Live Chat Plugin for Elementor – LiveChat Security & Risk Analysis

wordpress.org/plugins/livechat-elementor

A hassle-free WordPress Elementor live chat plugin for sales and customer support.

30 active installs v5.0.11 PHP 7.2+ WP 4.4+ Updated Jan 13, 2026
chat-pluginelementorlive-chatwordpress-chatwordpress-live-chat
100
A · Safe
CVEs total1
Unpatched0
Last CVEJan 8, 2024
Safety Verdict

Is Live Chat Plugin for Elementor – LiveChat Safe to Use in 2026?

Generally Safe

Score 100/100

Live Chat Plugin for Elementor – LiveChat has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 8, 2024Updated 2mo ago
Risk Assessment

The "livechat-elementor" plugin v5.0.11 exhibits a mixed security posture. On the positive side, all identified outputs are properly escaped, and there are no identified dangerous functions or file operations. The plugin also correctly handles external HTTP requests and has a history of no currently unpatched vulnerabilities, with the last known vulnerability being a medium severity CSRF issue from early 2024, which is now patched. This indicates good remediation practices for past issues.

However, significant concerns arise from the attack surface analysis. The plugin exposes three unprotected AJAX handlers, presenting a substantial risk of unauthorized actions if exploited. While the plugin has nonce checks and capability checks in some areas, the absence of these on a majority of its AJAX entry points is a critical weakness. The static analysis also reveals that its single SQL query does not utilize prepared statements, which, although a single instance, increases the risk of SQL injection vulnerabilities.

In conclusion, while the plugin has strengths in output sanitization and prompt patching of historical vulnerabilities, the presence of multiple unprotected AJAX endpoints and the use of raw SQL queries are significant security weaknesses that warrant immediate attention. The potential for unauthorized actions through the unprotected AJAX handlers is the most pressing concern.

Key Concerns

  • Unprotected AJAX handlers
  • SQL queries without prepared statements
Vulnerabilities
1

Live Chat Plugin for Elementor – LiveChat Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-32c2a25d-e660-4700-8df3-b043cf6aa78a-livechat-elementormedium · 4.3Cross-Site Request Forgery (CSRF)

LiveChat Elementor <= 1.0.13 - Cross-Site Request Forgery

Jan 8, 2024 Patched in 1.0.14 (15d)
Code Analysis
Analyzed Mar 16, 2026

Live Chat Plugin for Elementor – LiveChat Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
38 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

100% escaped38 total outputs
Attack Surface
3 unprotected

Live Chat Plugin for Elementor – LiveChat Attack Surface

Entry Points4
Unprotected3

AJAX Handlers 3

authwp_ajax_text-refresh-cartincludes\plugin.php:124
noprivwp_ajax_text-refresh-cartincludes\plugin.php:125
authwp_ajax_disconnect_accountincludes\plugin.php:163

REST API Routes 1

GET/wp-json/text/v1/(?P<pluginId>\d+)/diagnoseincludes\routes\diagnose.php:115
WordPress Hooks 14
actionactivated_pluginincludes\plugin.php:34
actionplugins_loadedincludes\plugin.php:35
actionrest_api_initincludes\plugin.php:36
actionelementor/initincludes\plugin.php:131
filterelementor/icons_manager/additional_tabsincludes\plugin.php:132
actionelementor/widgets/registerincludes\plugin.php:135
actionelementor/widgets/widgets_registeredincludes\plugin.php:137
actionwp_enqueue_scriptsincludes\plugin.php:141
actionwp_enqueue_scriptsincludes\plugin.php:177
actionadmin_noticesincludes\plugin.php:192
actionadmin_initincludes\plugin.php:220
actionadmin_menuincludes\plugin.php:226
actionadmin_enqueue_scriptsincludes\plugin.php:229
filterclean_urlincludes\plugin.php:318
Maintenance & Trust

Live Chat Plugin for Elementor – LiveChat Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 13, 2026
PHP min version7.2
Downloads6K

Community Trust

Rating60/100
Number of ratings2
Active installs30
Developer Profile

Live Chat Plugin for Elementor – LiveChat Developer Profile

WP-LiveChat

10 plugins · 113K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
1833 days
View full developer profile
Detection Fingerprints

How We Detect Live Chat Plugin for Elementor – LiveChat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/livechat-elementor/includes/css/text-icons.css/wp-content/plugins/livechat-elementor/includes/css/widgets.css/wp-content/plugins/livechat-elementor/includes/css/text.css/wp-content/plugins/livechat-elementor/includes/js/textConnect.js
Script Paths
/wp-content/plugins/livechat-elementor/includes/js/textConnect.js
Version Parameters
livechat-elementor/includes/css/text-icons.css?ver=livechat-elementor/includes/css/widgets.css?ver=livechat-elementor/includes/css/text.css?ver=livechat-elementor/includes/js/textConnect.js?ver=

HTML / DOM Fingerprints

CSS Classes
texttext-livechattext-icons
Data Attributes
data-elementor-device-mode
JS Globals
textConnect
REST Endpoints
/wp-json/livechat/v1/diagnose
FAQ

Frequently Asked Questions about Live Chat Plugin for Elementor – LiveChat