Lime Connect (formerly Userlike) – WordPress Live Chat plugin Security & Risk Analysis

wordpress.org/plugins/userlike

Free live chat plugin to chat with the visitors of your website. Integrate a beautiful and fully customizable chat box. Hosted in Europe.

1K active installs v2.5 PHP + WP 3.3+ Updated Feb 4, 2026
ai-agentsai-chatbotsai-supportlive-chatmessaging
100
A · Safe
CVEs total1
Unpatched0
Last CVEMar 21, 2023
Safety Verdict

Is Lime Connect (formerly Userlike) – WordPress Live Chat plugin Safe to Use in 2026?

Generally Safe

Score 100/100

Lime Connect (formerly Userlike) – WordPress Live Chat plugin has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 21, 2023Updated 1mo ago
Risk Assessment

The Userlike plugin v2.5 exhibits a generally good security posture due to the absence of known critical or high vulnerabilities and a lack of dangerous functions or raw SQL queries. The attack surface appears minimal, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication. This suggests a deliberate effort to limit potential entry points for attackers. However, a notable concern arises from the output escaping analysis, where only 33% of outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, especially considering the plugin's history of an XSS CVE in March 2023. While this specific CVE is reported as patched, the pattern of XSS vulnerabilities should be a focus for ongoing security efforts. The presence of one medium-severity vulnerability in its history, though currently patched, combined with the limited output escaping, warrants a cautious approach.

Key Concerns

  • Medium vulnerability in history (33% output escaping)
Vulnerabilities
1

Lime Connect (formerly Userlike) – WordPress Live Chat plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-23734medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Userlike <= 2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Mar 21, 2023 Patched in 2.3 (308d)
Code Analysis
Analyzed Mar 16, 2026

Lime Connect (formerly Userlike) – WordPress Live Chat plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped6 total outputs
Attack Surface

Lime Connect (formerly Userlike) – WordPress Live Chat plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuuserlike.php:39
filterplugin_action_linksuserlike.php:40
actionwp_footeruserlike.php:44
actionadmin_noticesuserlike.php:46
actionadmin_inituserlike.php:63
actioninituserlike.php:93
Maintenance & Trust

Lime Connect (formerly Userlike) – WordPress Live Chat plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 4, 2026
PHP min version
Downloads38K

Community Trust

Rating80/100
Number of ratings4
Active installs1K
Developer Profile

Lime Connect (formerly Userlike) – WordPress Live Chat plugin Developer Profile

Lime Connect

1 plugin · 1K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
308 days
View full developer profile
Detection Fingerprints

How We Detect Lime Connect (formerly Userlike) – WordPress Live Chat plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/userlike/userlike.png
Script Paths
https://s3-eu-west-1.amazonaws.com/userlike-cdn-widgets/https://userlike-cdn-widgets.s3-eu-west-1.amazonaws.com/

HTML / DOM Fingerprints

CSS Classes
userlike
Data Attributes
userlike_secret
JS Globals
userlikeStartChat
FAQ

Frequently Asked Questions about Lime Connect (formerly Userlike) – WordPress Live Chat plugin