
3CX Free Live Chat, Calls & Messaging Security & Risk Analysis
wordpress.org/plugins/wp-live-chat-supportChat with your website visitors in real-time for free! Engage with your customers and increase sales.
Is 3CX Free Live Chat, Calls & Messaging Safe to Use in 2026?
Generally Safe
Score 94/1003CX Free Live Chat, Calls & Messaging has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-live-chat-support" plugin v10.0.17 exhibits a mixed security posture. While it shows positive signs like the absence of dangerous functions, 100% prepared SQL statements, and a history of no currently unpatched CVEs, significant concerns arise from its static analysis. The plugin has a small but concerning attack surface with 2 entry points, both of which are unprotected due to missing authentication or permission checks. This exposes critical functionalities to unauthorized access. Furthermore, a substantial percentage (59%) of its output escaping is not properly handled, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities.
Key Concerns
- Unprotected AJAX handler
- Unprotected REST API route
- Insufficient output escaping (59% proper)
- Large number of historical CVEs (15)
- Historical critical vulnerabilities (2)
- Historical high vulnerability (1)
3CX Free Live Chat, Calls & Messaging Security Vulnerabilities
CVEs by Year
Severity Breakdown
15 total CVEs
3CX Live Chat <= 9.4.2 - Local File Inclusion
WP Live Chat Support <= 8.1.9 - Stored Cross-Site Scripting
WP Live Chat Support <= 8.0.32 - Unprotected Functions
WP Live Chat Support <= 8.0.27 - Unauthenticated Stored Cross-Site Scripting
WP Live Chat Support <= 8.0.17 - Cross-Site Scripting
WP Live Chat Support <= 8.0.15 - Cross-Site Scripting
3CX Live Chat <= 8.0.07 - Cross-Site Scripting
WP Live Chat Support <= 8.0.05 - Stored Cross-Site Scripting
WP Live Chat Support <= 7.1.04 - Cross-Site Scripting
WP Live Chat Support <= 7.1.02 - Cross-Site Scripting
WP Live Chat Support <= 7.0.06 - Cross-Site Scripting
3CX Free Live Chat <= 6.2.03 - Unauthenticated Stored Cross-Site Scripting
WP Live Chat Support <= 4.3.5 - Blind SQL Injection
WP Live Chat Support <= 4.3.5 - Stored Cross-site Scripting
WP Live Chat Support < 4.1.0 - JavaScript Code Injection
3CX Free Live Chat, Calls & Messaging Code Analysis
Output Escaping
3CX Free Live Chat, Calls & Messaging Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 12
Maintenance & Trust
3CX Free Live Chat, Calls & Messaging Maintenance & Trust
Maintenance Signals
Community Trust
3CX Free Live Chat, Calls & Messaging Alternatives
KP Fastest Tidio Chat
kp-fastest-tidio-chat
Tidio Live Chat made fast and easy. Speed up your WordPress website and help customers via Tidio Live Chat on your website.
KP Fastest Chat
kp-fastest-chat
Live Chat made fast and easy. Speed up your WordPress website and help customers via Live Chat on your website. Supports all Chat Platforms.
WP Chatbull
wp-chatbull
Now chat with your website visitors with WP ChatBull. This is a perfect fit for Small Business for both who sell products and services.
JivoChat Live Chat – WP live chat plugin for WordPress
jivochat
Omnichannel Live Chat and Help Desk plugin, optimized for WordPress. Free, fast, easy to install and to use. Turn your visitors into happy customers!
LiveAgent – Omnichannel Help Desk & Live Chat Software
liveagent
LiveAgent is a multichannel help desk software that offers over 180 help desk and live chat features. Discover the power of the universal inbox, a hyb …
3CX Free Live Chat, Calls & Messaging Developer Profile
1 plugin · 100K total installs
How We Detect 3CX Free Live Chat, Calls & Messaging
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-live-chat-support/css/wplc-plugin-admin.css/wp-content/plugins/wp-live-chat-support/js/wplc-plugin-admin.js/wp-content/plugins/wp-live-chat-support/js/wplc-chat-main.js/wp-content/plugins/wp-live-chat-support/css/wplc-chat-main.css/wp-content/plugins/wp-live-chat-support/css/wplc-chat-responsive.css/wp-content/plugins/wp-live-chat-support/css/wplc-chat-custom.css/wp-content/plugins/wp-live-chat-support/js/wplc-chat-new-conversation.js/wp-content/plugins/wp-live-chat-support/js/wplc-chat-new-conversation-new.js/wp-content/plugins/wp-live-chat-support/js/wplc-plugin-admin.js/wp-content/plugins/wp-live-chat-support/js/wplc-chat-main.jswp-live-chat-support/css/wplc-plugin-admin.css?ver=wp-live-chat-support/js/wplc-plugin-admin.js?ver=wp-live-chat-support/js/wplc-chat-main.js?ver=wp-live-chat-support/css/wplc-chat-main.css?ver=wp-live-chat-support/css/wplc-chat-responsive.css?ver=wp-live-chat-support/css/wplc-chat-custom.css?ver=wp-live-chat-support/js/wplc-chat-new-conversation.js?ver=wp-live-chat-support/js/wplc-chat-new-conversation-new.js?ver=HTML / DOM Fingerprints
wplc_chat_box_outerwplc_chat_box_innerwplc_chat_headerwplc_chat_message_sent_by_agentwplc_chat_message_sent_by_userwplc_chat_input_fieldwplc_chat_send_buttonwplc_agent_typing+1 more<!-- 3CX Live Chat v10.0.17 --><!-- WPLC Chat Box --><!-- WPLC New Conversation Form --><!-- WPLC Agent Typing Indicator -->data-wplc-chat-iddata-wplc-agent-iddata-wplc-user-iddata-wplc-conversation-iddata-wplc-agent-typingdata-wplc-user-typing+1 morewplc_chat_settingswplc_chat_datawplc_chat_activewplc_chat_historywplc_chat_typing_indicator/wp-json/wp-live-chat-support/v1/autoconfigure