AI Live Chat Security & Risk Analysis

wordpress.org/plugins/wp-iclew

Provide live technical assistance to users, give them reasons to buy your product! The Agent scans your website to learn relevant answers to user ques …

10 active installs v1.4.3 PHP 5.4+ WP 4.6+ Updated Dec 1, 2017
chatbothelp-desklive-chatsales-chatbotsupport
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AI Live Chat Safe to Use in 2026?

Generally Safe

Score 85/100

AI Live Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "wp-iclew" v1.4.3 plugin presents a generally good security posture based on the provided static analysis. The absence of any recorded vulnerabilities, critical taint flows, dangerous functions, raw SQL queries, file operations, or external HTTP requests is a strong positive indicator. Furthermore, the presence of a capability check and the absence of a large attack surface without authentication are commendable security practices. The plugin also adheres to good output escaping standards, with 70% of outputs being properly handled. However, a significant concern is the complete absence of nonce checks, which is a critical component for preventing Cross-Site Request Forgery (CSRF) attacks, especially in plugins with interactive elements like shortcodes. The lack of any identified taint flows or unsanitized paths is positive, but this could also be a reflection of the limited scope of the analysis or a simple absence of such complex flows in the code.

Key Concerns

  • Missing nonce checks for entry points
  • Some outputs not properly escaped
Vulnerabilities
None known

AI Live Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AI Live Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
16 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

70% escaped23 total outputs
Attack Surface

AI Live Chat Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[run_acobot] wp-acobot.php:57
WordPress Hooks 5
actionadmin_initwp-acobot.php:51
actionadmin_menuwp-acobot.php:52
actionplugins_loadedwp-acobot.php:53
actionadmin_enqueue_scriptswp-acobot.php:54
actionwp_enqueue_scriptswp-acobot.php:58
Maintenance & Trust

AI Live Chat Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedDec 1, 2017
PHP min version5.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

AI Live Chat Developer Profile

scottvavoom

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AI Live Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-acobot/js/w
Script Paths
https://acobot.ai/js/w

HTML / DOM Fingerprints

CSS Classes
aco_question
HTML Comments
<!--<p>Your language code is --><!--<script src="https://acobot.ai/js/w"></script>-->+2 more
Data Attributes
name="wp_acobot_key"name="wp_acobot_enb"name="wp_acobot_show_on_all"name="wp_acobot_color"name="wp_acobot_img"value="1"+3 more
JS Globals
window.acobot
Shortcode Output
[run_acobot/]
FAQ

Frequently Asked Questions about AI Live Chat