
Rabbit Messenger Live-chat Security & Risk Analysis
wordpress.org/plugins/rabbit-messenger-live-chatThis plugin allows you to display the Rabbit Messenger Live-chat on your WordPress website.
Is Rabbit Messenger Live-chat Safe to Use in 2026?
Generally Safe
Score 100/100Rabbit Messenger Live-chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rabbit-messenger-live-chat" plugin version 0.4.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has a high percentage of properly escaped output, indicating an awareness of preventing cross-site scripting (XSS) vulnerabilities. The absence of known CVEs and a clean vulnerability history further suggest a generally well-maintained codebase. However, a significant concern arises from the static analysis revealing a single REST API route that lacks any permission callback. This creates a direct entry point that could be exploited by an unauthenticated user, potentially leading to unauthorized actions or information disclosure depending on the functionality of that specific endpoint.
While the taint analysis shows no identified unsanitized paths, the lack of capability checks and nonce checks on the identified entry point is concerning. The presence of the Guzzle library also warrants attention, as bundled libraries can become a security risk if they are outdated and contain known vulnerabilities. Overall, the plugin has strengths in data handling but presents a critical weakness with an unprotected REST API endpoint that needs immediate attention to mitigate potential security risks.
Key Concerns
- Unprotected REST API endpoint without permission callback
- Missing nonce checks
- Missing capability checks
- Bundled library (Guzzle) potentially outdated
Rabbit Messenger Live-chat Security Vulnerabilities
Rabbit Messenger Live-chat Code Analysis
Bundled Libraries
Output Escaping
Rabbit Messenger Live-chat Attack Surface
REST API Routes 1
WordPress Hooks 6
Maintenance & Trust
Rabbit Messenger Live-chat Maintenance & Trust
Maintenance Signals
Community Trust
Rabbit Messenger Live-chat Alternatives
All-in-one Chat Button by anychat.one
anychat-widget
Free wordpress widget for live chat via WhatsApp, Facebook Messenger, Telegram and other chat apps.
Easy Chat Button
easy-chat-button
Easy Chat Button is a simple and lightweight plugin that allows you to add a WhatsApp button to your website. It enables visitors to contact you direc …
SaleChaty – AI Chatbot
salechaty-ai-chatbot
Your Cross-Border AI Private Domain Operation Assistant
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Rabbit Messenger Live-chat Developer Profile
1 plugin · 0 total installs
How We Detect Rabbit Messenger Live-chat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rabbit-messenger-live-chat/styles.css/wp-content/plugins/rabbit-messenger-live-chat/main.jsrabbit-messenger-live-chat/styles.css?ver=rabbit-messenger-live-chat/main.js?ver=HTML / DOM Fingerprints
rabbit-messenger-live-chat-widgetavatar-urllogin-urlwhatsapp-urlwelcome-descriptiondisplay-options+4 more/rmlc/login