LiveChat LazucruB Security & Risk Analysis

wordpress.org/plugins/livechat-lazucrub

This plugin is a client of RealTime Web Chat websocket service, build real time chat on your site.

0 active installs v1.2 PHP 7.0+ WP 4.7+ Updated Dec 5, 2020
chatonlinereal-timewebsocket
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LiveChat LazucruB Safe to Use in 2026?

Generally Safe

Score 85/100

LiveChat LazucruB has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The livechat-lazucrub plugin v1.2 exhibits a generally strong security posture based on the provided static analysis. The complete absence of any known CVEs, critically or highly vulnerable taint flows, and the use of prepared statements for all SQL queries are significant strengths. Furthermore, the code demonstrates good practices with a high percentage of properly escaped outputs and the presence of nonce and capability checks. The limited attack surface, with only one shortcode and no unprotected entry points, further contributes to its favorable security profile.

However, a few minor areas for consideration remain. While the percentage of escaped outputs is good at 75%, the remaining 25% could potentially introduce vulnerabilities if user-supplied data is not handled with sufficient care. The presence of a shortcode, while not inherently insecure, is an entry point that warrants careful review to ensure it doesn't become a vector for potential issues.

In conclusion, livechat-lazucrub v1.2 appears to be a secure plugin with a low-risk profile. The developers have implemented several key security best practices. Continuous monitoring for new vulnerabilities and ensuring all outputs remain consistently escaped are recommended to maintain this strong security posture.

Key Concerns

  • Unescaped output detected (25%)
Vulnerabilities
None known

LiveChat LazucruB Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LiveChat LazucruB Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
18 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped24 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
realtimewp_settings_save (admin.php:45)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LiveChat LazucruB Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[real-time-chat] livechat-lazucrub.php:24
WordPress Hooks 3
actionadmin_menuadmin.php:2
filtertemplate_includelivechat-lazucrub.php:13
actioninitlivechat-lazucrub.php:32
Maintenance & Trust

LiveChat LazucruB Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedDec 5, 2020
PHP min version7.0
Downloads8K

Community Trust

Rating20/100
Number of ratings1
Active installs0
Developer Profile

LiveChat LazucruB Developer Profile

Chirukin Bogdan

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LiveChat LazucruB

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/livechat-lazucrub/css/style.min.css/wp-content/plugins/livechat-lazucrub/lib/css/emoji.css/wp-content/plugins/livechat-lazucrub/lib/js/config.js/wp-content/plugins/livechat-lazucrub/lib/js/util.js/wp-content/plugins/livechat-lazucrub/lib/js/jquery.emojiarea.js/wp-content/plugins/livechat-lazucrub/lib/js/emoji-picker.js/wp-content/plugins/livechat-lazucrub/js/socket.js
Script Paths
/wp-content/plugins/livechat-lazucrub/lib/js/config.js/wp-content/plugins/livechat-lazucrub/lib/js/util.js/wp-content/plugins/livechat-lazucrub/lib/js/jquery.emojiarea.js/wp-content/plugins/livechat-lazucrub/lib/js/emoji-picker.js/wp-content/plugins/livechat-lazucrub/js/socket.js

HTML / DOM Fingerprints

CSS Classes
rtch-containerroomItemroomTitleroomActionchatWindowuserTriggerchatBodyuserColumn+9 more
Data Attributes
data-roomdata-roledata-userdata-emojiabledata-action
JS Globals
window.emojiPicker
REST Endpoints
/wp-json/
Shortcode Output
<iframe src="width="100%"height="100%"
FAQ

Frequently Asked Questions about LiveChat LazucruB