Free Live Chat Support Security & Risk Analysis

wordpress.org/plugins/livesupporti

Free Live Support Chat for your WordPress website.

700 active installs v1.0.12 PHP + WP 2.9.0+ Updated Dec 11, 2025
chatfree-live-chatlive-chatlivechatonline-chat
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 22, 2022
Safety Verdict

Is Free Live Chat Support Safe to Use in 2026?

Generally Safe

Score 99/100

Free Live Chat Support has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 22, 2022Updated 3mo ago
Risk Assessment

The static analysis of livesupporti v1.0.12 reveals a generally positive security posture, with no apparent direct attack vectors identified such as AJAX handlers, REST API routes, shortcodes, or cron events without authentication. The code exhibits good practices by using prepared statements for all SQL queries and performing output escaping on a majority of outputs. The absence of file operations and a low number of external HTTP requests also contribute to a more secure codebase. However, there is a single external HTTP request, which, while not inherently a vulnerability, can be a potential entry point if not handled with extreme care and proper validation. The presence of two nonce checks and one capability check suggests some attempt at securing actions, but the limited number, especially with no AJAX handlers, is noteworthy.

The vulnerability history, though, presents a significant concern. A past high-severity vulnerability, specifically Cross-Site Request Forgery (CSRF), was identified and last occurred in June 2022. While currently unpatched, the fact that there are no *currently* unpatched vulnerabilities is a positive sign. However, the historical pattern of a high-severity CSRF vulnerability indicates a potential weakness in how user actions are authenticated or authorized, and the lack of unpatched vulnerabilities could simply mean the plugin hasn't been flagged recently or the vulnerability was fixed in a later version not reflected in this data.

In conclusion, livesupporti v1.0.12 demonstrates strengths in its limited attack surface and secure SQL handling. The primary weakness lies in the historical presence of a high-severity CSRF vulnerability, suggesting a need for vigilance regarding user input validation and authorization, even with the current absence of known unpatched issues. The single external HTTP request warrants further investigation for secure implementation.

Key Concerns

  • Historical high-severity vulnerability (CSRF)
  • External HTTP request without explicit analysis
  • Low number of capability checks relative to potential actions
Vulnerabilities
1

Free Live Chat Support Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2022-2039high · 8.8Cross-Site Request Forgery (CSRF)

Free Live Chat Support <= 1.0.11 - Cross-Site Request Forgery to Cross-Site Scripting

Jun 22, 2022 Patched in 1.0.12 (580d)
Code Analysis
Analyzed Mar 16, 2026

Free Live Chat Support Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
16 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

76% escaped21 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
livesupporti_settings (livesupporti.php:81)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Free Live Chat Support Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_footerlivesupporti.php:27
actionadmin_menulivesupporti.php:29
actionadmin_initlivesupporti.php:33
Maintenance & Trust

Free Live Chat Support Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 11, 2025
PHP min version
Downloads85K

Community Trust

Rating80/100
Number of ratings27
Active installs700
Developer Profile

Free Live Chat Support Developer Profile

LiveSupporti

1 plugin · 700 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
580 days
View full developer profile
Detection Fingerprints

How We Detect Free Live Chat Support

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/livesupporti/wordpress-bg.png/wp-content/plugins/livesupporti/logo.png

HTML / DOM Fingerprints

HTML Comments
<!-- Live chat by LiveSupporti - https://livesupporti.com -->
Data Attributes
id="form1"name="form1"id="txtEmail"name="txtEmail"id="txtPassword"name="txtPassword"+3 more
FAQ

Frequently Asked Questions about Free Live Chat Support