
ZebChat – Live Support Chat Security & Risk Analysis
wordpress.org/plugins/zebchat-live-chatZebChat plugin for Wordpress adds a professional and easy to use live support chat.
Is ZebChat – Live Support Chat Safe to Use in 2026?
Generally Safe
Score 85/100ZebChat – Live Support Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "zebchat-live-chat" v1.0.1 plugin exhibits a generally good security posture with a small attack surface and no known vulnerabilities. The code analysis shows a positive sign with 100% of SQL queries using prepared statements, indicating protection against SQL injection. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. However, a concerning aspect is the low percentage of properly escaped output (29%), which suggests a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered without adequate sanitization.
The taint analysis revealed two flows with unsanitized paths. While these are not classified as critical or high severity, they still represent potential weaknesses where malicious input could lead to unexpected behavior or execution. The lack of explicit nonce checks on the single shortcode entry point is another area of concern, as it could potentially be exploited by attackers to trigger actions unintended by the user. The plugin's history of zero CVEs is a positive indicator of its current security, suggesting diligent development practices or a lack of significant historical exploits. In conclusion, while the plugin has a strong foundation with secure database interactions and no known exploits, the insufficient output escaping and potential for unsanitized path flows in the taint analysis warrant attention to prevent XSS and other injection-related vulnerabilities.
Key Concerns
- Insufficient output escaping
- Unsanitized paths in taint analysis
- Missing nonce checks on entry points
ZebChat – Live Support Chat Security Vulnerabilities
ZebChat – Live Support Chat Code Analysis
Output Escaping
Data Flow Analysis
ZebChat – Live Support Chat Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
ZebChat – Live Support Chat Maintenance & Trust
Maintenance Signals
Community Trust
ZebChat – Live Support Chat Alternatives
EngageBay Live Chat Support
engagebay-livechat
Add real-time live chat support to your WordPress site with EngageBay. Connect instantly with visitors, boost engagement, and grow your business.
REVE Chat – AI Chatbot, Live Chat, Helpdesk, Campaigns & More
revechat
A free all-in-one customer service and lead generation platform capable of engaging, retaining, and converting customers.
Hive Support | AI-Powered Help Desk, Live Chat and Chatbot
hive-support
The All-In-One Help Desk, Live Chat & AI Chat Bot Plugin for WordPress.
Paldesk – Live Chat & Helpdesk
paldesk-live-chat-helpdesk
Powerful live chat & helpdesk plugin made for your WordPress website. Convert leads to sales & help customers in real time - it's free!
HelpLane Chat
helplane-chat
Add HelpLane live chat widget to your WordPress site with automatic user identification.
ZebChat – Live Support Chat Developer Profile
1 plugin · 0 total installs
How We Detect ZebChat – Live Support Chat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zebchat-live-chat/assets/jakweb.admin.css/wp-content/plugins/zebchat-live-chat/assets/jakweb.admin.jsHTML / DOM Fingerprints
jakweb_admin_stylejakweb_admin_scriptwidgetid_formoptionsjakweblc-lc-optionsjakweblc-embed-widget-idjakwebLC_SettingsJakwebLC[ZebChat]