KP Fastest Tidio Chat Security & Risk Analysis

wordpress.org/plugins/kp-fastest-tidio-chat

Tidio Live Chat made fast and easy. Speed up your WordPress website and help customers via Tidio Live Chat on your website.

100 active installs v1.0.4 PHP 5.2.4+ WP 3.2+ Updated Apr 15, 2021
chat-pluginlive-chatlive-helplive-supportwordpress-live-chat
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is KP Fastest Tidio Chat Safe to Use in 2026?

Generally Safe

Score 85/100

KP Fastest Tidio Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The kp-fastest-tidio-chat v1.0.4 plugin exhibits a generally positive security posture with a notable absence of known vulnerabilities and a strong adherence to secure coding practices. The static analysis reveals a completely clean slate regarding dangerous functions, SQL injection risks (all queries use prepared statements), and external HTTP requests. Furthermore, there are no identified vulnerabilities in its history. However, a significant concern arises from the output escaping analysis, where 100% of identified outputs are not properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into web pages rendered by the plugin. Despite the strong security foundation in other areas, this oversight in output sanitization presents a tangible risk that needs immediate attention.

Key Concerns

  • Unescaped output found
Vulnerabilities
None known

KP Fastest Tidio Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

KP Fastest Tidio Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
kpftc_settings_view (includes\admin\kpftc-admin-settings-fileds.php:8)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

KP Fastest Tidio Chat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_enqueue_scriptsincludes\admin\kpftc-scripts-enqueue.php:27
actionwp_print_footer_scriptsincludes\kpftc-frontend.php:34
actionadmin_menuincludes\kpftc-init-config.php:15
actionplugins_loadedincludes\kpftc-init-config.php:39
actionadmin_noticesincludes\kpftc-init-config.php:63
filterplugin_row_metaincludes\kpftc-shortcuts.php:33
filteradmin_footer_textincludes\kpftc-shortcuts.php:44
Maintenance & Trust

KP Fastest Tidio Chat Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedApr 15, 2021
PHP min version5.2.4
Downloads6K

Community Trust

Rating96/100
Number of ratings11
Active installs100
Developer Profile

KP Fastest Tidio Chat Developer Profile

Kreativo Pro

3 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect KP Fastest Tidio Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kp-fastest-tidio-chat/assets/css/kpftc-backend.css/wp-content/plugins/kp-fastest-tidio-chat/assets/js/kpftc-backend.js
Script Paths
/wp-content/plugins/kp-fastest-tidio-chat/assets/js/kpftc-backend.js

HTML / DOM Fingerprints

JS Globals
kpftc_vars
FAQ

Frequently Asked Questions about KP Fastest Tidio Chat