Joleado Live Chat Software Security & Risk Analysis

wordpress.org/plugins/joleado-chat

Requires at least: 3.7 Tested up to: 4.9.x Stable tag: 18.9.3 Version: 18.9.3 License: GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.

0 active installs v18.9.3 PHP + WP + Updated Dec 10, 2018
best-live-chat-softwarefree-chat-systemlive-chat-softwarelive-chat-software-for-businesslive-chat-system
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Joleado Live Chat Software Safe to Use in 2026?

Generally Safe

Score 85/100

Joleado Live Chat Software has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The joleado-chat plugin version 18.9.3 exhibits a generally good security posture with no known vulnerabilities or critical code signals. The static analysis reveals a minimal attack surface, with zero unprotected entry points across AJAX handlers, REST API routes, shortcodes, and cron events. SQL queries are exclusively handled using prepared statements, and there are no detected file operations or bundled libraries that could introduce risks. The absence of critical or high severity taint flows is a significant strength, indicating that sensitive data is likely being handled with appropriate sanitization.

However, there are areas for improvement. The plugin makes external HTTP requests, which, while not inherently a vulnerability, represent a potential attack vector if the target endpoints are compromised or if the plugin fails to validate responses properly. Furthermore, only 60% of output escaping is properly implemented, leaving 40% of output potentially vulnerable to cross-site scripting (XSS) attacks. The presence of nonce checks on two occasions is positive, but the complete lack of capability checks on any entry points is a concern, as it means any authenticated user could potentially trigger plugin functionalities without proper authorization.

Given the clean vulnerability history and the low number of identified risks in the static analysis, the overall risk is assessed as low. The plugin demonstrates a commitment to secure coding practices in several key areas. The primary concerns revolve around the potential for XSS due to incomplete output escaping and the absence of capability checks, which could lead to authorization bypasses if specific functionalities are not adequately protected. Addressing these specific areas would further enhance the plugin's security.

Key Concerns

  • Output escaping is only 60% proper
  • No capability checks on entry points
Vulnerabilities
None known

Joleado Live Chat Software Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Joleado Live Chat Software Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
4
6 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared3 total queries

Output Escaping

60% escaped10 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<joleado_form_admin> (joleado_form_admin.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Joleado Live Chat Software Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuindex.php:32
actionwp_footerindex.php:90
Maintenance & Trust

Joleado Live Chat Software Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedDec 10, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Joleado Live Chat Software Developer Profile

Joleado Systems

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Joleado Live Chat Software

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrap
Data Attributes
id="txthidtoken"name="txthidtoken"id="txtemail"name="txtemail"id="txtname"name="txtname"+8 more
REST Endpoints
/wp_api?action=get_code/wp_api?action=create_store
FAQ

Frequently Asked Questions about Joleado Live Chat Software