
Live Chat Security & Risk Analysis
wordpress.org/plugins/live-chat-support-systemLive Chat plugin is a fully functional free Chat plugin, Add Live Chat plugin to your site to chat by sending emotions and attachments with message n …
Is Live Chat Safe to Use in 2026?
Generally Safe
Score 85/100Live Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "live-chat-support-system" v1.3 exhibits a concerning security posture due to a significant number of unprotected AJAX handlers and a pervasive lack of proper input sanitization. All 20 identified AJAX handlers lack authentication checks, representing a substantial attack surface that could be exploited by unauthenticated users. Furthermore, the taint analysis reveals a critical issue with 10 out of 11 analyzed flows having unsanitized paths, indicating a high likelihood of remote code execution or other serious vulnerabilities. The complete absence of capability checks on any entry points exacerbates these risks, as there are no role-based access controls in place. While the plugin has no recorded vulnerability history, this absence should not be interpreted as a sign of strong security, but rather potentially a lack of past scrutiny or public disclosure. The lack of prepared statements for all SQL queries is another significant weakness that could lead to SQL injection vulnerabilities. The limited output escaping (24%) further increases the risk of cross-site scripting (XSS) attacks. The plugin's strengths are minimal, primarily consisting of no directly identified dangerous functions or file operations. However, these strengths are heavily overshadowed by the critical deficiencies in authentication, sanitization, and SQL practices.
Key Concerns
- AJAX handlers without auth checks
- Taint flows with unsanitized paths (critical)
- SQL queries without prepared statements
- Capability checks missing
- Output escaping is low
- Nonce check present but insufficient
Live Chat Security Vulnerabilities
Live Chat Release Timeline
Live Chat Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Live Chat Attack Surface
AJAX Handlers 20
WordPress Hooks 6
Maintenance & Trust
Live Chat Maintenance & Trust
Maintenance Signals
Community Trust
Live Chat Alternatives
LiveHelpNow Help Desk
livehelpnow-helpdesk
LiveHelpNow Help desk embed plugin facilitates real time interactions between your website visitors and your customer service via multiple channels.
ChatSystem.io
chatsystemio
ChatSystem.io is the real time LeadChat.com plugin for loading the Lead Chat service.
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot
hive-support
The All-In-One Help Desk, Live Chat & AI Chat Bot Plugin for WordPress.
Paldesk – Live Chat & Helpdesk
paldesk-live-chat-helpdesk
Powerful live chat & helpdesk plugin made for your WordPress website. Convert leads to sales & help customers in real time - it's free!
Secure ChatSystem.io
secure-chatsystem-io
ChatSystem.io is the real time LeadChat.com plugin for loading the Lead Chat service.
Live Chat Developer Profile
8 plugins · 4.1M total installs
How We Detect Live Chat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/live-chat-support-system/inc/css/bootstrap.min.css/wp-content/plugins/live-chat-support-system/inc/js/bootstrap.min.js/wp-content/plugins/live-chat-support-system/inc/css/supportsystem.css/wp-content/plugins/live-chat-support-system/inc/css/font-awesome.min.css/wp-content/plugins/live-chat-support-system/inc/css/dataTables.bootstrap.min.css/wp-content/plugins/live-chat-support-system/inc/js/jquery.dataTables.min.js/wp-content/plugins/live-chat-support-system/inc/js/dataTables.bootstrap.min.js/wp-content/plugins/live-chat-support-system/inc/js/bootstrap.min.js/wp-content/plugins/live-chat-support-system/inc/js/jquery.dataTables.min.js/wp-content/plugins/live-chat-support-system/inc/js/dataTables.bootstrap.min.jslive-chat-support-system/inc/css/bootstrap.min.css?ver=live-chat-support-system/inc/js/bootstrap.min.js?ver=live-chat-support-system/inc/css/supportsystem.css?ver=live-chat-support-system/inc/css/font-awesome.min.css?ver=live-chat-support-system/inc/css/dataTables.bootstrap.min.css?ver=live-chat-support-system/inc/js/jquery.dataTables.min.js?ver=live-chat-support-system/inc/js/dataTables.bootstrap.min.js?ver=HTML / DOM Fingerprints
lvcht-chat-btnlvcht_headerlvcht_chat_titlelvcht_messageslvcht_message_bodylvcht_message_senderlvcht_message_datelvcht_form_control+8 more<!-- for admin --><!--conversation Table--><!--message Table--><!----- offline table------->+2 moredata-chat-iddata-conv-iddata-user-typesupportsystembymysenseLVCHT_AJAX_URL/wp-json/live-chat-support-system/v1/send-message/wp-json/live-chat-support-system/v1/load-message/wp-json/live-chat-support-system/v1/admin-send-message/wp-json/live-chat-support-system/v1/admin-load-message