Zoho SalesIQ – Live chat, chatbots, and visitor tracking Security & Risk Analysis

wordpress.org/plugins/zoho-salesiq

Identify, engage and convert website visitors with live chat and visitor analytics.

20K active installs v2.0.5 PHP + WP 2.8+ Updated Dec 5, 2025
chatbotlive-chatlivechatwordpress-live-chatzoho-salesiq
97
A · Safe
CVEs total4
Unpatched0
Last CVEMay 31, 2019
Safety Verdict

Is Zoho SalesIQ – Live chat, chatbots, and visitor tracking Safe to Use in 2026?

Generally Safe

Score 97/100

Zoho SalesIQ – Live chat, chatbots, and visitor tracking has a strong security track record. Known vulnerabilities have been patched promptly.

4 known CVEsLast CVE: May 31, 2019Updated 3mo ago
Risk Assessment

The static analysis of Zoho SalesIQ v2.0.5 reveals a generally strong security posture with no identified direct entry points into the application (AJAX handlers, REST API routes, shortcodes, cron events) that are unprotected. The code also demonstrates good practices regarding SQL queries, exclusively using prepared statements, and the vast majority of external requests are properly escaped. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is a positive sign. However, the presence of one nonce check and a complete lack of capability checks raise concerns about the potential for privilege escalation or unauthorized actions if an attacker can bypass the nonce or exploit a lack of authorization checks in other areas.

The plugin's vulnerability history, however, is a significant red flag. With four known CVEs, including three high-severity and one medium-severity vulnerability, this indicates a recurring pattern of security weaknesses. The common types of vulnerabilities, such as Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS), are particularly concerning as they can lead to data breaches, unauthorized actions, and compromise of user accounts. The fact that the last vulnerability was in 2019 and none are currently unpatched is a small positive, but the history of past issues suggests potential for future vulnerabilities if not actively maintained and rigorously audited.

In conclusion, while Zoho SalesIQ v2.0.5 exhibits some commendable security practices in its code, particularly in data handling and the absence of direct attack surfaces, its past vulnerability record is a serious concern. The lack of comprehensive capability checks alongside the historical prevalence of CSRF and XSS vulnerabilities suggests that while direct code exploits might be limited in this specific version, the plugin's overall security track record warrants caution.

Key Concerns

  • Multiple High Severity Vulnerabilities in History
  • Medium Severity Vulnerability in History
  • Lack of capability checks
  • Low percentage of properly escaped outputs
Vulnerabilities
4

Zoho SalesIQ – Live chat, chatbots, and visitor tracking Security Vulnerabilities

CVEs by Year

4 CVEs in 2019
2019
Patched Has unpatched

Severity Breakdown

High
3
Medium
1

4 total CVEs

CVE-2019-5963high · 8.8Cross-Site Request Forgery (CSRF)

Zoho SalesIQ <= 1.0.8 - Cross-Site Request Forgery

May 31, 2019 Patched in 1.0.9 (1698d)
CVE-2019-5962medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Zoho SalesIQ <= 1.0.8 - Cross-Site Scripting

May 31, 2019 Patched in 1.0.9 (1698d)
CVE-2019-15645high · 8.8Cross-Site Request Forgery (CSRF)

Zoho SalesIQ <= 1.0.8 - Cross-Site Request Forgery

May 31, 2019 Patched in 1.0.9 (1698d)
CVE-2019-15644high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Zoho SalesIQ <= 1.0.8 - Stored Cross-Site Scripting

May 31, 2019 Patched in 1.0.9 (1698d)
Code Analysis
Analyzed Mar 16, 2026

Zoho SalesIQ – Live chat, chatbots, and visitor tracking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
6 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped8 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<salesiq> (salesiq.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Zoho SalesIQ – Live chat, chatbots, and visitor tracking Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menuindex.php:15
actionwp_footerindex.php:107
Maintenance & Trust

Zoho SalesIQ – Live chat, chatbots, and visitor tracking Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 5, 2025
PHP min version
Downloads315K

Community Trust

Rating82/100
Number of ratings7
Active installs20K
Developer Profile

Zoho SalesIQ – Live chat, chatbots, and visitor tracking Developer Profile

zohosalesiq

1 plugin · 20K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
1698 days
View full developer profile
Detection Fingerprints

How We Detect Zoho SalesIQ – Live chat, chatbots, and visitor tracking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zoho-salesiq/logo.png
Script Paths
https://salesiq.zoho.com/widget?plugin_source=wordpress

HTML / DOM Fingerprints

CSS Classes
lvd_notelvd_notesblvd_embdlvd_embdlftlvd_embdlft spanlvd_embdlft alvd_embdlft a:hoverlvd_embdmid+18 more
Data Attributes
id="zsiqchat"id="zsiqscript"
JS Globals
window.$zoho$zoho.salesiq
FAQ

Frequently Asked Questions about Zoho SalesIQ – Live chat, chatbots, and visitor tracking