JivoChat Live Chat – WP live chat plugin for WordPress Security & Risk Analysis

wordpress.org/plugins/jivochat

Omnichannel Live Chat and Help Desk plugin, optimized for WordPress. Free, fast, easy to install and to use. Turn your visitors into happy customers!

20K active installs v1.3.6.1 PHP + WP 3.0.1+ Updated Oct 25, 2023
free-live-chatlive-chat-plugin%d1%81hat-pluginwordpress-chatwordpress-live-chat
84
B · Generally Safe
CVEs total1
Unpatched0
Last CVEMay 9, 2022
Safety Verdict

Is JivoChat Live Chat – WP live chat plugin for WordPress Safe to Use in 2026?

Mostly Safe

Score 84/100

JivoChat Live Chat – WP live chat plugin for WordPress is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVELast CVE: May 9, 2022Updated 2yr ago
Risk Assessment

The JivoChat plugin version 1.3.6.1 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good security practices by utilizing prepared statements for all SQL queries, properly escaping the vast majority of its output, and implementing nonce and capability checks where applicable. The absence of a significant attack surface through entry points like AJAX handlers, REST API routes, and shortcodes is also a positive indicator. Taint analysis revealing no unsanitized paths further strengthens this assessment.

However, the presence of one historical high-severity Cross-Site Request Forgery (CSRF) vulnerability, even though currently patched, warrants attention. While the static analysis shows no immediate critical or high risks in the current code, historical patterns of vulnerabilities, particularly CSRF, suggest potential areas where input validation or state-changing operations might have been less robust in the past. This historical context, combined with the plugin's reliance on external HTTP requests which can sometimes be vectors for certain attacks if not handled carefully, means a degree of caution is still advised.

In conclusion, JivoChat v1.3.6.1 appears to be well-secured in its current iteration with excellent adherence to core security principles like prepared statements and output escaping. The primary concern lies in the past vulnerability history, which implies that while the current code is likely safe, continuous vigilance and thorough review of any future updates are recommended to maintain this strong security stance.

Key Concerns

  • Historical high-severity vulnerability (CSRF)
Vulnerabilities
1

JivoChat Live Chat – WP live chat plugin for WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2022-0642high · 8.8Cross-Site Request Forgery (CSRF)

JivoChat Live Chat – WP live chat plugin for WordPress <= 1.3.5.3 - Cross-Site Request Forgery to Cross-Site Scripting

May 9, 2022 Patched in 1.3.5.4 (624d)
Code Analysis
Analyzed Mar 16, 2026

JivoChat Live Chat – WP live chat plugin for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
42 escaped
Nonce Checks
2
Capability Checks
1
File Operations
2
External Requests
2
Bundled Libraries
0

Output Escaping

95% escaped44 total outputs
Attack Surface

JivoChat Live Chat – WP live chat plugin for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuclass-jivosite.php:64
actionwp_enqueue_scriptsclass-jivosite.php:80
Maintenance & Trust

JivoChat Live Chat – WP live chat plugin for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedOct 25, 2023
PHP min version
Downloads698K

Community Trust

Rating98/100
Number of ratings709
Active installs20K
Developer Profile

JivoChat Live Chat – WP live chat plugin for WordPress Developer Profile

JivoChat

1 plugin · 20K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
624 days
View full developer profile
Detection Fingerprints

How We Detect JivoChat Live Chat – WP live chat plugin for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jivochat/css/jivosite_bootstrap.css/wp-content/plugins/jivochat/css/jivosite_base.css/wp-content/plugins/jivochat/scripts/jivosite_popper.js/wp-content/plugins/jivochat/scripts/jivosite_bootstrap.js
Script Paths
//code.jivosite.com/widget/
Version Parameters
jivochat/style.css?ver=jivosite_bootstrap.css?ver=jivosite_base.css?ver=jivosite_popper.js?ver=jivosite_bootstrap.js?ver=

HTML / DOM Fingerprints

CSS Classes
jivosite-widget
HTML Comments
<!-- Add css to page --><!-- Add js to page --><!-- Add locales to page --><!-- Render html-page with plugin settings -->+27 more
Data Attributes
data-jivosite-widget-iddata-jivosite-token
JS Globals
JIVOSITE_DOMAINJIVOSITE_API_URLJIVOSITE_WIDGET_URLJIVOSITE_URLJIVOSITE_LANGUAGES_URLJIVOSITE_INTEGRATION_URL+3 more
FAQ

Frequently Asked Questions about JivoChat Live Chat – WP live chat plugin for WordPress