White Label voice assistant for ElevenLabs AI Agents Security & Risk Analysis

wordpress.org/plugins/white-label-chat-widget-for-elevenlabs-ai-agents

White-label chat widget that connects to ElevenLabs Agents. Clean UI, no API key exposure in the front end.

50 active installs v6.0.45 PHP 7.0+ WP 5.0+ Updated Oct 21, 2025
ai-agentchat-widgeteleven-labselevenlabswhite-label
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is White Label voice assistant for ElevenLabs AI Agents Safe to Use in 2026?

Generally Safe

Score 100/100

White Label voice assistant for ElevenLabs AI Agents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The plugin "white-label-chat-widget-for-elevenlabs-ai-agents" v6.0.45 exhibits a generally strong security posture based on the provided static analysis. The plugin has a small attack surface with no unprotected entry points found. Crucially, all SQL queries are using prepared statements, and a high percentage of output is properly escaped, indicating good development practices to prevent common vulnerabilities like SQL injection and XSS.

No critical or high severity issues were identified in the taint analysis, and the plugin has no recorded vulnerability history, suggesting a well-maintained and secure codebase. The presence of a nonce check and capability checks (even if only one is explicitly mentioned) are positive indicators. However, the lack of explicit capability checks on all entry points and the presence of a file operation and external HTTP request, while not inherently problematic, warrant careful consideration and review in a real-world scenario to ensure these operations are strictly necessary and properly secured.

In conclusion, this plugin appears to be quite secure, with strong adherence to secure coding principles and a clean vulnerability history. The primary areas for potential, albeit minor, concern would be a thorough review of the file operations and external HTTP requests to confirm they are not exploitable, and potentially adding more robust capability checks if the functionality requires it.

Key Concerns

  • Missing capability checks on entry points
  • Presence of file operations
  • Presence of external HTTP requests
Vulnerabilities
None known

White Label voice assistant for ElevenLabs AI Agents Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

White Label voice assistant for ElevenLabs AI Agents Release Timeline

v6.0.45Current
v6.0.44
v6.0.43
v6.0.42
v6.0.41
Code Analysis
Analyzed Mar 16, 2026

White Label voice assistant for ElevenLabs AI Agents Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
29 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

85% escaped34 total outputs
Attack Surface

White Label voice assistant for ElevenLabs AI Agents Attack Surface

Entry Points2
Unprotected0

REST API Routes 1

POST/wp-json/elcw/v1/get-signed-urlwhite-label-chat-widget-for-elevenlabs-ai-agents.php:325

Shortcodes 1

[elevenlabs_chat_widget] white-label-chat-widget-for-elevenlabs-ai-agents.php:303
WordPress Hooks 7
actionadmin_initadmin\settings-page.php:64
actionadmin_menuadmin\settings-page.php:198
filterpre_update_option_elcw_settingswhite-label-chat-widget-for-elevenlabs-ai-agents.php:68
actionwp_enqueue_scriptswhite-label-chat-widget-for-elevenlabs-ai-agents.php:146
actionwp_footerwhite-label-chat-widget-for-elevenlabs-ai-agents.php:254
actioninitwhite-label-chat-widget-for-elevenlabs-ai-agents.php:308
actionrest_api_initwhite-label-chat-widget-for-elevenlabs-ai-agents.php:324
Maintenance & Trust

White Label voice assistant for ElevenLabs AI Agents Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 21, 2025
PHP min version7.0
Downloads656

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

White Label voice assistant for ElevenLabs AI Agents Developer Profile

littleplugins

1 plugin · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect White Label voice assistant for ElevenLabs AI Agents

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/white-label-chat-widget-for-elevenlabs-ai-agents/public/css/chat-widget.css/wp-content/plugins/white-label-chat-widget-for-elevenlabs-ai-agents/public/js/main.js/wp-content/plugins/white-label-chat-widget-for-elevenlabs-ai-agents/public/js/orb.js/wp-content/plugins/white-label-chat-widget-for-elevenlabs-ai-agents/assets/vendor/fontawesome/css/all.min.css
Script Paths
/wp-content/plugins/white-label-chat-widget-for-elevenlabs-ai-agents/public/js/main.js/wp-content/plugins/white-label-chat-widget-for-elevenlabs-ai-agents/public/js/orb.js
Version Parameters
white-label-chat-widget-for-elevenlabs-ai-agents/public/css/chat-widget.css?ver=white-label-chat-widget-for-elevenlabs-ai-agents/public/js/main.js?ver=white-label-chat-widget-for-elevenlabs-ai-agents/public/js/orb.js?ver=

HTML / DOM Fingerprints

CSS Classes
elcw-widget-containerelcw-launcher-boxelcw-chat-panel
HTML Comments
<!-- 2 ▸ abort if API creds missing --><!-- 4 ▸ Font Awesome (local, no CDN) --><!-- 5 ▸ Widget CSS / JS --><!-- Settings-driven UI variables (now via wp_add_inline_style) -->+4 more
Data Attributes
data-elcw-agent-iddata-elcw-orb-imagedata-elcw-orb-basedata-elcw-text-onlydata-elcw-launcher-boxdata-elcw-voice-color+1 more
JS Globals
elcw_varselcw_rest
REST Endpoints
/elcw/v1/get-signed-url
FAQ

Frequently Asked Questions about White Label voice assistant for ElevenLabs AI Agents