Live Chat Plugin for WooCommerce – LiveChat Security & Risk Analysis

wordpress.org/plugins/livechat-woocommerce

Live chat and help desk software plugin for WooCommerce. Add live chat to your WooCommerce store to connect immediately with customers.

1K active installs v5.0.11 PHP 7.2+ WP 4.4+ Updated Jan 13, 2026
chat-pluginlive-chatwoocommercewoocommerce-live-chatwordpress-live-chat
100
A · Safe
CVEs total1
Unpatched0
Last CVEJan 8, 2024
Safety Verdict

Is Live Chat Plugin for WooCommerce – LiveChat Safe to Use in 2026?

Generally Safe

Score 100/100

Live Chat Plugin for WooCommerce – LiveChat has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 8, 2024Updated 2mo ago
Risk Assessment

The 'livechat-woocommerce' plugin version 5.0.11 presents a mixed security posture. While it demonstrates good practices in output escaping and avoids dangerous functions, file operations, and bundled libraries, significant concerns arise from its attack surface and lack of authorization checks on entry points. Three out of four identified entry points, specifically AJAX handlers, are not protected by authentication checks, creating a substantial risk for unauthorized access and potential manipulation of plugin functionalities. The single REST API route, while having a permission callback, is still part of the overall entry point count, and its security depends entirely on the correctness of that callback.

The plugin's vulnerability history shows one known medium-severity CVE, a Cross-Site Request Forgery (CSRF). Although currently patched, this pattern suggests a history of security weaknesses that could resurface or be exploited if not diligently managed. The absence of taint analysis results is neutral, but the presence of raw SQL queries without prepared statements is a critical concern, potentially opening the door to SQL injection vulnerabilities, especially when combined with unprotected entry points.

In conclusion, the plugin has areas of strength, particularly in output sanitization. However, the unprotected AJAX handlers and the raw SQL query are significant weaknesses that overshadow these strengths. The past medium CVE indicates that the plugin has been susceptible to vulnerabilities, reinforcing the need for caution and vigilance. Addressing the unprotected entry points and ensuring all SQL queries are properly prepared should be immediate priorities.

Key Concerns

  • Unprotected AJAX handlers
  • Raw SQL queries without prepared statements
  • Medium severity CVE in vulnerability history
Vulnerabilities
1

Live Chat Plugin for WooCommerce – LiveChat Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-872f13bc-e6d0-4307-b2c9-b55a44df1016-livechat-woocommercemedium · 4.3Cross-Site Request Forgery (CSRF)

LiveChat WooCommerce <= 2.2.16 - Cross-Site Request Forgery

Jan 8, 2024 Patched in 2.2.17 (15d)
Code Analysis
Analyzed Mar 16, 2026

Live Chat Plugin for WooCommerce – LiveChat Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
0
38 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

100% escaped38 total outputs
Attack Surface
3 unprotected

Live Chat Plugin for WooCommerce – LiveChat Attack Surface

Entry Points4
Unprotected3

AJAX Handlers 3

authwp_ajax_text-refresh-cartincludes\plugin.php:124
noprivwp_ajax_text-refresh-cartincludes\plugin.php:125
authwp_ajax_disconnect_accountincludes\plugin.php:163

REST API Routes 1

GET/wp-json/text/v1/(?P<pluginId>\d+)/diagnoseincludes\routes\diagnose.php:115
WordPress Hooks 14
actionactivated_pluginincludes\plugin.php:34
actionplugins_loadedincludes\plugin.php:35
actionrest_api_initincludes\plugin.php:36
actionelementor/initincludes\plugin.php:131
filterelementor/icons_manager/additional_tabsincludes\plugin.php:132
actionelementor/widgets/registerincludes\plugin.php:135
actionelementor/widgets/widgets_registeredincludes\plugin.php:137
actionwp_enqueue_scriptsincludes\plugin.php:141
actionwp_enqueue_scriptsincludes\plugin.php:177
actionadmin_noticesincludes\plugin.php:192
actionadmin_initincludes\plugin.php:220
actionadmin_menuincludes\plugin.php:226
actionadmin_enqueue_scriptsincludes\plugin.php:229
filterclean_urlincludes\plugin.php:318
Maintenance & Trust

Live Chat Plugin for WooCommerce – LiveChat Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 13, 2026
PHP min version7.2
Downloads187K

Community Trust

Rating90/100
Number of ratings22
Active installs1K
Developer Profile

Live Chat Plugin for WooCommerce – LiveChat Developer Profile

WP-LiveChat

10 plugins · 113K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
1833 days
View full developer profile
Detection Fingerprints

How We Detect Live Chat Plugin for WooCommerce – LiveChat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/livechat-woocommerce/includes/css/text-icons.css/wp-content/plugins/livechat-woocommerce/includes/css/text.css/wp-content/plugins/livechat-woocommerce/includes/css/widgets.css/wp-content/plugins/livechat-woocommerce/includes/js/textConnect.js
Script Paths
/wp-content/plugins/livechat-woocommerce/includes/js/textConnect.js
Version Parameters
livechat-woocommerce/includes/css/text-icons.css?ver=livechat-woocommerce/includes/css/text.css?ver=livechat-woocommerce/includes/css/widgets.css?ver=livechat-woocommerce/includes/js/textConnect.js?ver=

HTML / DOM Fingerprints

CSS Classes
text-livechattext-icons
Data Attributes
data-elementor-device-mode
JS Globals
textConnect
REST Endpoints
/wp-json/livechat/v1/diagnose
FAQ

Frequently Asked Questions about Live Chat Plugin for WooCommerce – LiveChat