
Site Chat on Telegram Security & Risk Analysis
wordpress.org/plugins/site-chat-on-telegramIntegrate a support chat on your website with Telegram. Customers message via chat widget; admins reply in Telegram.
Is Site Chat on Telegram Safe to Use in 2026?
Generally Safe
Score 98/100Site Chat on Telegram has a strong security track record. Known vulnerabilities have been patched promptly.
The "site-chat-on-telegram" plugin v1.1.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by using prepared statements for all SQL queries and properly escaping all output, which are crucial for preventing common web vulnerabilities. The plugin also includes a reasonable number of nonce and capability checks relative to its entry points.
However, several concerns warrant attention. The presence of one AJAX handler without authentication checks creates a direct entry point for potential unauthorized actions, especially if it performs sensitive operations. The taint analysis revealing two flows with unsanitized paths, both classified as high severity, is a significant risk. While the vulnerability history shows no currently unpatched CVEs, the single high severity vulnerability in the past, specifically related to deserialization, coupled with the static analysis finding of the `unserialize` function, indicates a historical area of weakness that requires vigilant monitoring and secure coding practices.
In conclusion, while the plugin has strong foundations in secure SQL and output handling, the unauthenticated AJAX endpoint and the high-severity taint flows are critical areas of concern. The past deserialization vulnerability further underscores the need for careful code review and potential remediation for the identified taint flows. The overall security posture is moderately concerning due to these specific weaknesses.
Key Concerns
- Unprotected AJAX handler found
- High severity taint flows found (2)
- Dangerous function 'unserialize' found
- 1 known high severity CVE in history
Site Chat on Telegram Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Site Chat on Telegram <= 1.0.4 - Unauthenticated PHP Object Injection
Site Chat on Telegram Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Site Chat on Telegram Attack Surface
AJAX Handlers 12
Shortcodes 1
WordPress Hooks 31
Maintenance & Trust
Site Chat on Telegram Maintenance & Trust
Maintenance Signals
Community Trust
Site Chat on Telegram Alternatives
BusinessBot AI Chat Assistant
ai-chat-assistant-for-business
An AI-powered support assistant that uses Gemini GPT Api to interact with your site visitors using your business data.
TOCHAT.BE
tochat-be
Add a free WhatsApp click-to-chat button to your WordPress site. Easily connect your WhatsApp account and start chatting with customers instantly.
AI Chatbot for WordPress by Customerly
customerly
AI Chatbot to support customers, create engaging messages and send automated emails.
BuddyBot – OpenAI Assistants, AI Chatbots and Support Agents for WordPress
buddybot-ai-custom-ai-assistant-and-chat-agent
Discover AI Chatbots for WordPress, only plugin built on native OpenAI assistants. Explore a new different way to chat!
Zeno – AI-Powered Chatbot
zeno-chatbot-ai
An AI-powered WordPress automation chatbot plugin that helps you automate support, engage visitors, and answer questions using OpenAI or Google Gemini
Site Chat on Telegram Developer Profile
3 plugins · 400 total installs
How We Detect Site Chat on Telegram
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/site-chat-on-telegram/assets/css/chat.css/wp-content/plugins/site-chat-on-telegram/assets/js/chat.js/wp-content/plugins/site-chat-on-telegram/assets/css/admin.css/wp-content/plugins/site-chat-on-telegram/assets/js/admin.js/wp-content/plugins/site-chat-on-telegram/assets/js/webhook.js/wp-content/plugins/site-chat-on-telegram/images/chat-icon.svg/wp-content/plugins/site-chat-on-telegram/images/chat-close.svg/wp-content/plugins/site-chat-on-telegram/assets/vendors/petite-vue.js/wp-content/plugins/site-chat-on-telegram/assets/js/chat.js/wp-content/plugins/site-chat-on-telegram/assets/js/admin.js/wp-content/plugins/site-chat-on-telegram/assets/js/webhook.js/wp-content/plugins/site-chat-on-telegram/assets/css/chat.css?ver=/wp-content/plugins/site-chat-on-telegram/assets/js/chat.js?ver=/wp-content/plugins/site-chat-on-telegram/assets/css/admin.css?ver=/wp-content/plugins/site-chat-on-telegram/assets/js/admin.js?ver=/wp-content/plugins/site-chat-on-telegram/assets/js/webhook.js?ver=HTML / DOM Fingerprints
scot-chat-widgetscot-chat-messagesscot-chat-inputscot-chat-messagescot-chat-supportscot-chat-customer<!-- Chat Widget --><!-- Chat widget initialization -->data-scot-ajax-urldata-scot-noncescot_data