Moneypenny Live Chat Security & Risk Analysis

wordpress.org/plugins/moneypenny-live-chat

The easiest way to install Moneypenny Live Chat on your WordPress site!

20 active installs v1.1 PHP + WP 3.0.1+ Updated Apr 11, 2018
live-chatlive-chat-saleslive-chat-supportmoney-pennymoneypenny
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Moneypenny Live Chat Safe to Use in 2026?

Generally Safe

Score 85/100

Moneypenny Live Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of moneypenny-live-chat v1.1 indicates a strong adherence to several WordPress security best practices. Notably, there are no detected dangerous functions, all SQL queries utilize prepared statements, and all observed output operations are properly escaped. The absence of file operations and external HTTP requests further reduces potential attack vectors. Furthermore, the plugin has no recorded vulnerability history, including critical or high-severity CVEs, which suggests a history of secure development or diligent patching.

However, the analysis also reveals a significant concern: a complete lack of entry points such as AJAX handlers, REST API routes, shortcodes, or cron events. While this might seem positive at first glance, it could indicate that the plugin is either extremely basic and lacks core functionality, or that its intended functionality is entirely reliant on external integration not visible in this analysis. The absence of any capability checks or nonce checks, even with zero entry points, is a potential weakness. If any entry points were to be introduced in future versions or through external interaction, these security mechanisms would be missing, leaving the plugin vulnerable to unauthorized actions or cross-site request forgery (CSRF) attacks.

In conclusion, the plugin exhibits good defensive coding practices for the analyzed aspects. The lack of vulnerabilities in its history is a positive sign. The primary weakness lies in the complete absence of any detectable interaction points and the corresponding lack of authorization and nonce checks. This presents a risk if functionality is added or if the plugin's intended use involves integration points that are not analyzed here. The plugin's security posture is good in terms of preventing common vulnerabilities within its current, limited scope, but lacks robustness for potential future expansion or integration.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • No entry points detected
Vulnerabilities
None known

Moneypenny Live Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Moneypenny Live Chat Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Moneypenny Live Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Moneypenny Live Chat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menump-livechat.php:24
actionadmin_initmp-livechat.php:25
actionwp_footermp-livechat.php:192
Maintenance & Trust

Moneypenny Live Chat Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedApr 11, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Moneypenny Live Chat Developer Profile

Moneypenny

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Moneypenny Live Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/moneypenny-live-chat/js/moneypenny-chat.js
Version Parameters
moneypenny-live-chat/js/moneypenny-chat.js?ver=

HTML / DOM Fingerprints

CSS Classes
logo
HTML Comments
<!-- begin Moneypenny code --><!-- end Moneypenny code --><!-- begin Moneypenny GTM code --><!-- end Moneypenny GTM code -->
Data Attributes
name="moneypenny_option[widget_id]"name="moneypenny_option[enable]"name="moneypenny_option[gtm_ua]"
JS Globals
ga
FAQ

Frequently Asked Questions about Moneypenny Live Chat