LiveAgent – Omnichannel Help Desk & Live Chat Software Security & Risk Analysis

wordpress.org/plugins/liveagent

LiveAgent is a multichannel help desk software that offers over 180 help desk and live chat features. Discover the power of the universal inbox, a hyb …

500 active installs v4.5.1 PHP + WP 3.0.1+ Updated Aug 20, 2025
chat-pluginlive-chatlive-chat-supportlive-supportwordpress-live-chat
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 7, 2025
Safety Verdict

Is LiveAgent – Omnichannel Help Desk & Live Chat Software Safe to Use in 2026?

Generally Safe

Score 99/100

LiveAgent – Omnichannel Help Desk & Live Chat Software has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 7, 2025Updated 7mo ago
Risk Assessment

The liveagent plugin version 4.5.1 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and includes a reasonable number of capability checks (5) and nonce checks (2). There are no identified critical or high-severity taint flows, and the absence of unpatched CVEs is a strong indicator of a proactive security approach. The attack surface is also minimal, with only one entry point (a shortcode) and no unprotected AJAX handlers or REST API routes. This suggests a generally well-developed and security-conscious plugin.

However, there are notable areas of concern. The most significant is the low rate of proper output escaping, with only 18% of 11 total outputs being properly escaped. This leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks, where malicious scripts could be injected and executed within a user's browser. The presence of 4 flows with unsanitized paths, even without critical or high severity ratings, indicates potential weaknesses in how file paths are handled, which could be exploited in conjunction with other vulnerabilities. The plugin also performs file operations and makes external HTTP requests, which, while not inherently insecure, are entry points that require careful scrutiny. The history of a medium-severity CSRF vulnerability, even though patched, signifies that past security issues have existed and should be a reminder to maintain vigilance.

In conclusion, while the liveagent plugin has made significant strides in security with its SQL practices and attack surface management, the glaring issue with output escaping presents a substantial risk. The potential for XSS, coupled with unsanitized path flows, necessitates immediate attention. The plugin's development team should prioritize addressing the output escaping deficiencies and reviewing the handling of file paths to further harden its security profile. The absence of current unpatched vulnerabilities is a positive sign, but the identified weaknesses require remediation to ensure a robust security posture.

Key Concerns

  • Low output escaping rate
  • Flows with unsanitized paths detected
  • Medium severity vulnerability in history
  • File operations detected
  • External HTTP requests detected
Vulnerabilities
1

LiveAgent – Omnichannel Help Desk & Live Chat Software Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-47667medium · 4.3Cross-Site Request Forgery (CSRF)

LiveAgent <= 4.4.7 - Cross-Site Request Forgery

May 7, 2025 Patched in 4.4.8 (15d)
Code Analysis
Analyzed Mar 16, 2026

LiveAgent – Omnichannel Help Desk & Live Chat Software Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
2 escaped
Nonce Checks
2
Capability Checks
5
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

18% escaped11 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

5 flows4 with unsanitized paths
reviewNoticeMessage (Settings.class.php:102)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LiveAgent – Omnichannel Help Desk & Live Chat Software Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[customerPortalLogin] liveagent.php:115
WordPress Hooks 14
actionadmin_noticesliveagent.php:37
filterwp_footerliveagent.php:92
actionadmin_initliveagent.php:99
actionuser_registerliveagent.php:103
actionmgm_user_registerliveagent.php:107
actionwoocommerce_created_customerliveagent.php:111
actionadmin_menuliveagent.php:125
filteradmin_headliveagent.php:129
actionwp_enqueue_scriptsliveagent.php:133
actionadmin_enqueue_scriptsliveagent.php:137
actionin_admin_footerliveagent.php:141
actionplugins_loadedliveagent.php:145
filteradmin_footer_textliveagent.php:149
actionadmin_noticesSettings.class.php:87
Maintenance & Trust

LiveAgent – Omnichannel Help Desk & Live Chat Software Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 20, 2025
PHP min version
Downloads49K

Community Trust

Rating84/100
Number of ratings32
Active installs500
Developer Profile

LiveAgent – Omnichannel Help Desk & Live Chat Software Developer Profile

qusupport

1 plugin · 500 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
15 days
View full developer profile
Detection Fingerprints

How We Detect LiveAgent – Omnichannel Help Desk & Live Chat Software

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/liveagent/lasignup.js
Version Parameters
liveagent/lasignup.js?ver=

HTML / DOM Fingerprints

CSS Classes
liveagent-chat-buttonliveagent-chat-windowliveagent-chat-bubble
Data Attributes
data-liveagent-scriptdata-liveagent-url
JS Globals
LiveAgentliveagentLocalizations
Shortcode Output
<form id='redirectForm' name='redirectForm' action='
FAQ

Frequently Asked Questions about LiveAgent – Omnichannel Help Desk & Live Chat Software