
Live Chat Plugin for Elementor – LiveChat Security & Risk Analysis
wordpress.org/plugins/livechat-elementorA hassle-free WordPress Elementor live chat plugin for sales and customer support.
Is Live Chat Plugin for Elementor – LiveChat Safe to Use in 2026?
Generally Safe
Score 100/100Live Chat Plugin for Elementor – LiveChat has a strong security track record. Known vulnerabilities have been patched promptly.
The "livechat-elementor" plugin v5.0.11 exhibits a mixed security posture. On the positive side, all identified outputs are properly escaped, and there are no identified dangerous functions or file operations. The plugin also correctly handles external HTTP requests and has a history of no currently unpatched vulnerabilities, with the last known vulnerability being a medium severity CSRF issue from early 2024, which is now patched. This indicates good remediation practices for past issues.
However, significant concerns arise from the attack surface analysis. The plugin exposes three unprotected AJAX handlers, presenting a substantial risk of unauthorized actions if exploited. While the plugin has nonce checks and capability checks in some areas, the absence of these on a majority of its AJAX entry points is a critical weakness. The static analysis also reveals that its single SQL query does not utilize prepared statements, which, although a single instance, increases the risk of SQL injection vulnerabilities.
In conclusion, while the plugin has strengths in output sanitization and prompt patching of historical vulnerabilities, the presence of multiple unprotected AJAX endpoints and the use of raw SQL queries are significant security weaknesses that warrant immediate attention. The potential for unauthorized actions through the unprotected AJAX handlers is the most pressing concern.
Key Concerns
- Unprotected AJAX handlers
- SQL queries without prepared statements
Live Chat Plugin for Elementor – LiveChat Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
LiveChat Elementor <= 1.0.13 - Cross-Site Request Forgery
Live Chat Plugin for Elementor – LiveChat Code Analysis
SQL Query Safety
Output Escaping
Live Chat Plugin for Elementor – LiveChat Attack Surface
AJAX Handlers 3
REST API Routes 1
WordPress Hooks 14
Maintenance & Trust
Live Chat Plugin for Elementor – LiveChat Maintenance & Trust
Maintenance Signals
Community Trust
Live Chat Plugin for Elementor – LiveChat Alternatives
JivoChat Live Chat – WP live chat plugin for WordPress
jivochat
Omnichannel Live Chat and Help Desk plugin, optimized for WordPress. Free, fast, easy to install and to use. Turn your visitors into happy customers!
Live Chat by User.com
userengage-live-chat-marketing-automation-integration
With Live Chat by User.com you can chat with any visitor on your website with a simple Wordpress plugin.
Live Chat Plugin for WooCommerce – LiveChat
livechat-woocommerce
Live chat and help desk software plugin for WooCommerce. Add live chat to your WooCommerce store to connect immediately with customers.
Replain
replain
Be in touch with your clients through Telegram, WhatsApp or Facebook Messenger. Fast, functional and free live-chat service for your website.
LiveAgent – Omnichannel Help Desk & Live Chat Software
liveagent
LiveAgent is a multichannel help desk software that offers over 180 help desk and live chat features. Discover the power of the universal inbox, a hyb …
Live Chat Plugin for Elementor – LiveChat Developer Profile
10 plugins · 113K total installs
How We Detect Live Chat Plugin for Elementor – LiveChat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/livechat-elementor/includes/css/text-icons.css/wp-content/plugins/livechat-elementor/includes/css/widgets.css/wp-content/plugins/livechat-elementor/includes/css/text.css/wp-content/plugins/livechat-elementor/includes/js/textConnect.js/wp-content/plugins/livechat-elementor/includes/js/textConnect.jslivechat-elementor/includes/css/text-icons.css?ver=livechat-elementor/includes/css/widgets.css?ver=livechat-elementor/includes/css/text.css?ver=livechat-elementor/includes/js/textConnect.js?ver=HTML / DOM Fingerprints
texttext-livechattext-iconsdata-elementor-device-modetextConnect/wp-json/livechat/v1/diagnose