ZebChat – Live Support Chat Security & Risk Analysis

wordpress.org/plugins/zebchat-live-chat

ZebChat plugin for Wordpress adds a professional and easy to use live support chat.

0 active installs v1.0.1 PHP + WP 2.7+ Updated Apr 2, 2019
customer-supporthelpdesklive-chatlive-chat-for-websitezebchat
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ZebChat – Live Support Chat Safe to Use in 2026?

Generally Safe

Score 85/100

ZebChat – Live Support Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "zebchat-live-chat" v1.0.1 plugin exhibits a generally good security posture with a small attack surface and no known vulnerabilities. The code analysis shows a positive sign with 100% of SQL queries using prepared statements, indicating protection against SQL injection. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. However, a concerning aspect is the low percentage of properly escaped output (29%), which suggests a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered without adequate sanitization.

The taint analysis revealed two flows with unsanitized paths. While these are not classified as critical or high severity, they still represent potential weaknesses where malicious input could lead to unexpected behavior or execution. The lack of explicit nonce checks on the single shortcode entry point is another area of concern, as it could potentially be exploited by attackers to trigger actions unintended by the user. The plugin's history of zero CVEs is a positive indicator of its current security, suggesting diligent development practices or a lack of significant historical exploits. In conclusion, while the plugin has a strong foundation with secure database interactions and no known exploits, the insufficient output escaping and potential for unsanitized path flows in the taint analysis warrant attention to prevent XSS and other injection-related vulnerabilities.

Key Concerns

  • Insufficient output escaping
  • Unsanitized paths in taint analysis
  • Missing nonce checks on entry points
Vulnerabilities
None known

ZebChat – Live Support Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ZebChat – Live Support Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
4 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped14 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
__construct (jakweblc.php:16)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ZebChat – Live Support Chat Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ZebChat] jakweblc.php:208
WordPress Hooks 10
actionadmin_initjakweblc.php:51
actionadmin_menujakweblc.php:52
actionadmin_enqueue_scriptsjakweblc.php:54
actionadmin_noticesjakweblc.php:76
actionadmin_noticesjakweblc.php:81
actionadmin_noticesjakweblc.php:121
actionadmin_noticesjakweblc.php:143
actionadmin_noticesjakweblc.php:144
actionwp_footerjakweblc.php:240
actionwp_footerjakweblc.php:380
Maintenance & Trust

ZebChat – Live Support Chat Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedApr 2, 2019
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ZebChat – Live Support Chat Developer Profile

zebchat

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ZebChat – Live Support Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zebchat-live-chat/assets/jakweb.admin.css/wp-content/plugins/zebchat-live-chat/assets/jakweb.admin.js

HTML / DOM Fingerprints

CSS Classes
jakweb_admin_stylejakweb_admin_script
Data Attributes
widgetid_formoptionsjakweblc-lc-optionsjakweblc-embed-widget-id
JS Globals
jakwebLC_SettingsJakwebLC
Shortcode Output
[ZebChat]
FAQ

Frequently Asked Questions about ZebChat – Live Support Chat