LiveHelpNow Help Desk Security & Risk Analysis

wordpress.org/plugins/livehelpnow-helpdesk

LiveHelpNow Help desk embed plugin facilitates real time interactions between your website visitors and your customer service via multiple channels.

60 active installs v0.2.0 PHP 5.4+ WP 4.5+ Updated Dec 10, 2021
live-chatlive-chat-pluginlive-chat-softwarelive-chat-systemlive-chat-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LiveHelpNow Help Desk Safe to Use in 2026?

Generally Safe

Score 85/100

LiveHelpNow Help Desk has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The livehelpnow-helpdesk plugin version 0.2.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, all of which utilize prepared statements, and there are no known vulnerabilities or CVEs associated with this plugin, suggesting a history of stable and secure development or a lack of prior rigorous security auditing. However, significant concerns arise from the static analysis. The plugin has a notable number of unsanitized paths identified in the taint analysis, with 5 out of 6 analyzed flows having this issue. While no critical or high-severity taint flows were explicitly flagged, unsanitized paths are a common precursor to various injection vulnerabilities. Additionally, the lack of nonce checks and capability checks across all entry points, coupled with a moderate percentage of output not being properly escaped, presents a considerable risk of cross-site scripting (XSS) and unauthorized actions if an attacker can influence the data flowing through these unsanitized paths. The presence of external HTTP requests also warrants scrutiny for potential SSRF or data leakage risks.

Key Concerns

  • Unsanitized paths found in taint analysis
  • No nonce checks on entry points
  • No capability checks on entry points
  • Output not properly escaped
  • External HTTP requests
Vulnerabilities
None known

LiveHelpNow Help Desk Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

LiveHelpNow Help Desk Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

75% escaped32 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

6 flows5 with unsanitized paths
authenticate_user (src\class\API\Authentication.php:45)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LiveHelpNow Help Desk Attack Surface

Entry Points0
Unprotected0

Scheduled Events 1

lhn_destroy_user_session_schedule
Maintenance & Trust

LiveHelpNow Help Desk Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedDec 10, 2021
PHP min version5.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

LiveHelpNow Help Desk Developer Profile

livehelpnow

1 plugin · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LiveHelpNow Help Desk

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/livehelpnow-helpdesk/assets/dist/scripts/chat.js/wp-content/plugins/livehelpnow-helpdesk/assets/dist/styles/admin.css
Script Paths
/wp-content/plugins/livehelpnow-helpdesk/assets/dist/scripts/chat.js

HTML / DOM Fingerprints

Data Attributes
data-lhn-chat-id
JS Globals
lhnchat
FAQ

Frequently Asked Questions about LiveHelpNow Help Desk