
Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk Security & Risk Analysis
wordpress.org/plugins/thrivedeskAdd ThriveDesk AI Live Chat & Chatbot to your WordPress for free to answer customers' questions and provide excellent support.
Is Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk Safe to Use in 2026?
Generally Safe
Score 99/100Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The ThriveDesk plugin v2.1.6 presents a mixed security posture. While it demonstrates good practices like using prepared statements for a high percentage of SQL queries and proper output escaping, there are notable areas of concern. The significant attack surface, with 11 AJAX handlers and 5 of them lacking authentication checks, is a primary risk. This could allow unauthenticated users to trigger plugin functionality that might have unintended consequences or be exploitable if not properly secured downstream.
Although no critical or high severity taint flows were detected, 3 flows with unsanitized paths were identified. These, combined with the unprotected AJAX handlers, suggest potential avenues for attackers to manipulate file operations or other sensitive code if specific conditions are met. The plugin's vulnerability history shows a single medium severity CVE related to Cross-site Scripting, which was patched. The timing of the last vulnerability (2024-11-11) is relatively recent, indicating that while vulnerabilities have been addressed, ongoing vigilance is necessary.
Overall, the plugin benefits from a strong foundation in secure coding practices for SQL and output handling. However, the substantial number of unprotected AJAX endpoints and the presence of unsanitized path flows introduce specific vulnerabilities that require attention. The plugin's track record of addressing past vulnerabilities is positive, but the current attack surface without proper authorization is a notable weakness.
Key Concerns
- Unprotected AJAX handlers detected
- Flows with unsanitized paths identified
- Medium severity CVE history
Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WordPress Helpdesk & Live Chat Plugin Powered by AI – ThriveDesk <= 2.0.6 - Reflected Cross-Site Scripting
Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk Release Timeline
Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk Attack Surface
AJAX Handlers 11
REST API Routes 2
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk Maintenance & Trust
Maintenance Signals
Community Trust
Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk Alternatives
AI Chatbot – Jotform
jotform-ai-chatbot
AI chatbot that automates support, answers FAQs, drives WooCommerce sales, generates leads, and boosts engagement — easy setup, no coding!
Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System
support-genix-lite
AI-powered helpdesk & support ticket system with chatbot, knowledge base, and smart automation for WordPress.
AI Chat App – Live Agent Handover, Help Docs, Email, Call Button, Fast Support
help-dialog
Improve customer support with AI chat, live agent handover, FAQs, search, and contact form. Cut support tickets by 50% or more while boosting sales.
REVE Chat – AI Chatbot, Live Chat, Helpdesk, Campaigns & More
revechat
A free all-in-one customer service and lead generation platform capable of engaging, retaining, and converting customers.
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot
hive-support
The All-In-One Help Desk, Live Chat & AI Chat Bot Plugin for WordPress.
Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk Developer Profile
1 plugin · 100 total installs
How We Detect Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/thrivedesk/assets/css/bootstrap.min.css/wp-content/plugins/thrivedesk/assets/css/style.css/wp-content/plugins/thrivedesk/assets/js/app.js/wp-content/plugins/thrivedesk/assets/js/bootstrap.min.js/wp-content/plugins/thrivedesk/assets/js/vendor.js/wp-content/plugins/thrivedesk/assets/js/vue.js/wp-content/plugins/thrivedesk/assets/js/vendors/vue-multiselect.min.js/wp-content/plugins/thrivedesk/assets/js/vendors/vue-clipboard2.min.js/wp-content/plugins/thrivedesk/assets/js/app.js/wp-content/plugins/thrivedesk/assets/js/bootstrap.min.js/wp-content/plugins/thrivedesk/assets/js/vendor.js/wp-content/plugins/thrivedesk/assets/js/vue.js/wp-content/plugins/thrivedesk/assets/js/vendors/vue-multiselect.min.js/wp-content/plugins/thrivedesk/assets/js/vendors/vue-clipboard2.min.jsthrivedesk/assets/css/bootstrap.min.css?ver=thrivedesk/assets/css/style.css?ver=thrivedesk/assets/js/app.js?ver=thrivedesk/assets/js/bootstrap.min.js?ver=thrivedesk/assets/js/vendor.js?ver=thrivedesk/assets/js/vue.js?ver=thrivedesk/assets/js/vendors/vue-multiselect.min.js?ver=thrivedesk/assets/js/vendors/vue-clipboard2.min.js?ver=HTML / DOM Fingerprints
thrivedesk-appthrivedesk-widget<!-- ThriveDesk Widget Start --><!-- ThriveDesk Widget End -->data-thrivedesk-widget-urlwindow.ThriveDeskwindow.tdSettings/wp-json/thrivedesk/v1/settings/wp-json/thrivedesk/v1/connect