UrLive Chat widget by UrLive Security & Risk Analysis

wordpress.org/plugins/urlive-call-widget

A plugin powered by urLive that allows people to instantly communicate with each other in the browser

0 active installs v1.0.0 PHP + WP 4.7+ Updated Unknown
audio-chatcommunicationim-chatvideo-chat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is UrLive Chat widget by UrLive Safe to Use in 2026?

Generally Safe

Score 100/100

UrLive Chat widget by UrLive has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "urlive-call-widget" plugin version 1.0.0 exhibits a surprisingly clean static analysis report, with no identified dangerous functions, SQL queries (all using prepared statements), file operations, or external HTTP requests. The attack surface is also reported as zero, indicating no exposed AJAX handlers, REST API routes, shortcodes, or cron events.

However, a significant concern arises from the output escaping analysis. With 100% of its three identified output points being unescaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Even with a clean vulnerability history and no reported CVEs, this lack of output sanitization is a critical oversight that could be easily exploited if the plugin handles any user-supplied or dynamic data.

In conclusion, while the plugin avoids many common pitfalls like raw SQL and a broad attack surface, the complete absence of output escaping is a major weakness. The lack of reported vulnerabilities in the past might be due to the limited scope of the plugin or simply a lack of historical reporting, rather than an inherent secure design in this specific area.

Key Concerns

  • Output is not properly escaped
Vulnerabilities
None known

UrLive Chat widget by UrLive Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

UrLive Chat widget by UrLive Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped3 total outputs
Attack Surface

UrLive Chat widget by UrLive Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initurll_widget.php:52
actionadmin_menuurll_widget.php:87
actionwp_footerurll_widget.php:251
Maintenance & Trust

UrLive Chat widget by UrLive Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

UrLive Chat widget by UrLive Developer Profile

urlive

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect UrLive Chat widget by UrLive

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/urlive-call-widget/URLL_widget/urll_style.css
Script Paths
/wp-content/plugins/urlive-call-widget/URLL_widget/jquery.min.js

HTML / DOM Fingerprints

CSS Classes
urll_bodyurl_input
HTML Comments
<!-- <script src="https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script> <link rel="stylesheet" href="https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/css/bootstrap.min.css" integrity="sha384-ggOyR0iXCbMQv3Xipma34MD+dH/1fQ784/j6cY/iJTQUOhcWr7x9JvoRxT2MZw1T" crossorigin="anonymous"> <link rel = "stylesheet" href="../wp-content/plugins/URLL_widget/urll_style.css"> -->
Data Attributes
id="widget-form2"id="restart"
JS Globals
window.openjQuery("#widget-form2").cssjQuery("#restart").cssjQuery("#widget-form1").css
FAQ

Frequently Asked Questions about UrLive Chat widget by UrLive