
TG Live Chat Security & Risk Analysis
wordpress.org/plugins/tg-live-chatConnect your website visitors with live chat through messaging service. Customers chat on your website while you reply from your messaging app.
Is TG Live Chat Safe to Use in 2026?
Generally Safe
Score 100/100TG Live Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tg-live-chat" v1.0.4 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices with 100% of SQL queries using prepared statements and a high rate of output escaping (94%). The complete absence of known CVEs and a clean vulnerability history are also strong indicators of a well-maintained and secure plugin.
However, significant concerns arise from its attack surface. With a total of 5 entry points, 3 of which lack permission callbacks, there's a notable exposure of functionality without proper authentication or authorization checks. The taint analysis further highlights this weakness, revealing 2 flows with unsanitized paths, both classified as high severity. These unsanitized flows, coupled with unprotected entry points, suggest potential vulnerabilities that could be exploited.
In conclusion, while the plugin benefits from robust internal coding practices regarding SQL and output handling, and has no historical vulnerabilities, the substantial number of unprotected entry points and high-severity unsanitized taint flows represent a tangible security risk. These areas require immediate attention to mitigate potential exploitation.
Key Concerns
- Unprotected REST API routes (3)
- High severity unsanitized taint flows (2)
- Unprotected AJAX handlers (implicitly via overall unprotected entry points)
TG Live Chat Security Vulnerabilities
TG Live Chat Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
TG Live Chat Attack Surface
AJAX Handlers 1
REST API Routes 4
WordPress Hooks 11
Scheduled Events 2
Maintenance & Trust
TG Live Chat Maintenance & Trust
Maintenance Signals
Community Trust
TG Live Chat Alternatives
Lime Connect (formerly Userlike) – WordPress Live Chat plugin
userlike
Free live chat plugin to chat with the visitors of your website. Integrate a beautiful and fully customizable chat box. Hosted in Europe.
Chat Floating Button BY XD
chat-floating-button-by-xd
Floating button for chatting with your visitors via WhatsApp.
Richpanel – Customer Support Helpdesk & Chat
richpanel-for-woocommerce
Free Live Chat & Help desk for WooCommerce. Integrate in 2 mins.
Paldesk – Live Chat & Helpdesk
paldesk-live-chat-helpdesk
Powerful live chat & helpdesk plugin made for your WordPress website. Convert leads to sales & help customers in real time - it's free!
5chat – Blazing fast live chat
5chat-blazing-fast-live-chat
Ultra-fast live chat widget that loads in
TG Live Chat Developer Profile
6 plugins · 180 total installs
How We Detect TG Live Chat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tg-live-chat/assets/css/admin-styles.css/wp-content/plugins/tg-live-chat/assets/js/admin-scripts.js/wp-content/plugins/tg-live-chat/assets/css/chat-widget.css/wp-content/plugins/tg-live-chat/assets/js/chat-widget-customer-details.js/wp-content/plugins/tg-live-chat/assets/js/chat-widget-notifications.js/wp-content/plugins/tg-live-chat/assets/js/chat-widget-core.js/wp-content/plugins/tg-live-chat/assets/js/admin-scripts.js/wp-content/plugins/tg-live-chat/assets/js/chat-widget-customer-details.js/wp-content/plugins/tg-live-chat/assets/js/chat-widget-notifications.js/wp-content/plugins/tg-live-chat/assets/js/chat-widget-core.jstg-live-chat/assets/css/admin-styles.css?ver=tg-live-chat/assets/js/admin-scripts.js?ver=tg-live-chat/assets/css/chat-widget.css?ver=tg-live-chat/assets/js/chat-widget-customer-details.js?ver=tg-live-chat/assets/js/chat-widget-notifications.js?ver=tg-live-chat/assets/js/chat-widget-core.js?ver=HTML / DOM Fingerprints
nandanntglivechat-widget-stylesnandanntglivechatAjaxnandanntglivechatWidgetnandanntglivechatAjaxnandanntglivechatWidget/wp-json/nandanntglivechat/v1/