Smartsupp – live chat, AI shopping assistant and chatbots Security & Risk Analysis

wordpress.org/plugins/smartsupp-live-chat

Boost your sales and turn visitors into customers with live chat, AI tools and chatbots. Smartsupp is trusted by 100,000+ online stores.

20K active installs v3.9.2 PHP 5.3.2+ WP 3.0+ Updated Dec 8, 2025
aichatbotlivechatonline-chatsmartsupp
98
A · Safe
CVEs total2
Unpatched0
Last CVEFeb 18, 2026
Safety Verdict

Is Smartsupp – live chat, AI shopping assistant and chatbots Safe to Use in 2026?

Generally Safe

Score 98/100

Smartsupp – live chat, AI shopping assistant and chatbots has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Feb 18, 2026Updated 3mo ago
Risk Assessment

The static analysis of smartsupp-live-chat v3.9.2 reveals a generally strong security posture with several positive indicators. The complete absence of dangerous functions, SQL queries utilizing prepared statements exclusively, and a very high percentage of properly escaped output are commendable. Furthermore, the presence of nonce and capability checks, despite a limited attack surface, suggests an awareness of basic security principles. However, the lack of any taint analysis flows being analyzed is a concern, as it means potential vulnerabilities in how data is handled and processed might have been missed. The vulnerability history shows two medium-severity CVEs in the past, primarily related to Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). While there are currently no unpatched vulnerabilities, the historical presence of these common web security flaws, especially XSS, warrants continued vigilance. The last recorded vulnerability date also suggests a potential for undiscovered issues that could emerge in future versions.

Key Concerns

  • No taint analysis flows analyzed
  • Historical medium-severity CVEs (2)
Vulnerabilities
2

Smartsupp – live chat, AI shopping assistant and chatbots Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-12448medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Smartsupp – live chat, AI shopping assistant and chatbots <= 3.9.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

Feb 18, 2026 Patched in 3.9.2 (1d)
CVE-2024-38790medium · 4.3Cross-Site Request Forgery (CSRF)

Smartsupp – live chat, chatbots, AI and lead generation <= 3.6 - Cross-Site Request Forgery

Jul 20, 2024 Patched in 3.7 (27d)
Code Analysis
Analyzed Mar 16, 2026

Smartsupp – live chat, AI shopping assistant and chatbots Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
3
57 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

95% escaped60 total outputs
Attack Surface

Smartsupp – live chat, AI shopping assistant and chatbots Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuadmin\class-smartsupp-admin.php:35
actionadmin_initadmin\class-smartsupp-admin.php:36
actionadmin_enqueue_scriptsadmin\class-smartsupp-admin.php:37
actioninitpublic\class-smartsupp.php:65
actionwp_footerpublic\class-smartsupp.php:72
actionplugins_loadedsmartsupp.php:36
actionplugins_loadedsmartsupp.php:46
Maintenance & Trust

Smartsupp – live chat, AI shopping assistant and chatbots Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 8, 2025
PHP min version5.3.2
Downloads369K

Community Trust

Rating94/100
Number of ratings131
Active installs20K
Developer Profile

Smartsupp – live chat, AI shopping assistant and chatbots Developer Profile

Smartsupp

2 plugins · 20K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
14 days
View full developer profile
Detection Fingerprints

How We Detect Smartsupp – live chat, AI shopping assistant and chatbots

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smartsupp-live-chat/public/css/smartsupp-style.css/wp-content/plugins/smartsupp-live-chat/public/js/smartsupp-widget.js/wp-content/plugins/smartsupp-live-chat/public/js/smartsupp-backend.js
Generator Patterns
Smartsupp
Script Paths
/wp-content/plugins/smartsupp-live-chat/public/js/smartsupp-widget.js/wp-content/plugins/smartsupp-live-chat/public/js/smartsupp-backend.js
Version Parameters
smartsupp-live-chat/public/css/smartsupp-style.css?ver=smartsupp-live-chat/public/js/smartsupp-widget.js?ver=smartsupp-live-chat/public/js/smartsupp-backend.js?ver=

HTML / DOM Fingerprints

CSS Classes
smartsupp-chat-widget
HTML Comments
<!-- Smartsupp chat code --><!-- END Smartsupp chat code -->
Data Attributes
data-widget-id
JS Globals
Smartsupp
REST Endpoints
/wp-json/smartsupp/v1/nonce/wp-json/smartsupp/v1/chat
FAQ

Frequently Asked Questions about Smartsupp – live chat, AI shopping assistant and chatbots