
WordLive | Livecall Addon for Woocommerce Security & Risk Analysis
wordpress.org/plugins/wordlive-livecall-addon-for-woocommerceWordLive plugin enables a customizable button on both Shop Page and Product page for a Live Video call between the buyer and seller.
Is WordLive | Livecall Addon for Woocommerce Safe to Use in 2026?
Generally Safe
Score 85/100WordLive | Livecall Addon for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wordlive-livecall-addon-for-woocommerce" plugin v1.2.1 exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are positive indicators. The plugin correctly utilizes prepared statements for all SQL queries and implements a significant number of nonce and capability checks, suggesting an awareness of common WordPress security practices. However, a notable concern arises from the taint analysis, where four out of five analyzed flows have unsanitized paths. While no critical or high severity issues were flagged by the taint analysis itself, this indicates potential weaknesses in how user-supplied data is handled, which could be exploited if combined with other vulnerabilities or specific attack vectors.
Furthermore, the output escaping is only properly implemented in 51% of cases, which is a significant weakness. This leaves a substantial portion of plugin outputs potentially vulnerable to Cross-Site Scripting (XSS) attacks. The plugin also performs file operations and external HTTP requests, which, while not inherently insecure, require careful implementation to avoid vulnerabilities. The presence of the Freemius v1.0 bundled library is also a point of attention, as outdated bundled libraries can introduce known security flaws if not managed and updated by the plugin developer.
In conclusion, while the plugin avoids common pitfalls like raw SQL or unprotected entry points, the high number of unsanitized taint flows and the low percentage of proper output escaping are serious concerns that significantly elevate the risk. The lack of historical vulnerabilities is encouraging, but the static analysis highlights areas that require immediate attention to improve the plugin's overall security. The developer should prioritize sanitizing input paths in taint flows and improving output escaping mechanisms.
Key Concerns
- Unsanitized paths in taint flows
- Low percentage of proper output escaping
- Bundled outdated library (Freemius v1.0)
WordLive | Livecall Addon for Woocommerce Security Vulnerabilities
WordLive | Livecall Addon for Woocommerce Release Timeline
WordLive | Livecall Addon for Woocommerce Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WordLive | Livecall Addon for Woocommerce Attack Surface
Shortcodes 2
WordPress Hooks 40
Maintenance & Trust
WordLive | Livecall Addon for Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
WordLive | Livecall Addon for Woocommerce Alternatives
Advanced Product Fields (Product Addons) for WooCommerce
advanced-product-fields-for-woocommerce
Add options (addons) to your WooCommerce products so your customers can personalize their products. Product forms for everyone!
Product Addons for Woocommerce – Product Options with Custom Fields
woo-custom-product-addons
WooCommerce Product Addons Add custom fields to your WooCommerce product page. With an easy-to-use Custom Form Builder.
PPOM – Product Addons & Custom Fields for WooCommerce
woocommerce-product-addon
Easily add a range of custom fields to WooCommerce products, from text boxes to date selectors, allowing customers to personalize their orders.
StoreCustomizer – A plugin to Customize all WooCommerce Pages
woocustomizer
A store editor plugin for editing all WooCommerce store and product pages, cart, checkout and user account pages, all within the WordPress Customizer
YITH WooCommerce Product Add-Ons
yith-woocommerce-product-add-ons
Increase average order value by letting your customers purchase additional options on your products.
WordLive | Livecall Addon for Woocommerce Developer Profile
9 plugins · 350 total installs
How We Detect WordLive | Livecall Addon for Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wordlive-livecall-addon-for-woocommerce/includes/freemius/freemius-sdk/js/freemius-checkout.js/wp-content/plugins/wordlive-livecall-addon-for-woocommerce/includes/freemius/freemius-sdk/css/freemius-checkout.css/wp-content/plugins/wordlive-livecall-addon-for-woocommerce/admin/js/wordlive_admin.jswordlive-livecall-addon-for-woocommerce/includes/freemius/freemius-sdk/js/freemius-checkout.js?ver=wordlive-livecall-addon-for-woocommerce/includes/freemius/freemius-sdk/css/freemius-checkout.css?ver=wordlive-livecall-addon-for-woocommerce/admin/js/wordlive_admin.js?ver=HTML / DOM Fingerprints
dokan-form-groupgregcustomwatchlive_fromwatchlive_toWORDLIVE_PLUGINLINKWORDLIVE_PLUGINPATHWORDLIVE_PLUGINNAMEWORDLIVE_PLUGIN_PREFIX