
Lime Connect (formerly Userlike) – WordPress Live Chat plugin Security & Risk Analysis
wordpress.org/plugins/userlikeFree live chat plugin to chat with the visitors of your website. Integrate a beautiful and fully customizable chat box. Hosted in Europe.
Is Lime Connect (formerly Userlike) – WordPress Live Chat plugin Safe to Use in 2026?
Generally Safe
Score 100/100Lime Connect (formerly Userlike) – WordPress Live Chat plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The Userlike plugin v2.5 exhibits a generally good security posture due to the absence of known critical or high vulnerabilities and a lack of dangerous functions or raw SQL queries. The attack surface appears minimal, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. This suggests a deliberate effort to limit potential entry points for attackers. However, a notable concern arises from the output escaping analysis, where only 33% of outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, especially considering the plugin's history of an XSS CVE in March 2023. While this specific CVE is reported as patched, the pattern of XSS vulnerabilities should be a focus for ongoing security efforts. The presence of one medium-severity vulnerability in its history, though currently patched, combined with the limited output escaping, warrants a cautious approach.
Key Concerns
- Medium vulnerability in history (33% output escaping)
Lime Connect (formerly Userlike) – WordPress Live Chat plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Userlike <= 2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Lime Connect (formerly Userlike) – WordPress Live Chat plugin Code Analysis
Output Escaping
Lime Connect (formerly Userlike) – WordPress Live Chat plugin Attack Surface
WordPress Hooks 6
Maintenance & Trust
Lime Connect (formerly Userlike) – WordPress Live Chat plugin Maintenance & Trust
Maintenance Signals
Community Trust
Lime Connect (formerly Userlike) – WordPress Live Chat plugin Alternatives
Paldesk – Live Chat & Helpdesk
paldesk-live-chat-helpdesk
Powerful live chat & helpdesk plugin made for your WordPress website. Convert leads to sales & help customers in real time - it's free!
SiteGlue
siteglue
Convert visitors into customers. Make it easy for mobile visitors to ask a question, get a quote or schedule an appointment via text message.
Voizee
voizee
Voizee is a powerful communications suite application that offers callbacks, live chat, SMS, and email capabilities, all in one integrated solution.
Cnvrse
cnvrse
Add live chat to WordPress in seconds. Reply from your dashboard or Telegram. No external accounts, no monthly fees, 100% privacy-focused.
GTChatPro Live Chat Plugin
gtchatpro
Convert Your Leads To Customers Seamlessly
Lime Connect (formerly Userlike) – WordPress Live Chat plugin Developer Profile
1 plugin · 1K total installs
How We Detect Lime Connect (formerly Userlike) – WordPress Live Chat plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/userlike/userlike.pnghttps://s3-eu-west-1.amazonaws.com/userlike-cdn-widgets/https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com/HTML / DOM Fingerprints
userlikeuserlike_secretuserlikeStartChat