SiteHeart Security & Risk Analysis

wordpress.org/plugins/siteheart

SiteHeart - Free online chat for website.

60 active installs v1.0.0 PHP + WP 2.8+ Updated Mar 11, 2014
chatchat-widgetlive-helponline-chatoperator
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SiteHeart Safe to Use in 2026?

Generally Safe

Score 85/100

SiteHeart has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'siteheart' plugin v1.0.0 demonstrates a concerning lack of security best practices despite its small attack surface and absence of known vulnerabilities. While the plugin has no recorded CVEs and utilizes prepared statements for its SQL queries, the static analysis reveals significant issues. Notably, 100% of the 74 outputs are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis shows two flows with unsanitized paths, which, although not classified as critical or high severity, still represent potential security weaknesses that could be exploited if more complex or sensitive data were involved. The complete absence of nonce and capability checks across all entry points (even though the attack surface is currently zero) is a critical oversight, as any future additions without these checks would be immediately vulnerable. The lack of vulnerability history is a positive sign but should not be interpreted as a guarantee of future security, especially given the current code quality issues.

Key Concerns

  • Output escaping not properly implemented (74/74)
  • Taint analysis: unsanitized paths detected (2/2 flows)
  • Missing nonce checks (0/0 total)
  • Missing capability checks (0/0 total)
Vulnerabilities
None known

SiteHeart Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SiteHeart Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
74
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped74 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
sh_options_page (siteheart.php:96)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SiteHeart Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitsiteheart.php:20
actionadmin_menusiteheart.php:22
actionadmin_noticessiteheart.php:23
actionwp_headsiteheart.php:24
Maintenance & Trust

SiteHeart Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedMar 11, 2014
PHP min version
Downloads10K

Community Trust

Rating100/100
Number of ratings3
Active installs60
Developer Profile

SiteHeart Developer Profile

siteheart

1 plugin · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SiteHeart

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/siteheart/success.php/wp-content/plugins/siteheart/set.php/wp-content/plugins/siteheart/widget.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about SiteHeart