SaleAssist Live Video Engagements Security & Risk Analysis

wordpress.org/plugins/saleassist

The best Live Video Engagement solution for your website. The most trusted Live Video solution for WordPress and WooCommerce.

0 active installs v2.0.0 PHP + WP 4.8+ Updated Mar 23, 2023
live-commercelive-shoppinglive-streaminglive-video-callvideo-commerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SaleAssist Live Video Engagements Safe to Use in 2026?

Generally Safe

Score 85/100

SaleAssist Live Video Engagements has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "saleassist" plugin v2.0.0 demonstrates several good security practices, including a high percentage of properly escaped outputs and a decent number of capability and nonce checks. It also has a clean vulnerability history with no recorded CVEs, suggesting a potentially stable and well-maintained codebase. However, a significant concern arises from the presence of one unprotected AJAX handler, representing a direct entry point for potential attackers to exploit. While taint analysis didn't reveal critical or high-severity issues, the single flow with unsanitized paths warrants attention, as it could lead to unexpected behavior or vulnerabilities if not handled carefully. The plugin's limited attack surface and lack of file operations or external HTTP requests are positive indicators, but the unprotected AJAX handler remains the most immediate risk that should be addressed.

Key Concerns

  • Unprotected AJAX handler
  • Flow with unsanitized paths
Vulnerabilities
None known

SaleAssist Live Video Engagements Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SaleAssist Live Video Engagements Code Analysis

Dangerous Functions
0
Raw SQL Queries
9
10 prepared
Unescaped Output
3
71 escaped
Nonce Checks
7
Capability Checks
9
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

53% prepared19 total queries

Output Escaping

96% escaped74 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
display_notice (class.saleassist-admin.php:704)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

SaleAssist Live Video Engagements Attack Surface

Entry Points3
Unprotected1

AJAX Handlers 1

authwp_ajax_saleassist_recheck_queueclass.saleassist-admin.php:74

Shortcodes 2

[saleassist_button] class.saleassist.php:41
[saleassist_iframe] class.saleassist.php:42
WordPress Hooks 18
actionadmin_initclass.saleassist-admin.php:65
actionadmin_menuclass.saleassist-admin.php:66
actionadmin_noticesclass.saleassist-admin.php:67
actionadmin_enqueue_scriptsclass.saleassist-admin.php:68
actionactivity_box_endclass.saleassist-admin.php:69
actionrightnow_endclass.saleassist-admin.php:70
actionadmin_action_saleassist_recheck_queueclass.saleassist-admin.php:73
filterplugin_action_linksclass.saleassist-admin.php:76
filterall_pluginsclass.saleassist-admin.php:79
actionupdate_option_saleassist_api_keyclass.saleassist.php:31
actionadd_option_saleassist_api_keyclass.saleassist.php:32
actionupdate_option_saleassist_secret_keyclass.saleassist.php:34
actionadd_option_saleassist_secret_keyclass.saleassist.php:35
actionwp_enqueue_scriptsclass.saleassist.php:37
actionwp_footerclass.saleassist.php:38
actioninitsaleassist.php:64
actionrest_api_initsaleassist.php:67
actioninitsaleassist.php:71
Maintenance & Trust

SaleAssist Live Video Engagements Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedMar 23, 2023
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

SaleAssist Live Video Engagements Developer Profile

saleassist

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SaleAssist Live Video Engagements

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/saleassist/css/saleassist.css/wp-content/plugins/saleassist/js/saleassist.js/wp-content/plugins/saleassist/js/saleassist-admin.js/wp-content/plugins/saleassist/js/saleassist-widget.js
Script Paths
/wp-content/plugins/saleassist/js/saleassist.js/wp-content/plugins/saleassist/js/saleassist-admin.js/wp-content/plugins/saleassist/js/saleassist-widget.js
Version Parameters
saleassist/css/saleassist.css?ver=saleassist/js/saleassist.js?ver=saleassist/js/saleassist-admin.js?ver=saleassist/js/saleassist-widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
saleassist_chatsaleassist-admin-wrap
HTML Comments
<!-- saleassist -->
Data Attributes
data-saleassist-widget-iddata-saleassist-setup-widget-iddata-saleassist-chat-id
JS Globals
saleassist_settingssaleassist_widget_idsaleassist_chat_idsaleassist_page_url
REST Endpoints
/wp-json/saleassist/v1/chat
Shortcode Output
[saleassist_chat]
FAQ

Frequently Asked Questions about SaleAssist Live Video Engagements