
Casengo Live Chat Support Security & Risk Analysis
wordpress.org/plugins/the-casengo-chat-widgetLive Chat by Casengo, fully functional, easy to use and has great design! Install live chat support on your WordPress site today!
Is Casengo Live Chat Support Safe to Use in 2026?
Use With Caution
Score 63/100Casengo Live Chat Support has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The security posture of the-casengo-chat-widget v2.1.4 exhibits a mixed bag of good practices and significant concerns. On the positive side, the plugin demonstrates a commitment to secure database interactions by utilizing prepared statements exclusively and shows some level of access control with one capability check. The absence of dangerous functions, file operations, and external HTTP requests is also reassuring, and the taint analysis indicates no immediate critical or high-severity issues within the analyzed flows.
However, the static analysis reveals a critical flaw in output escaping, with 0% of the 11 total outputs being properly escaped. This widespread lack of escaping presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the plugin has a known, unpatched medium severity vulnerability, which is a direct security risk. While the attack surface is currently reported as zero, the presence of an unpatched CVE, coupled with the output escaping issues, suggests that the plugin may not be rigorously maintained or tested for security before releases.
In conclusion, while the plugin avoids some common pitfalls like raw SQL queries and large attack surfaces, the severe lack of output escaping and the existence of an unpatched CVE are major security weaknesses. These issues, particularly the XSS risk, require immediate attention. The plugin's vulnerability history, with a recent medium severity CSRF issue, suggests a pattern of security oversights that need to be addressed to improve its overall security.
Key Concerns
- Unpatched Medium Severity CVE
- No proper output escaping
Casengo Live Chat Support Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Casengo Live Chat Support <= 2.1.4 - Cross-Site Request Forgery
Casengo Live Chat Support Code Analysis
Output Escaping
Data Flow Analysis
Casengo Live Chat Support Attack Surface
WordPress Hooks 3
Maintenance & Trust
Casengo Live Chat Support Maintenance & Trust
Maintenance Signals
Community Trust
Casengo Live Chat Support Alternatives
LiveHelpNow Help Desk
livehelpnow-helpdesk
LiveHelpNow Help desk embed plugin facilitates real time interactions between your website visitors and your customer service via multiple channels.
VISITLEAD Live Chat and Realtime Monitoring
visitlead
Enterprise Live Chat and realtime monitoring for business websites. We convert your visitors to clients. Live Chat is only one piece of our success.
Chaport — Live Chat & Chatbots
chaport
Modern live chat plugin for WordPress. Powerful features: multi-channel, chatbots, customization, etc. Free plan. Unlimited chats & websites.
HelpCrunch – Live Chat, Chatbot & Knowledge Base for Customer Service
helpcrunch-live-chat
The one-stop platform for even stronger customer relations. Bolster your customer support with its live chat, chatbot, and knowledge base software.
Chat Bro Live Group Chat
chatbro
Chat Bro - live Chat for your website. Turns your Telegram Chat or VK Chat into Live Chat on your website. Allows your visitors to Chat in live group …
Casengo Live Chat Support Developer Profile
1 plugin · 70 total installs
How We Detect Casengo Live Chat Support
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/the-casengo-chat-widget/css/casengo-style.css/wp-content/plugins/the-casengo-chat-widget/js/casengo.js//*.casengo.com/apis/vip-widget.js//*.casengo.com/apis/inline-widget.jsHTML / DOM Fingerprints
casengo-vipbtn<!-- Live Chat and Customer Support Software by Casengo - WordPress Live Chat and Customer Support Software v2.0 - http://www.casengo.com/ --><!--Place this code where you want the button to be rendered --><!--Place this code after the last Casengo script --><!-- // Casengo Wordpress Live Chat and Customer Support Software -->subdomaingrouplabelpositionthemelanguage+1 morecasengo_domaincasengo_typecasengo_poscasengo_labelcasengo_themecasengo_lang+1 more/wp-json/the-casengo-chat-widget/