Historical high-severity vulnerability (CSRF)
JivoChat Live Chat – WP live chat plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
JivoChat Live Chat – WP live chat plugin for WordPress <= 1.3.5.3 - Cross-Site Request Forgery to Cross-Site Scripting
JivoChat Live Chat – WP live chat plugin for WordPress Code Analysis
Output Escaping
JivoChat Live Chat – WP live chat plugin for WordPress Attack Surface
WordPress Hooks 2
Maintenance & Trust
JivoChat Live Chat – WP live chat plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
JivoChat Live Chat – WP live chat plugin for WordPress Alternatives
3CX Free Live Chat, Calls & Messaging
wp-live-chat-support
Chat with your website visitors in real-time for free! Engage with your customers and increase sales.
Replain
replain
Be in touch with your clients through Telegram, WhatsApp or Facebook Messenger. Fast, functional and free live-chat service for your website.
Live Chat by User.com
userengage-live-chat-marketing-automation-integration
With Live Chat by User.com you can chat with any visitor on your website with a simple Wordpress plugin.
ProProfs Chat- Live Chat & Chatbot Plugin
proprofs-chat
ProProfs Chat is a SaaS-based live chat software that helps businesses of all sizes communicate with their website visitors and customers in real-time …
Live Chat Plugin for Elementor – LiveChat
livechat-elementor
A hassle-free WordPress Elementor live chat plugin for sales and customer support.
JivoChat Live Chat – WP live chat plugin for WordPress Developer Profile
1 plugin · 20K total installs
How We Detect JivoChat Live Chat – WP live chat plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jivochat/css/jivosite_bootstrap.css/wp-content/plugins/jivochat/css/jivosite_base.css/wp-content/plugins/jivochat/scripts/jivosite_popper.js/wp-content/plugins/jivochat/scripts/jivosite_bootstrap.js//code.jivosite.com/widget/jivochat/style.css?ver=jivosite_bootstrap.css?ver=jivosite_base.css?ver=jivosite_popper.js?ver=jivosite_bootstrap.js?ver=HTML / DOM Fingerprints
jivosite-widget<!-- Add css to page --><!-- Add js to page --><!-- Add locales to page --><!-- Render html-page with plugin settings -->+27 moredata-jivosite-widget-iddata-jivosite-tokenJIVOSITE_DOMAINJIVOSITE_API_URLJIVOSITE_WIDGET_URLJIVOSITE_URLJIVOSITE_LANGUAGES_URLJIVOSITE_INTEGRATION_URL+3 more