Social Intents – Live Chat Security & Risk Analysis

wordpress.org/plugins/live-chat-support-by-social-intents

AI Chatbot & Live Chat plugin for WordPress. Chat with visitors using ChatGPT, Claude, Gemini, Slack, Teams, and Google Chat.

400 active installs v1.6.19 PHP 7.2+ WP 3.6+ Updated Jun 3, 2025
ai-chatbotchatgptcustomer-supportlive-chatslack
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 4, 2025
Safety Verdict

Is Social Intents – Live Chat Safe to Use in 2026?

Mostly Safe

Score 79/100

Social Intents – Live Chat is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Apr 4, 2025Updated 11mo ago
Risk Assessment

The plugin "live-chat-support-by-social-intents" v1.6.19 exhibits a mixed security posture. Static analysis shows a very small attack surface with no identified entry points, which is generally a positive sign. The absence of dangerous functions, file operations, and external HTTP requests, coupled with the use of prepared statements for all SQL queries, are strong security practices. However, concerns arise from the moderate level of output escaping (75% properly escaped), suggesting potential for Cross-Site Scripting (XSS) vulnerabilities if not all output is handled securely. The lack of nonce checks on any entry points, though the entry points are currently zero, could become a concern if future updates introduce them without adequate protection. The plugin's vulnerability history is a significant red flag, with one medium-severity CVE related to XSS that remains unpatched. This indicates a recurring security weakness and a lack of timely remediation, which is a critical concern for any plugin, especially one with past XSS issues.

Key Concerns

  • Unpatched medium severity CVE
  • Output escaping not 100%
  • No nonce checks on entry points
Vulnerabilities
1 published

Social Intents – Live Chat Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32131medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Social Intents <= 1.6.14 - Authenticated (Administrator+) Stored Cross-Site Scripting

Apr 4, 2025Unpatched
Version History

Social Intents – Live Chat Release Timeline

v1.6.691 CVE
v1.6.501 CVE
v1.6.491 CVE
v1.6.481 CVE
v1.6.471 CVE
v1.6.461 CVE
v1.6.451 CVE
v1.6.441 CVE
v1.6.19Current1 CVE
v1.6.181 CVE
v1.6.141 CVE
v1.6.131 CVE
v1.6.91 CVE
v1.6.81 CVE
v1.6.71 CVE
v1.6.61 CVE
v1.6.51 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Social Intents – Live Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
18 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped24 total outputs
Attack Surface

Social Intents – Live Chat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actioninitlive-chat-support-by-socialintents.php:12
actionadmin_noticeslive-chat-support-by-socialintents.php:13
filterplugin_action_linkslive-chat-support-by-socialintents.php:14
actionwp_footerlive-chat-support-by-socialintents.php:15
actionadmin_footerlive-chat-support-by-socialintents.php:16
actionadmin_menulive-chat-support-by-socialintents.php:23
actionadmin_menulive-chat-support-by-socialintents.php:24
actioninittrunk\live-chat-support-by-socialintents.php:12
actionadmin_noticestrunk\live-chat-support-by-socialintents.php:13
filterplugin_action_linkstrunk\live-chat-support-by-socialintents.php:14
actionwp_footertrunk\live-chat-support-by-socialintents.php:15
actionadmin_footertrunk\live-chat-support-by-socialintents.php:16
actionadmin_menutrunk\live-chat-support-by-socialintents.php:23
actionadmin_menutrunk\live-chat-support-by-socialintents.php:24
Maintenance & Trust

Social Intents – Live Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 3, 2025
PHP min version7.2
Downloads67K

Community Trust

Rating66/100
Number of ratings7
Active installs400
Developer Profile

Social Intents – Live Chat Developer Profile

socialintents

6 plugins · 550 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Social Intents – Live Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/live-chat-support-by-social-intents/socialintents.png/wp-content/plugins/live-chat-support-by-social-intents/app-key.png
Script Paths
https://www.socialintents.com/api/chat/socialintents.1.4.js
Version Parameters
live-chat-support-by-social-intents/style.css?ver=live-chat-support-by-social-intents/scripts/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
silc_noAccountSpansilc_registersilc_registerCompleteaddAppKey
HTML Comments
<!-- www.socialintents.com -->
Data Attributes
id="silc_widgetID"name="silc_widgetID"id="silc_noAccountSpan"id="silc_register"id="silc_registerComplete"id="addAppKey"+3 more
JS Globals
si_domain
FAQ

Frequently Asked Questions about Social Intents – Live Chat