
Zendesk Chat Security & Risk Analysis
wordpress.org/plugins/zopim-live-chatZendesk Chat (previously Zopim) lets you monitor and chat with visitors surfing your store in real-time. Impress them personally and ease them into th …
Is Zendesk Chat Safe to Use in 2026?
Generally Safe
Score 85/100Zendesk Chat has a strong security track record. Known vulnerabilities have been patched promptly.
The "zopim-live-chat" plugin v1.4.18 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack authorization checks. All SQL queries are properly prepared, indicating good practice in database interaction. Furthermore, there are no critical or high-severity taint flows detected. However, concerns arise from the low percentage (7%) of properly escaped output, which suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, especially given the historical prevalence of this vulnerability type in past CVEs. The plugin also makes three external HTTP requests, which could be a vector for other security issues if not handled with extreme care.
The vulnerability history shows a single known CVE, which is currently unpatched. This is a significant concern, even if it's of medium severity and quite old. The fact that it was an XSS vulnerability reinforces the concern about insufficient output escaping. While the current version may not be actively exploited due to its age, the pattern of XSS vulnerabilities in its history and the low output escaping rate present a notable risk. The plugin's strengths lie in its limited attack surface and secure database practices, but the weakness in output sanitization and the presence of a historical vulnerability are significant drawbacks.
Key Concerns
- Low percentage of properly escaped output
- 1 medium severity historical CVE
- Flows with unsanitized paths detected
Zendesk Chat Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Zendesk Chat < 1.2.6 - Cross-Site Scripting
Zendesk Chat Code Analysis
Output Escaping
Data Flow Analysis
Zendesk Chat Attack Surface
WordPress Hooks 6
Maintenance & Trust
Zendesk Chat Maintenance & Trust
Maintenance Signals
Community Trust
Zendesk Chat Alternatives
Jibber Chat
jibber-chat
Jibber is a chat service that lets you connect with your customers instantly. It works by placing a chat bubble on your Wordpress site that your custo …
Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons
chatway-live-chat
AI chatbot & live chat for customer support, FAQ, chat buttons including WhatsApp with Chatway live chat. iOS & Android apps available 💬
LiveChat – Live Chat Plugin for WP Websites
wp-live-chat-software-for-wordpress
Best live chat and help desk plugin for WordPress websites. Add the LiveChat widget to engage visitors and provide real‑time customer support! 🚀
Typebot
typebot
Collect 4x more responses with conversational apps using Typebot.
Live Chat with Messenger Customer Chat
fb-messenger-live-chat
Support your customers via Facebook Messenger Live Chat conveniently from your own website.
Zendesk Chat Developer Profile
2 plugins · 12K total installs
How We Detect Zendesk Chat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zopim-live-chat/assets/css/zopim.css/wp-content/plugins/zopim-live-chat/assets/js/zopim.jshttps://v2.zopim.com/widget/livechat.jszopim-live-chat/assets/css/zopim.css?ver=zopim-live-chat/assets/js/zopim.js?ver=HTML / DOM Fingerprints
zopim-auth-error-messagedata-zopim-idzopim_livechat