
Tiviclick Video Chat for WordPress Security & Risk Analysis
wordpress.org/plugins/tiviclick-live-video-chatWelcome to Tiviclick Video Chats for WordPress websites.
Is Tiviclick Video Chat for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Tiviclick Video Chat for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of tiviclick-live-video-chat v2.2.1 indicates a generally good security posture. The plugin demonstrates a complete absence of identified attack surface points such as AJAX handlers, REST API routes, shortcodes, and cron events that are unprotected by authentication or permission checks. Furthermore, the code signals show no dangerous functions, file operations, or external HTTP requests, and all SQL queries are properly prepared. The taint analysis also reported zero flows with unsanitized paths, suggesting that data is handled with care within the analyzed code segments.
However, there are areas that warrant attention. The output escaping is only properly implemented for 57% of detected outputs, which could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not consistently sanitized before being displayed. The complete lack of nonce checks and capability checks, while seemingly benign due to the absence of attack surface, indicates a potential weakness. If any entry points were to be discovered or added in future versions, these crucial security mechanisms would be missing, leaving them unprotected.
The plugin's vulnerability history is exceptionally clean, with zero recorded CVEs. This, combined with the lack of critical or high-severity findings in the static analysis, suggests a well-maintained and secure codebase to date. Despite the minor concern regarding output escaping and the absence of authorization checks, the overall security is strong due to the minimal attack surface and diligent SQL handling. Users should be aware of the potential for XSS if the plugin evolves to include user-facing output that is not consistently escaped.
Key Concerns
- Output escaping not consistently applied
- No nonce checks implemented
- No capability checks implemented
Tiviclick Video Chat for WordPress Security Vulnerabilities
Tiviclick Video Chat for WordPress Release Timeline
Tiviclick Video Chat for WordPress Code Analysis
Output Escaping
Tiviclick Video Chat for WordPress Attack Surface
WordPress Hooks 2
Maintenance & Trust
Tiviclick Video Chat for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Tiviclick Video Chat for WordPress Alternatives
Vidtok Live Video Chat using WebRTC
vidtok-live-video-chat-using-webrtc
Integrate live video chat using WebRTC on your WordPress site in a few simple steps with Vidtok!
Connect-EZ Click-To-Call
connect-ez-click-to-call
Make phone calls directly from your website!
LiveSmart Video Chat Live Video Chat
new-dev-livesmart-video-chat
LiveSmart Video Chat Live Video chat plugin for WordPress that allows visitors to establish live video chat in the browser without download.
WP-WebRTC2
wp-webrtc2
Free video chat for registered site users.
AgilityFeat's Click To Call
agilityfeats-click-to-call
This plugin adds the functionality of video chat between users of your blog by using Tokbox (Experimental).
Tiviclick Video Chat for WordPress Developer Profile
1 plugin · 10 total installs
How We Detect Tiviclick Video Chat for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tiviclick-live-video-chat/tiviclick.css/wp-content/plugins/tiviclick-live-video-chat/tiviclick.js//www.tiviclick.com/plugin/js/tiviclick-live-video-chat/tiviclick.css?ver=tiviclick-live-video-chat/tiviclick.js?ver=HTML / DOM Fingerprints
tiviclick_admin_newtiviclick_new_containerid="tiviclick_external"window.tiviclick_account_idwindow.tiviclick_use_lang<div id="tiviclick_external" class="