
KN Public Chat Security & Risk Analysis
wordpress.org/plugins/kn-public-chatKN Public Chat is a free WordPress Plugin that lets your visitors and visitor from anyone who install this plugin can chat together in 1 public chat r …
Is KN Public Chat Safe to Use in 2026?
Generally Safe
Score 100/100KN Public Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kn-public-chat" plugin v1.0.2 presents a mixed security posture. On the positive side, it has a small attack surface, with only one shortcode identified and no AJAX handlers or REST API routes. All SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are good indicators of secure coding practices in those areas. Furthermore, the plugin has no recorded vulnerability history, suggesting a lack of past exploitable issues.
However, there are significant concerns revealed by the static analysis. The use of the `create_function` is a major red flag, as it can lead to arbitrary code execution if not handled with extreme care. Crucially, the analysis shows a severe lack of output escaping, with only 1% of outputs being properly escaped. This is a critical vulnerability that can lead to cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts into pages viewed by other users. The absence of nonce checks and capability checks on its entry points, despite the limited attack surface, also increases the risk of unauthorized actions or privilege escalation if an attacker can find a way to trigger the shortcode maliciously.
In conclusion, while the plugin exhibits good practices in database interaction and avoids external dependencies, the high number of unescaped outputs and the use of a dangerous function like `create_function` represent critical security weaknesses. The absence of basic security checks like nonces and capability checks on its sole entry point further exacerbates these risks. The lack of historical vulnerabilities is positive but does not negate the significant, evidence-backed risks identified in the current version.
Key Concerns
- Dangerous function: create_function
- Output escaping: 1% properly escaped
- Nonce checks: 0
- Capability checks: 0
KN Public Chat Security Vulnerabilities
KN Public Chat Code Analysis
Dangerous Functions Found
Output Escaping
KN Public Chat Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
KN Public Chat Maintenance & Trust
Maintenance Signals
Community Trust
KN Public Chat Alternatives
Tawk.To Live Chat
tawkto-live-chat
(OFFICIAL tawk.to plugin) Instantly chat with visitors on your website with the free tawk.to chat widget. Website: http://tawk.to
LiveChat – Live Chat Plugin for WP Websites
wp-live-chat-software-for-wordpress
Best live chat and help desk plugin for WordPress websites. Add the LiveChat widget to engage visitors and provide real‑time customer support! 🚀
Pure Chat – Live Chat & More!
pure-chat
Pure Chat provides a Live Chat plugin with Unlimited Chats for your website!
Chaport — Live Chat & Chatbots
chaport
Modern live chat plugin for WordPress. Powerful features: multi-channel, chatbots, customization, etc. Free plan. Unlimited chats & websites.
HelpCrunch – Live Chat, Chatbot & Knowledge Base for Customer Service
helpcrunch-live-chat
The one-stop platform for even stronger customer relations. Bolster your customer support with its live chat, chatbot, and knowledge base software.
KN Public Chat Developer Profile
4 plugins · 300 total installs
How We Detect KN Public Chat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
knmalaychatcode()