WG Live Chat Security & Risk Analysis

wordpress.org/plugins/wg-live-chat

Your customers deserve your attention. WG Live Chat plugin enables you to chat with the customers on your site. Add WG Live Chat to your website insta …

10 active installs v1.1.0 PHP + WP 4.5+ Updated Mar 19, 2022
live-chatlive-chat-for-businesseslive-chat-for-websitelive-chat-supportlive-chat-tool
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WG Live Chat Safe to Use in 2026?

Generally Safe

Score 85/100

WG Live Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "wg-live-chat" v1.1.0 plugin exhibits a strong security posture in several key areas. The static analysis reveals no identified attack surface through AJAX handlers, REST API routes, shortcodes, or cron events, indicating a well-contained plugin. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests, along with the use of prepared statements for all SQL queries, demonstrates a commitment to secure coding practices. The vulnerability history is also clean, with no known CVEs, which is a significant positive indicator.

However, a critical concern arises from the output escaping analysis. With 4 total outputs and 0% properly escaped, there is a high likelihood of cross-site scripting (XSS) vulnerabilities. Any data displayed to users that originates from or passes through the plugin without proper escaping could be exploited by attackers. The lack of nonce checks and capability checks on the identified entry points (though zero in this case) also represent potential oversights that could become a risk if new entry points are introduced in the future without proper security.

In conclusion, while the plugin is architecturally sound and free from known historical vulnerabilities, the complete lack of output escaping is a glaring weakness. This presents a significant risk of XSS attacks that must be addressed. The plugin's strengths lie in its minimal attack surface and secure data handling for SQL, but the unescaped output severely undermines its overall security.

Key Concerns

  • No output escaping
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

WG Live Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WG Live Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

WG Live Chat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuwg-live-chat.php:11
actionadmin_enqueue_scriptswg-live-chat.php:29
Maintenance & Trust

WG Live Chat Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMar 19, 2022
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WG Live Chat Developer Profile

liveadmins

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WG Live Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wg-live-chat/admin-area/js/la-my-script.js/wp-content/plugins/wg-live-chat/admin-area/css/plugin-basic.css
Script Paths
wp-content/plugins/wg-live-chat/admin-area/js/la-my-script.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WG Live Chat