
Live Agent Call Security & Risk Analysis
wordpress.org/plugins/live-agent-callLive Agent Call is Sip based Calling plugin provide customer to real time call with website agent.
Is Live Agent Call Safe to Use in 2026?
Generally Safe
Score 100/100Live Agent Call has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'live-agent-call' plugin v0.1.1 presents a concerning security posture primarily due to a complete lack of output escaping. While the plugin appears to have a limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication, this is overshadowed by the critical flaw in how it handles output. All 26 identified output operations fail to properly escape data, which could lead to cross-site scripting (XSS) vulnerabilities if any data rendered by the plugin originates from user input or external sources.
Furthermore, the complete absence of nonce and capability checks, combined with a lack of any taint analysis or known vulnerability history, paints a picture of a plugin that has not undergone thorough security review or implementation of essential security best practices. While the use of prepared statements for SQL queries is a positive sign, it does not mitigate the risks posed by unescaped output. The plugin's current state suggests a high potential for exploitation via XSS, and further investigation into how data is handled and rendered is strongly recommended before deployment.
Key Concerns
- All output is unescaped
- No nonce checks implemented
- No capability checks implemented
Live Agent Call Security Vulnerabilities
Live Agent Call Code Analysis
Output Escaping
Live Agent Call Attack Surface
WordPress Hooks 9
Maintenance & Trust
Live Agent Call Maintenance & Trust
Maintenance Signals
Community Trust
Live Agent Call Alternatives
Call-Now
call-now
Call Now is mobile calling plugin provide customer to call from website .
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
Click to Call or Chat Buttons
click-to-call-or-chat-buttons
This plugin adds Phone Call and WhatsApp button on your webpage.
Click To Dial – Wp Click To Call Support
click-to-dial
Easily add a "Call Now" bubble to your WordPress site—let visitors call you in 3 clicks with customizable buttons, forms, and time-based availability.
Simple Contact Bar
simple-contact-bar
Simple Contact Bar: A plugin that easily adds Call Now and WhatsApp Message buttons to your site, along with customizable options and a popup feature …
Live Agent Call Developer Profile
3 plugins · 50 total installs
How We Detect Live Agent Call
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/live-agent-call/gui.js/wp-content/plugins/live-agent-call/init.js/wp-content/plugins/live-agent-call/sip-0.7.3.js/wp-content/plugins/live-agent-call/ua4.js/wp-content/plugins/live-agent-call/ua3.js/wp-content/plugins/live-agent-call/call.js/wp-content/plugins/live-agent-call/css.css/wp-content/plugins/live-agent-call/gui.js/wp-content/plugins/live-agent-call/init.js/wp-content/plugins/live-agent-call/sip-0.7.3.js/wp-content/plugins/live-agent-call/ua4.js/wp-content/plugins/live-agent-call/ua3.js/wp-content/plugins/live-agent-call/call.jsHTML / DOM Fingerprints
lac_settingslac-color-fieldlac-color-field-hoverdata-default-color