
Tidio – Live Chat & AI Chatbots Security & Risk Analysis
wordpress.org/plugins/tidio-live-chatAdd Tidio Live Chat to your WordPress for free to answer customers’ questions, engage website visitors, generate leads, and increase sales.
Is Tidio – Live Chat & AI Chatbots Safe to Use in 2026?
Generally Safe
Score 99/100Tidio – Live Chat & AI Chatbots has a strong security track record. Known vulnerabilities have been patched promptly.
The Tidio Live Chat plugin version 7.0.0 exhibits a mixed security posture. On the positive side, the static analysis reveals a lack of identified critical vulnerabilities within the code itself, with no dangerous functions, raw SQL queries, or unsanitized taint flows detected. The presence of nonce and capability checks, along with the use of prepared statements for SQL, are good security practices. However, the plugin's history of two known CVEs, one of which was high severity and the other medium, raises significant concern. The fact that these vulnerabilities were Exposure of Sensitive Information and Cross-Site Request Forgery suggests recurring or complex security flaws.
The primary weaknesses lie not in the current code's apparent lack of immediate threats, but in its past. The historical vulnerabilities, particularly the CSRF and sensitive information exposure, indicate that the plugin has previously been susceptible to attacks that could compromise user data or site integrity. While there are currently no unpatched vulnerabilities, the existence of these past issues warrants vigilance. The relatively low percentage of properly escaped output (44%) is also a minor concern, as it could lead to cross-site scripting (XSS) vulnerabilities if not handled carefully in all contexts.
Key Concerns
- High severity vulnerability in history (unpatched in past)
- Medium severity vulnerability in history (unpatched in past)
- Low percentage of properly escaped output
Tidio – Live Chat & AI Chatbots Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Tidio – Live Chat, Chatbots & Email Integration <= 5.2.0 - Sensitive Information Disclosure
Tidio Live Chat < 4.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Tidio – Live Chat & AI Chatbots Code Analysis
Output Escaping
Tidio – Live Chat & AI Chatbots Attack Surface
WordPress Hooks 13
Maintenance & Trust
Tidio – Live Chat & AI Chatbots Maintenance & Trust
Maintenance Signals
Community Trust
Tidio – Live Chat & AI Chatbots Alternatives
Crisp – Live Chat and Chatbot
crisp
A Free, one-click-to-install, Live Chat and chatbot plugin. No coding skills are required. Used by more than 30 000 customers on WordPress.
Support Board Cloud
support-board-cloud
A Free one-click-to-install Live Chat plugin. No coding skills required. Used by more than 2000 customers on WordPress.
SaleSmartly – Live Chat & Chat Bot Integrate
salesmartly-chat
Smart Sales Human service for your customers
Kimiyi AI – AI Chatbot with Digital Human, ChatGPT
kimiyiai-chatbot
Enhance your WordPress site with Free ChatGPT AI Chatbot. Easily create lifelike digital humans to Answer Questions with Voice, Provide 24/7 Support, …
MsgSmartly By Digidopt
msgsmartly-by-digidopt
A Free one-click-to-install Live Chat plugin. No coding skills required. Used by more than 2000 customers on WordPress.
Tidio – Live Chat & AI Chatbots Developer Profile
1 plugin · 80K total installs
How We Detect Tidio – Live Chat & AI Chatbots
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tidio-live-chat/css/top-bar.css/wp-content/plugins/tidio-live-chat/css/system-info.css/wp-content/plugins/tidio-live-chat/js/system-info.js//code.tidio.co//wp-content/plugins/tidio-live-chat/vendor/TidioLiveChat/dist/widget.jstidio-live-chat/style.css?ver=tidio-live-chat/script.js?ver=HTML / DOM Fingerprints
tidio-chat-widget<!-- Tidio Chat -->data-tidio-chat-codetidioChatCode