
SiteGlue Security & Risk Analysis
wordpress.org/plugins/siteglueConvert visitors into customers. Make it easy for mobile visitors to ask a question, get a quote or schedule an appointment via text message.
Is SiteGlue Safe to Use in 2026?
Generally Safe
Score 85/100SiteGlue has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "siteglue" v1.0 plugin exhibits a strong security posture in several key areas, with no recorded vulnerabilities, a lack of dangerous functions, and the exclusive use of prepared statements for SQL queries. The absence of file operations and external HTTP requests further reduces the potential for common attack vectors. However, the static analysis reveals a critical weakness: 100% of its output is not properly escaped. This presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the website through the plugin's output.
While the plugin has no known CVEs and a clean vulnerability history, this lack of past issues doesn't negate the immediate risk posed by the unescaped output. The attack surface is currently zero, which is excellent, but this is a small sample size and doesn't guarantee future safety, especially if functionality is added without proper security considerations. The lack of capability checks and nonce checks, while not directly exploitable due to the current lack of entry points, would become immediate concerns if any new AJAX handlers, REST API routes, or shortcodes were introduced without them.
In conclusion, "siteglue" v1.0 has several good security practices in place, particularly regarding SQL and the absence of known vulnerabilities. The primary concern is the pervasive lack of output escaping, which creates a high risk for XSS. The current minimal attack surface is a positive sign, but the unescaped output is a serious flaw that needs immediate attention to prevent potential compromises.
Key Concerns
- Output escaping is not used on any output
- No capability checks detected
- No nonce checks detected
SiteGlue Security Vulnerabilities
SiteGlue Code Analysis
Output Escaping
SiteGlue Attack Surface
WordPress Hooks 5
Maintenance & Trust
SiteGlue Maintenance & Trust
Maintenance Signals
Community Trust
SiteGlue Alternatives
SYNCRO
syncro-web-chat-2-text
Use this WordPress plugin to easily install a SYNCRO web chat to text tool (SMS chat tool) on your WordPress site.
Voizee
voizee
Voizee is a powerful communications suite application that offers callbacks, live chat, SMS, and email capabilities, all in one integrated solution.
GTChatPro Live Chat Plugin
gtchatpro
Convert Your Leads To Customers Seamlessly
Liveforce
liveforce
No coding required! Effortlessly integrate the Liveforce live chat widget into your WordPress site with just a few clicks.
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
SiteGlue Developer Profile
1 plugin · 10 total installs
How We Detect SiteGlue
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
http://load.lokalmotion.com/cs_widget/v2/cw_lokalmotion.jsHTML / DOM Fingerprints
siteglue-top-sectionrow-gluetop-titlebtn-get-it-nowdata-lokalmotion-phonedata-lokalmotion-bgdata-lokalmotion-colordata-lokalmotion-text