
Lexity Live for WP e-Commerce Security & Risk Analysis
wordpress.org/plugins/lexity-live-for-wp-e-commerceProvides real-time customer monitoring, analytics and insight to help WP e-Commerce-based store owners increase both their traffic and their sales.
Is Lexity Live for WP e-Commerce Safe to Use in 2026?
Generally Safe
Score 100/100Lexity Live for WP e-Commerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'lexity-live-for-wp-e-commerce' version 1.0.9 exhibits a mixed security posture. On the positive side, it demonstrates good practices in database interaction by utilizing prepared statements for all its SQL queries and has no known historical vulnerabilities (CVEs). It also avoids making external HTTP requests and does not bundle third-party libraries, which reduces the risk of inheriting vulnerabilities from external sources.
However, significant concerns arise from the static analysis. The lack of nonce checks and capability checks on any entry points, combined with 11% of outputs being improperly escaped, presents a considerable risk. More critically, the taint analysis revealed three flows with unsanitized paths, all classified as high severity. While these do not currently map to known CVEs, the presence of high-severity taint flows indicates potential for cross-site scripting (XSS) or other injection vulnerabilities that could be exploited if an attacker can control the data flowing through these paths. The file operation also warrants attention, though its context without further detail is uncertain.
In conclusion, while the plugin benefits from secure database handling and a clean vulnerability history, the identified high-severity taint flows and the absence of critical security checks like nonces and capability checks on all entry points are substantial weaknesses. These issues create an attack surface that, while currently unexploited according to historical data, is ripe for potential exploitation. The plugin requires immediate attention to address these identified code-level risks.
Key Concerns
- High severity taint flows with unsanitized paths
- Lack of nonce checks on entry points
- Lack of capability checks on entry points
- Low percentage of properly escaped output
- Presence of file operations
Lexity Live for WP e-Commerce Security Vulnerabilities
Lexity Live for WP e-Commerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Lexity Live for WP e-Commerce Attack Surface
WordPress Hooks 3
Maintenance & Trust
Lexity Live for WP e-Commerce Maintenance & Trust
Maintenance Signals
Community Trust
Lexity Live for WP e-Commerce Alternatives
Channel.io
channel-io
Channel is a conversational CRM solution that helps online businesses to capture potential customers before they leave the websites.
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
Klarna for WooCommerce
klarna-payments-for-woocommerce
Grow your business for increased sales and enhanced shopping experiences at no extra costs.
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation
sumome
Sumo is trusted by over 600,000 businesses — small and large — in growing their email lists, customer base, and revenue online.
Lexity Live for WP e-Commerce Developer Profile
4 plugins · 1K total installs
How We Detect Lexity Live for WP e-Commerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lexity-live-for-wp-e-commerce/libraries/sidecar/sidecar.js/wp-content/plugins/lexity-live-for-wp-e-commerce/libraries/imperative/imperative.js/wp-content/plugins/lexity-live-for-wp-e-commerce/libraries/restian/restian.js/wp-content/plugins/lexity-live-for-wp-e-commerce/js/lexity-live-for-wp-e-commerce.js/wp-content/plugins/lexity-live-for-wp-e-commerce/libraries/imperative/imperative.php/wp-content/plugins/lexity-live-for-wp-e-commerce/libraries/restian/restian.php/wp-content/plugins/lexity-live-for-wp-e-commerce/libraries/sidecar/sidecar.phplexity-live-for-wp-e-commerce/js/lexity-live-for-wp-e-commerce.js?ver=lexity-live-for-wp-e-commerce/libraries/imperative/imperative.js?ver=lexity-live-for-wp-e-commerce/libraries/restian/restian.js?ver=lexity-live-for-wp-e-commerce/libraries/sidecar/sidecar.js?ver=HTML / DOM Fingerprints
lexitydata-lexity-plugin-settingslexity_live_for_wp_e_commerce