Leaddevs Messenger Live Chatbot Security & Risk Analysis

wordpress.org/plugins/leaddevs-chatbot

Leaddevs Messenger Live Chatbot

10 active installs v1.0.0 PHP + WP 3.0.1+ Updated Dec 31, 2019
facebook-chatfacebook-messengermessenger-live-chatwoocommercewordpress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Leaddevs Messenger Live Chatbot Safe to Use in 2026?

Generally Safe

Score 85/100

Leaddevs Messenger Live Chatbot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "leaddevs-chatbot" plugin v1.0.0 exhibits a generally strong security posture due to the absence of known vulnerabilities and a commitment to secure coding practices like prepared statements for SQL queries and nonce checks. The static analysis reveals a minimal attack surface with all identified entry points appearing to be protected. The lack of file operations and external HTTP requests also reduces potential risks. However, a significant concern is the low percentage of properly escaped output, with only 16% of 19 total outputs being escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being rendered in the browser. While taint analysis shows no immediate critical or high-severity issues, the output escaping deficiency means that even without explicit tainted flows, an attacker could potentially inject malicious scripts through improperly handled data. The plugin's history of zero recorded vulnerabilities is positive, suggesting developers have maintained a good track record, but the current output escaping issues warrant attention to maintain this record.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Leaddevs Messenger Live Chatbot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Leaddevs Messenger Live Chatbot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
3 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

16% escaped19 total outputs
Attack Surface

Leaddevs Messenger Live Chatbot Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_wpfbmb_facebook_messenger_bot_manage_settingleaddevs-chatbot.php:131
WordPress Hooks 7
actionwp_footerleaddevs-chatbot.php:175
actionplugins_loadedsrc\includes\FacebookMessengerLiveChat.php:149
actionadmin_enqueue_scriptssrc\includes\FacebookMessengerLiveChat.php:164
actionadmin_enqueue_scriptssrc\includes\FacebookMessengerLiveChat.php:165
actionadmin_menusrc\includes\FacebookMessengerLiveChat.php:166
actionwp_enqueue_scriptssrc\includes\FacebookMessengerLiveChat.php:181
actionwp_enqueue_scriptssrc\includes\FacebookMessengerLiveChat.php:182
Maintenance & Trust

Leaddevs Messenger Live Chatbot Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedDec 31, 2019
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Leaddevs Messenger Live Chatbot Developer Profile

Najmul

2 plugins · 10 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Leaddevs Messenger Live Chatbot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/leaddevs-chatbot/assets/css/style.css/wp-content/plugins/leaddevs-chatbot/assets/js/wp-messenger-chat.js/wp-content/plugins/leaddevs-chatbot/assets/css/whatsapp-button.css/wp-content/plugins/leaddevs-chatbot/assets/js/whatsapp-button.js/wp-content/plugins/leaddevs-chatbot/assets/css/whatsapp-chat.css/wp-content/plugins/leaddevs-chatbot/assets/js/whatsapp-chat.js/wp-content/plugins/leaddevs-chatbot/assets/css/messenger-icon.css/wp-content/plugins/leaddevs-chatbot/assets/js/messenger-icon.js
Script Paths
/wp-content/plugins/leaddevs-chatbot/assets/js/wp-messenger-chat.js/wp-content/plugins/leaddevs-chatbot/assets/js/whatsapp-button.js/wp-content/plugins/leaddevs-chatbot/assets/js/whatsapp-chat.js/wp-content/plugins/leaddevs-chatbot/assets/js/messenger-icon.js
Version Parameters
leaddevs-chatbot/assets/css/style.css?ver=leaddevs-chatbot/assets/js/wp-messenger-chat.js?ver=leaddevs-chatbot/assets/css/whatsapp-button.css?ver=leaddevs-chatbot/assets/js/whatsapp-button.js?ver=leaddevs-chatbot/assets/css/whatsapp-chat.css?ver=leaddevs-chatbot/assets/js/whatsapp-chat.js?ver=leaddevs-chatbot/assets/css/messenger-icon.css?ver=leaddevs-chatbot/assets/js/messenger-icon.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpfbmb-chat-boxwpfbmb-chat-inputwpfbmb-chat-send-btn
HTML Comments
<!-- Admin View --><!-- Chatbot -->
Data Attributes
data-wpfbmb-page-iddata-wpfbmb-page-tokendata-wpfbmb-bot-iddata-wpfbmb-bot-token
JS Globals
window.wpfbmb_chat_config
REST Endpoints
/wp-json/wpfbmb/v1/messages
FAQ

Frequently Asked Questions about Leaddevs Messenger Live Chatbot