
WP Mibew Security & Risk Analysis
wordpress.org/plugins/wp-mibewWP Mibew generates the javascript chat snippet for the mibew.org open source chat software
Is WP Mibew Safe to Use in 2026?
Generally Safe
Score 85/100WP Mibew has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-mibew plugin version 1.0.1 exhibits a mixed security posture. On the positive side, it shows no known historical vulnerabilities (CVEs), and its SQL queries are all properly handled with prepared statements. The attack surface also appears to be zero in terms of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events, which is a strong indicator of good design practice against common web vulnerabilities. Furthermore, there are no identified taint flows, suggesting that data flowing through the plugin is not being mishandled in critical ways.
However, the static analysis reveals several significant concerns. The presence of the 'create_function' and 'unserialize' dangerous functions is a red flag, as these can be exploited for code execution and object injection vulnerabilities if not handled with extreme caution and strict input validation. The very low percentage of properly escaped output (4%) is a major weakness, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the site.
While the plugin has no recorded vulnerabilities, this could be due to a lack of thorough security auditing or its relatively niche nature. The combination of dangerous functions and widespread unescaped output, despite a limited direct attack surface, presents a notable risk. Future development should prioritize addressing the unescaped output and carefully sanitizing any data processed by 'create_function' and 'unserialize'.
Key Concerns
- Presence of 'unserialize' dangerous function
- Presence of 'create_function' dangerous function
- Low percentage of properly escaped output (4%)
- No nonce checks detected
WP Mibew Security Vulnerabilities
WP Mibew Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
WP Mibew Attack Surface
WordPress Hooks 15
Maintenance & Trust
WP Mibew Maintenance & Trust
Maintenance Signals
Community Trust
WP Mibew Alternatives
VISITLEAD Live Chat and Realtime Monitoring
visitlead
Enterprise Live Chat and realtime monitoring for business websites. We convert your visitors to clients. Live Chat is only one piece of our success.
WP User Chat
wp-user-chat
These plugins gives you many to many interaction through chat like social media`s. Additionaly, you can share your feelings with every logged-in users …
Smartsupp – live chat, AI shopping assistant and chatbots
smartsupp-live-chat
Boost your sales and turn visitors into customers with live chat, AI tools and chatbots. Smartsupp is trusted by 100,000+ online stores.
Goftino
goftino
Goftino widget for wordpress users.
Live Chat & AI Chatbots – onWebChat
onwebchat
Enhance customer service with instant 24/7 AI-powered replies. Now with WooCommerce integration, so your chatbot understands your products and helps c …
WP Mibew Developer Profile
26 plugins · 12K total installs
How We Detect WP Mibew
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-mibew/css/main.css/wp-content/plugins/wp-mibew/js/webweb_wp_mibew.js/wp-content/plugins/wp-mibew/js/webweb_wp_mibew_admin.js/wp-content/plugins/wp-mibew/js/tinymce/editor_plugin.js/wp-content/plugins/wp-mibew/js/webweb_wp_mibew.js/wp-content/plugins/wp-mibew/js/webweb_wp_mibew_admin.js/wp-content/plugins/wp-mibew/js/tinymce/editor_plugin.js/wp-content/plugins/wp-mibew/css/main.css?ver=/wp-content/plugins/wp-mibew/js/webweb_wp_mibew.js?ver=/wp-content/plugins/wp-mibew/js/webweb_wp_mibew_admin.js?ver=/wp-content/plugins/wp-mibew/js/tinymce/editor_plugin.js?ver=HTML / DOM Fingerprints
webweb_wp_mibew_admin_page<!-- Snippet generated by WP Mibew | orbisius.com --><!-- /WP Mibew | orbisius.com --><!-- WP Mibew is not enabled. Please check the settings at [ admin.php?page=/webweb_wp_mibew/menu.settings.php ] --><!-- using global defaults -->data-plugin-name="WP Mibew"data-plugin-id="wp_mibew"webweb_wp_mibew_objwebweb_wp_mibew_common_objWebWeb_WP_MibewWebWeb_WP_MibewWidgetWebWeb_WP_MibewBaseWebWeb_WP_MibewUtil[wp-mibew]