Pure Chat – Live Chat & More! Security & Risk Analysis

wordpress.org/plugins/pure-chat

Pure Chat provides a Live Chat plugin with Unlimited Chats for your website!

3K active installs v2.41 PHP 5.3.0+ WP 3.0.1+ Updated Feb 24, 2025
chat-widgetlive-chatpurechatvisitor-trackingwordpress-chat
90
A · Safe
CVEs total3
Unpatched0
Last CVEFeb 18, 2025
Download
Safety Verdict

Is Pure Chat – Live Chat & More! Safe to Use in 2026?

Generally Safe

Score 90/100

Pure Chat – Live Chat & More! has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Feb 18, 2025Updated 1yr ago
Risk Assessment

The pure-chat plugin v2.41 exhibits a mixed security posture. On the positive side, static analysis reveals a small attack surface, with the single AJAX handler being protected by a capability check. The code demonstrates good practices in other areas, such as using prepared statements for all SQL queries, a high percentage of output escaping, and no detected file operations or external HTTP requests. Taint analysis also shows no critical or high severity vulnerabilities, indicating that unsanitized data is not flowing into dangerous functions.

However, the plugin's vulnerability history presents a significant concern. With a total of three known medium severity CVEs, all of which are currently unpatched, there is a clear pattern of past security weaknesses. The common vulnerability types, CSRF and XSS, suggest potential issues with input validation and output sanitization that may not have been fully addressed in previous fixes. While the current version shows no critical flaws in static or taint analysis, the history of past vulnerabilities, especially unpatched ones, means users remain at risk from these known issues.

In conclusion, while the current codebase for pure-chat v2.41 appears to have addressed many common security pitfalls, the presence of three unpatched medium severity CVEs overrides these strengths. The plugin's past indicates a potential for recurring vulnerabilities, and users should be aware of the ongoing risks associated with these unpatched issues.

Key Concerns

  • Unpatched medium severity CVEs
Vulnerabilities
3

Pure Chat – Live Chat & More! Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2024-13736medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Pure Chat – Live Chat & More! <= 2.4 - Reflected Cross-Site Scripting via purechatWidgetName Parameter

Feb 18, 2025 Patched in 2.41 (10d)
CVE-2024-35673medium · 5.4Cross-Site Request Forgery (CSRF)

Pure Chat – Live Chat Plugin & More! <= 2.22 - Cross-Site Request Forgery

Jun 5, 2024 Patched in 2.23 (15d)
CVE-2024-3595medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Pure Chat – Live Chat Plugin & More! <= 2.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting

May 8, 2024 Patched in 2.23 (29d)
Code Analysis
Analyzed Mar 17, 2026

Pure Chat – Live Chat & More! Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
23 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped25 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
pure_chat_update (purechat.php:59)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Pure Chat – Live Chat & More! Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_pure_chat_updatepurechat.php:39
WordPress Hooks 3
actionwp_footerpurechat.php:36
actionadmin_menupurechat.php:38
actionadmin_enqueue_scriptspurechat.php:40
Maintenance & Trust

Pure Chat – Live Chat & More! Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 24, 2025
PHP min version5.3.0
Downloads247K

Community Trust

Rating82/100
Number of ratings45
Active installs3K
Developer Profile

Pure Chat – Live Chat & More! Developer Profile

pure-chat

1 plugin · 3K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
18 days
View full developer profile
Detection Fingerprints

How We Detect Pure Chat – Live Chat & More!

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pure-chat/favicon.ico/wp-content/plugins/pure-chat/purechatStyles.css
Version Parameters
pure-chat/purechatStyles.css?ver=

HTML / DOM Fingerprints

CSS Classes
purechatbuttonboxpurechatcontentdivpurechatbuttonpurechatlinkboxpurechatCurrentWidgetNamepurechatCurrentWidgetCode
HTML Comments
<!-- Please select a widget in the wordpress plugin to activate purechat -->
Data Attributes
data-cfasync='false'
JS Globals
pureChatChildWindowpurechatNameToPasspurechatIdToPasspurechatNonce
FAQ

Frequently Asked Questions about Pure Chat – Live Chat & More!