Social Intents – Live Chat Security & Risk Analysis

wordpress.org/plugins/live-chat-support-by-social-intents

AI Chatbot & Live Chat plugin for WordPress. Chat with visitors using ChatGPT, Claude, Gemini, Slack, Teams, and Google Chat.

400 active installs v1.6.19 PHP 7.2+ WP 3.6+ Updated Jun 3, 2025
ai-chatbotchatgptcustomer-supportlive-chatslack
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 4, 2025
Safety Verdict

Is Social Intents – Live Chat Safe to Use in 2026?

Mostly Safe

Score 78/100

Social Intents – Live Chat is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Apr 4, 2025Updated 10mo ago
Risk Assessment

The plugin "live-chat-support-by-social-intents" v1.6.19 exhibits a mixed security posture. Static analysis shows a very small attack surface with no identified entry points, which is generally a positive sign. The absence of dangerous functions, file operations, and external HTTP requests, coupled with the use of prepared statements for all SQL queries, are strong security practices. However, concerns arise from the moderate level of output escaping (75% properly escaped), suggesting potential for Cross-Site Scripting (XSS) vulnerabilities if not all output is handled securely. The lack of nonce checks on any entry points, though the entry points are currently zero, could become a concern if future updates introduce them without adequate protection. The plugin's vulnerability history is a significant red flag, with one medium-severity CVE related to XSS that remains unpatched. This indicates a recurring security weakness and a lack of timely remediation, which is a critical concern for any plugin, especially one with past XSS issues.

Key Concerns

  • Unpatched medium severity CVE
  • Output escaping not 100%
  • No nonce checks on entry points
Vulnerabilities
1

Social Intents – Live Chat Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32131medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Social Intents <= 1.6.14 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 4, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Social Intents – Live Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
18 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped24 total outputs
Attack Surface

Social Intents – Live Chat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actioninitlive-chat-support-by-socialintents.php:12
actionadmin_noticeslive-chat-support-by-socialintents.php:13
filterplugin_action_linkslive-chat-support-by-socialintents.php:14
actionwp_footerlive-chat-support-by-socialintents.php:15
actionadmin_footerlive-chat-support-by-socialintents.php:16
actionadmin_menulive-chat-support-by-socialintents.php:23
actionadmin_menulive-chat-support-by-socialintents.php:24
actioninittrunk\live-chat-support-by-socialintents.php:12
actionadmin_noticestrunk\live-chat-support-by-socialintents.php:13
filterplugin_action_linkstrunk\live-chat-support-by-socialintents.php:14
actionwp_footertrunk\live-chat-support-by-socialintents.php:15
actionadmin_footertrunk\live-chat-support-by-socialintents.php:16
actionadmin_menutrunk\live-chat-support-by-socialintents.php:23
actionadmin_menutrunk\live-chat-support-by-socialintents.php:24
Maintenance & Trust

Social Intents – Live Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 3, 2025
PHP min version7.2
Downloads67K

Community Trust

Rating66/100
Number of ratings7
Active installs400
Developer Profile

Social Intents – Live Chat Developer Profile

socialintents

5 plugins · 540 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Intents – Live Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/live-chat-support-by-social-intents/socialintents.png/wp-content/plugins/live-chat-support-by-social-intents/app-key.png
Script Paths
https://www.socialintents.com/api/chat/socialintents.1.4.js
Version Parameters
live-chat-support-by-social-intents/style.css?ver=live-chat-support-by-social-intents/scripts/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
silc_noAccountSpansilc_registersilc_registerCompleteaddAppKey
HTML Comments
<!-- www.socialintents.com -->
Data Attributes
id="silc_widgetID"name="silc_widgetID"id="silc_noAccountSpan"id="silc_register"id="silc_registerComplete"id="addAppKey"+3 more
JS Globals
si_domain
FAQ

Frequently Asked Questions about Social Intents – Live Chat