Tidio – Live Chat & AI Chatbots Security & Risk Analysis

wordpress.org/plugins/tidio-live-chat

Add Tidio Live Chat to your WordPress for free to answer customers’ questions, engage website visitors, generate leads, and increase sales.

80K active installs v7.0.0 PHP 7.2+ WP 4.7+ Updated Feb 19, 2026
chatchatbotfree-live-chatlive-chatlivechat
99
A · Safe
CVEs total2
Unpatched0
Last CVESep 20, 2022
Safety Verdict

Is Tidio – Live Chat & AI Chatbots Safe to Use in 2026?

Generally Safe

Score 99/100

Tidio – Live Chat & AI Chatbots has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Sep 20, 2022Updated 1mo ago
Risk Assessment

The Tidio Live Chat plugin version 7.0.0 exhibits a mixed security posture. On the positive side, the static analysis reveals a lack of identified critical vulnerabilities within the code itself, with no dangerous functions, raw SQL queries, or unsanitized taint flows detected. The presence of nonce and capability checks, along with the use of prepared statements for SQL, are good security practices. However, the plugin's history of two known CVEs, one of which was high severity and the other medium, raises significant concern. The fact that these vulnerabilities were Exposure of Sensitive Information and Cross-Site Request Forgery suggests recurring or complex security flaws.

The primary weaknesses lie not in the current code's apparent lack of immediate threats, but in its past. The historical vulnerabilities, particularly the CSRF and sensitive information exposure, indicate that the plugin has previously been susceptible to attacks that could compromise user data or site integrity. While there are currently no unpatched vulnerabilities, the existence of these past issues warrants vigilance. The relatively low percentage of properly escaped output (44%) is also a minor concern, as it could lead to cross-site scripting (XSS) vulnerabilities if not handled carefully in all contexts.

Key Concerns

  • High severity vulnerability in history (unpatched in past)
  • Medium severity vulnerability in history (unpatched in past)
  • Low percentage of properly escaped output
Vulnerabilities
2

Tidio – Live Chat & AI Chatbots Security Vulnerabilities

CVEs by Year

1 CVE in 2019
2019
1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

WF-cbdb3be2-50c5-4516-bce1-8785e338fe5c-tidio-live-chatmedium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Tidio – Live Chat, Chatbots & Email Integration <= 5.2.0 - Sensitive Information Disclosure

Sep 20, 2022 Patched in 5.3.0 (490d)
WF-7886708a-8daa-465b-b820-53bf409e682c-tidio-live-chathigh · 8.8Cross-Site Request Forgery (CSRF)

Tidio Live Chat < 4.2.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Nov 5, 2019 Patched in 4.2.1 (1540d)
Code Analysis
Analyzed Mar 16, 2026

Tidio – Live Chat & AI Chatbots Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
4 escaped
Nonce Checks
1
Capability Checks
1
File Operations
5
External Requests
2
Bundled Libraries
0

Output Escaping

44% escaped9 total outputs
Attack Surface

Tidio – Live Chat & AI Chatbots Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
filterplugin_action_linkssrc\Admin\AdminActionLink.php:33
actionadmin_menusrc\Admin\AdminDashboard.php:40
actionadmin_menusrc\Admin\AdminDashboard.php:41
actionadmin_bar_menusrc\Admin\AdminDashboard.php:42
actionadmin_enqueue_scriptssrc\Admin\AdminDashboard.php:43
actionadmin_noticessrc\Admin\AdminNotice.php:38
actionadmin_noticessrc\Admin\AdminNotice.php:39
filterload_textdomain_mofilesrc\Translation\TranslationLoader.php:15
actionwp_headsrc\Widget\WidgetLoader.php:34
actionwp_footersrc\Widget\WidgetLoader.php:37
actionwp_enqueue_scriptssrc\Widget\WidgetLoader.php:41
actioninittidio-elements.php:35
actionactivated_plugintidio-elements.php:53
Maintenance & Trust

Tidio – Live Chat & AI Chatbots Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version7.2
Downloads3.4M

Community Trust

Rating94/100
Number of ratings395
Active installs80K
Developer Profile

Tidio – Live Chat & AI Chatbots Developer Profile

Tytus Gołas

1 plugin · 80K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
1015 days
View full developer profile
Detection Fingerprints

How We Detect Tidio – Live Chat & AI Chatbots

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tidio-live-chat/css/top-bar.css/wp-content/plugins/tidio-live-chat/css/system-info.css/wp-content/plugins/tidio-live-chat/js/system-info.js
Script Paths
//code.tidio.co//wp-content/plugins/tidio-live-chat/vendor/TidioLiveChat/dist/widget.js
Version Parameters
tidio-live-chat/style.css?ver=tidio-live-chat/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
tidio-chat-widget
HTML Comments
<!-- Tidio Chat -->
Data Attributes
data-tidio-chat-code
JS Globals
tidioChatCode
FAQ

Frequently Asked Questions about Tidio – Live Chat & AI Chatbots