
SiteHeart Security & Risk Analysis
wordpress.org/plugins/siteheartSiteHeart - Free online chat for website.
Is SiteHeart Safe to Use in 2026?
Generally Safe
Score 85/100SiteHeart has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'siteheart' plugin v1.0.0 demonstrates a concerning lack of security best practices despite its small attack surface and absence of known vulnerabilities. While the plugin has no recorded CVEs and utilizes prepared statements for its SQL queries, the static analysis reveals significant issues. Notably, 100% of the 74 outputs are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis shows two flows with unsanitized paths, which, although not classified as critical or high severity, still represent potential security weaknesses that could be exploited if more complex or sensitive data were involved. The complete absence of nonce and capability checks across all entry points (even though the attack surface is currently zero) is a critical oversight, as any future additions without these checks would be immediately vulnerable. The lack of vulnerability history is a positive sign but should not be interpreted as a guarantee of future security, especially given the current code quality issues.
Key Concerns
- Output escaping not properly implemented (74/74)
- Taint analysis: unsanitized paths detected (2/2 flows)
- Missing nonce checks (0/0 total)
- Missing capability checks (0/0 total)
SiteHeart Security Vulnerabilities
SiteHeart Code Analysis
Output Escaping
Data Flow Analysis
SiteHeart Attack Surface
WordPress Hooks 4
Maintenance & Trust
SiteHeart Maintenance & Trust
Maintenance Signals
Community Trust
SiteHeart Alternatives
Tawk.To Live Chat
tawkto-live-chat
(OFFICIAL tawk.to plugin) Instantly chat with visitors on your website with the free tawk.to chat widget. Website: http://tawk.to
3CX Free Live Chat, Calls & Messaging
wp-live-chat-support
Chat with your website visitors in real-time for free! Engage with your customers and increase sales.
LeadConnector
leadconnector
LeadConnector: It helps you to add the LeadConnector chat widget and the LeadConnector funnel pages to your WordPress website.
Smartsupp – live chat, AI shopping assistant and chatbots
smartsupp-live-chat
Boost your sales and turn visitors into customers with live chat, AI tools and chatbots. Smartsupp is trusted by 100,000+ online stores.
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist
bit-assist
Floating sticky chat button for WhatsApp Chat, Facebook Messenger, Telegram, Instagram, SMS, Call, Discord chat, TikTok, Line & 30+ channels
SiteHeart Developer Profile
1 plugin · 60 total installs
How We Detect SiteHeart
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/siteheart/success.php/wp-content/plugins/siteheart/set.php/wp-content/plugins/siteheart/widget.php