Casengo Live Chat Support Security & Risk Analysis

wordpress.org/plugins/the-casengo-chat-widget

Live Chat by Casengo, fully functional, easy to use and has great design! Install live chat support on your WordPress site today!

70 active installs v2.1.4 PHP + WP 3.3+ Updated Jan 22, 2016
chatchat-onlinechat-pluginchat-softwarechat-widget
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is Casengo Live Chat Support Safe to Use in 2026?

Use With Caution

Score 63/100

Casengo Live Chat Support has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 10yr ago
Risk Assessment

The security posture of the-casengo-chat-widget v2.1.4 exhibits a mixed bag of good practices and significant concerns. On the positive side, the plugin demonstrates a commitment to secure database interactions by utilizing prepared statements exclusively and shows some level of access control with one capability check. The absence of dangerous functions, file operations, and external HTTP requests is also reassuring, and the taint analysis indicates no immediate critical or high-severity issues within the analyzed flows.

However, the static analysis reveals a critical flaw in output escaping, with 0% of the 11 total outputs being properly escaped. This widespread lack of escaping presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the plugin has a known, unpatched medium severity vulnerability, which is a direct security risk. While the attack surface is currently reported as zero, the presence of an unpatched CVE, coupled with the output escaping issues, suggests that the plugin may not be rigorously maintained or tested for security before releases.

In conclusion, while the plugin avoids some common pitfalls like raw SQL queries and large attack surfaces, the severe lack of output escaping and the existence of an unpatched CVE are major security weaknesses. These issues, particularly the XSS risk, require immediate attention. The plugin's vulnerability history, with a recent medium severity CSRF issue, suggests a pattern of security oversights that need to be addressed to improve its overall security.

Key Concerns

  • Unpatched Medium Severity CVE
  • No proper output escaping
Vulnerabilities
1

Casengo Live Chat Support Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58688medium · 4.3Cross-Site Request Forgery (CSRF)

Casengo Live Chat Support <= 2.1.4 - Cross-Site Request Forgery

Sep 22, 2025Unpatched
Code Analysis
Analyzed Mar 17, 2026

Casengo Live Chat Support Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped11 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
casengo_settings (casengo.php:146)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Casengo Live Chat Support Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_footercasengo.php:85
actionadmin_menucasengo.php:103
actionadmin_initcasengo.php:106
Maintenance & Trust

Casengo Live Chat Support Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedJan 22, 2016
PHP min version
Downloads86K

Community Trust

Rating86/100
Number of ratings31
Active installs70
Developer Profile

Casengo Live Chat Support Developer Profile

Casengo

1 plugin · 70 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Casengo Live Chat Support

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/the-casengo-chat-widget/css/casengo-style.css/wp-content/plugins/the-casengo-chat-widget/js/casengo.js
Script Paths
//*.casengo.com/apis/vip-widget.js//*.casengo.com/apis/inline-widget.js

HTML / DOM Fingerprints

CSS Classes
casengo-vipbtn
HTML Comments
<!-- Live Chat and Customer Support Software by Casengo - WordPress Live Chat and Customer Support Software v2.0 - http://www.casengo.com/ --><!--Place this code where you want the button to be rendered --><!--Place this code after the last Casengo script --><!-- // Casengo Wordpress Live Chat and Customer Support Software -->
Data Attributes
subdomaingrouplabelpositionthemelanguage+1 more
JS Globals
casengo_domaincasengo_typecasengo_poscasengo_labelcasengo_themecasengo_lang+1 more
REST Endpoints
/wp-json/the-casengo-chat-widget/
FAQ

Frequently Asked Questions about Casengo Live Chat Support