WordLive | Livecall Addon for Woocommerce Security & Risk Analysis

wordpress.org/plugins/wordlive-livecall-addon-for-woocommerce

WordLive plugin enables a customizable button on both Shop Page and Product page for a Live Video call between the buyer and seller.

0 active installs v1.2.1 PHP 5.6+ WP 3.9+ Updated Nov 28, 2022
woocommercewoocommerce-addonwoocommerce-live-chatwoocommerce-product-live-chatwoocommerce-product-options
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WordLive | Livecall Addon for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

WordLive | Livecall Addon for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "wordlive-livecall-addon-for-woocommerce" plugin v1.2.1 exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are positive indicators. The plugin correctly utilizes prepared statements for all SQL queries and implements a significant number of nonce and capability checks, suggesting an awareness of common WordPress security practices. However, a notable concern arises from the taint analysis, where four out of five analyzed flows have unsanitized paths. While no critical or high severity issues were flagged by the taint analysis itself, this indicates potential weaknesses in how user-supplied data is handled, which could be exploited if combined with other vulnerabilities or specific attack vectors.

Furthermore, the output escaping is only properly implemented in 51% of cases, which is a significant weakness. This leaves a substantial portion of plugin outputs potentially vulnerable to Cross-Site Scripting (XSS) attacks. The plugin also performs file operations and external HTTP requests, which, while not inherently insecure, require careful implementation to avoid vulnerabilities. The presence of the Freemius v1.0 bundled library is also a point of attention, as outdated bundled libraries can introduce known security flaws if not managed and updated by the plugin developer.

In conclusion, while the plugin avoids common pitfalls like raw SQL or unprotected entry points, the high number of unsanitized taint flows and the low percentage of proper output escaping are serious concerns that significantly elevate the risk. The lack of historical vulnerabilities is encouraging, but the static analysis highlights areas that require immediate attention to improve the plugin's overall security. The developer should prioritize sanitizing input paths in taint flows and improving output escaping mechanisms.

Key Concerns

  • Unsanitized paths in taint flows
  • Low percentage of proper output escaping
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
None known

WordLive | Livecall Addon for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WordLive | Livecall Addon for Woocommerce Release Timeline

v1.2.1Current
v1.2.0
v1.1.9
v1.1.8
v1.1.7
v1.1.6
v1.1.5
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
Code Analysis
Analyzed Apr 16, 2026

WordLive | Livecall Addon for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
5 prepared
Unescaped Output
504
529 escaped
Nonce Checks
6
Capability Checks
3
File Operations
1
External Requests
3
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared5 total queries

Output Escaping

51% escaped1033 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

5 flows4 with unsanitized paths
install_plugin_information (includes/includes/fs-plugin-info-dialog.php:928)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WordLive | Livecall Addon for Woocommerce Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[watchlive] admin/register.php:7
[videocall] admin/register.php:26
WordPress Hooks 40
filterdokan_query_var_filteradmin/functions.php:10
filterdokan_get_dashboard_navadmin/functions.php:16
filterdokan_settings_form_bottomadmin/functions.php:38
actiondokan_store_profile_savedadmin/functions.php:65
actiondokan_store_header_info_fieldsadmin/functions.php:80
actioninitadmin/functions.php:104
actionwp_enqueue_scriptsadmin/functions.php:212
filterpage_templateadmin/functions.php:352
actionwp_footeradmin/functions.php:451
actionadmin_menuadmin/settings.php:460
actionadmin_enqueue_scriptsadmin/settings.php:461
actionwp_enqueue_scriptsadmin/settings.php:598
actionadmin_footerincludes/includes/class-fs-logger.php:108
actionwp_footerincludes/includes/class-fs-logger.php:110
filterplugins_apiincludes/includes/class-fs-plugin-updater.php:83
actionadmin_headincludes/includes/class-fs-plugin-updater.php:106
filterhttp_request_host_is_externalincludes/includes/class-fs-plugin-updater.php:110
filterupgrader_post_installincludes/includes/class-fs-plugin-updater.php:118
filterupgrader_pre_installincludes/includes/class-fs-plugin-updater.php:121
filterupgrader_source_selectionincludes/includes/class-fs-plugin-updater.php:122
filterwp_prepare_themes_for_jsincludes/includes/class-fs-plugin-updater.php:125
actionadmin_footerincludes/includes/class-fs-plugin-updater.php:142
filterpre_set_site_transient_update_pluginsincludes/includes/class-fs-plugin-updater.php:253
filterpre_set_site_transient_update_themesincludes/includes/class-fs-plugin-updater.php:258
filterupgrader_source_selectionincludes/includes/class-fs-plugin-updater.php:1344
filterdebug_bar_panelsincludes/includes/debug/debug-bar-start.php:51
filterdebug_bar_statusesincludes/includes/debug/debug-bar-start.php:52
actioninstall_plugins_pre_plugin-informationincludes/includes/fs-plugin-info-dialog.php:66
filterfs_plugins_apiincludes/includes/fs-plugin-info-dialog.php:69
actionadmin_footerincludes/includes/managers/class-fs-admin-notice-manager.php:211
actionnetwork_admin_noticesincludes/includes/managers/class-fs-admin-notice-manager.php:390
actionadmin_noticesincludes/includes/managers/class-fs-admin-notice-manager.php:391
actionadmin_enqueue_scriptsincludes/includes/managers/class-fs-admin-notice-manager.php:394
actionadmin_post_fs_clone_resolutionincludes/includes/managers/class-fs-clone-manager.php:145
actionadmin_footerincludes/includes/managers/class-fs-clone-manager.php:163
actionhttp_api_curlincludes/includes/sdk/FreemiusWordPress.php:444
actionadmin_footerincludes/templates/account.php:93
filterconnect_message_on_updatewordlive.php:69
filterconnect_messagewordlive.php:92
actionactivated_pluginwordlive.php:132
Maintenance & Trust

WordLive | Livecall Addon for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 28, 2022
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

WordLive | Livecall Addon for Woocommerce Developer Profile

Rajin Sharwar

9 plugins · 350 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WordLive | Livecall Addon for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wordlive-livecall-addon-for-woocommerce/includes/freemius/freemius-sdk/js/freemius-checkout.js/wp-content/plugins/wordlive-livecall-addon-for-woocommerce/includes/freemius/freemius-sdk/css/freemius-checkout.css
Script Paths
/wp-content/plugins/wordlive-livecall-addon-for-woocommerce/admin/js/wordlive_admin.js
Version Parameters
wordlive-livecall-addon-for-woocommerce/includes/freemius/freemius-sdk/js/freemius-checkout.js?ver=wordlive-livecall-addon-for-woocommerce/includes/freemius/freemius-sdk/css/freemius-checkout.css?ver=wordlive-livecall-addon-for-woocommerce/admin/js/wordlive_admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
dokan-form-groupgregcustom
Data Attributes
watchlive_fromwatchlive_to
JS Globals
WORDLIVE_PLUGINLINKWORDLIVE_PLUGINPATHWORDLIVE_PLUGINNAMEWORDLIVE_PLUGIN_PREFIX
FAQ

Frequently Asked Questions about WordLive | Livecall Addon for Woocommerce