REVE Chat – AI Chatbot, Live Chat, Helpdesk, Campaigns & More Security & Risk Analysis

wordpress.org/plugins/revechat

A free all-in-one customer service and lead generation platform capable of engaging, retaining, and converting customers.

100 active installs v6.4.4 PHP 7.0+ WP 2.7+ Updated Feb 22, 2026
chatbotcustomer-supporthelpdesklive-chatlivechat
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 9, 2025
Download
Safety Verdict

Is REVE Chat – AI Chatbot, Live Chat, Helpdesk, Campaigns & More Safe to Use in 2026?

Mostly Safe

Score 78/100

REVE Chat – AI Chatbot, Live Chat, Helpdesk, Campaigns & More is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Apr 9, 2025Updated 1mo ago
Risk Assessment

The "revechat" plugin v6.4.4 presents a concerning security posture primarily due to significant vulnerabilities in its access control mechanisms and a history of known security issues. The static analysis reveals two direct entry points into the plugin: one AJAX handler and one REST API route, both of which lack proper authentication or permission checks. This oversight represents a critical weakness, as it allows any unauthenticated user to potentially interact with these functions, leading to unintended consequences or information disclosure. While the plugin demonstrates good practices in its SQL query handling, using prepared statements, and has no reported critical or high severity taint flows, the lack of output escaping on a substantial portion of its outputs (64%) raises concerns about potential Cross-Site Scripting (XSS) vulnerabilities. The plugin's vulnerability history, including a currently unpatched medium severity CVE, further exacerbates these concerns. The recurring theme of Cross-Site Request Forgery (CSRF) in past vulnerabilities, coupled with the absence of nonce checks, suggests a persistent pattern of inadequate security implementation regarding user actions.

Key Concerns

  • Unauthenticated AJAX handler
  • Unauthenticated REST API route
  • Insufficient output escaping
  • Unpatched medium severity CVE
  • No nonce checks
Vulnerabilities
1

REVE Chat – AI Chatbot, Live Chat, Helpdesk, Campaigns & More Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32559medium · 6.1Cross-Site Request Forgery (CSRF)

REVE Chat <= 6.2.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Apr 9, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

REVE Chat – AI Chatbot, Live Chat, Helpdesk, Campaigns & More Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
4 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

36% escaped11 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
reveChatOptions (revechat.php:342)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

REVE Chat – AI Chatbot, Live Chat, Helpdesk, Campaigns & More Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 1

authwp_ajax_revechat_disconnectrevechat.php:116

REST API Routes 1

GET/wp-json/revechat/v1/cartrevechat.php:60
WordPress Hooks 9
actionadmin_initrevechat.php:41
actionwp_headrevechat.php:43
actionadmin_menurevechat.php:47
actionadmin_enqueue_scriptsrevechat.php:50
actionwp_enqueue_scriptsrevechat.php:55
actionrest_api_initrevechat.php:58
actiontemplate_redirectrevechat.php:68
filterwoocommerce_rest_prepare_product_objectrevechat.php:111
actionactivated_pluginrevechat.php:713
Maintenance & Trust

REVE Chat – AI Chatbot, Live Chat, Helpdesk, Campaigns & More Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 22, 2026
PHP min version7.0
Downloads32K

Community Trust

Rating96/100
Number of ratings9
Active installs100
Developer Profile

REVE Chat – AI Chatbot, Live Chat, Helpdesk, Campaigns & More Developer Profile

REVE Chat

1 plugin · 100 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect REVE Chat – AI Chatbot, Live Chat, Helpdesk, Campaigns & More

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/revechat/build/revechat-frontend.css/wp-content/plugins/revechat/build/revechat-frontend.js
Version Parameters
revechat/build/revechat-frontend.css?ver=revechat/build/revechat-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
revechat-widget-container
HTML Comments
<!-- REVE Chat Start --><!-- REVE Chat End -->
JS Globals
revechatSettings
REST Endpoints
/wp-json/revechat/v1/cart
FAQ

Frequently Asked Questions about REVE Chat – AI Chatbot, Live Chat, Helpdesk, Campaigns & More