Ace Social Chat Security & Risk Analysis

wordpress.org/plugins/ace-social-chat

Connect with your customer through whatsapp, its very easy and fast.

10 active installs v1.0.8 PHP 5.6.0+ WP 4.9+ Updated Jun 30, 2025
agentsfloatingmessagewhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ace Social Chat Safe to Use in 2026?

Generally Safe

Score 100/100

Ace Social Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The plugin "ace-social-chat" version 1.0.8 exhibits a mixed security posture. On the positive side, it has no known CVEs, zero unpatched vulnerabilities, and reports no dangerous functions or raw SQL queries. The absence of file operations and external HTTP requests also reduces potential attack vectors. However, significant concerns arise from the static analysis. A notable weakness is the very low percentage (26%) of properly escaped outputs, indicating a high risk of cross-site scripting (XSS) vulnerabilities across numerous output points. Additionally, the taint analysis reveals two flows with unsanitized paths, which could potentially lead to code execution or information disclosure if exploited, even though they are not classified as critical or high severity in the provided data.

The plugin's vulnerability history is clean, which is a strong indicator of good development practices or a lack of targeted attacks so far. However, the static analysis findings, particularly the unescaped output and unsanitized paths, suggest that the plugin is not as secure as its history might imply. The lack of nonce checks and capability checks on its single shortcode entry point is also a concern, potentially allowing unauthorized users to trigger plugin actions. The overall security posture is therefore one of caution, with strengths in vulnerability history and basic code hygiene but significant weaknesses in output sanitization and potential path traversal issues.

Key Concerns

  • Low output escaping percentage
  • Unsanitized paths in taint analysis
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Ace Social Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ace Social Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
40
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

26% escaped54 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
aceWhatsappMenuCallback (admin\class-ace-social-chat-admin.php:279)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Ace Social Chat Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ace_wtsp_agent] public\class-ace-social-chat-public.php:140
WordPress Hooks 13
actionplugins_loadedincludes\class-ace-social-chat.php:144
actionadmin_enqueue_scriptsincludes\class-ace-social-chat.php:159
actionadmin_enqueue_scriptsincludes\class-ace-social-chat.php:160
actioninitincludes\class-ace-social-chat.php:162
actionadd_meta_boxesincludes\class-ace-social-chat.php:163
actionsave_postincludes\class-ace-social-chat.php:164
actionmanage_ace_whatsapp_agent_posts_custom_columnincludes\class-ace-social-chat.php:165
filtermanage_ace_whatsapp_agent_posts_columnsincludes\class-ace-social-chat.php:166
actionadmin_menuincludes\class-ace-social-chat.php:167
actionwp_enqueue_scriptsincludes\class-ace-social-chat.php:182
actionwp_enqueue_scriptsincludes\class-ace-social-chat.php:183
actionwp_footerincludes\class-ace-social-chat.php:185
actionwpincludes\class-ace-social-chat.php:186
Maintenance & Trust

Ace Social Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 30, 2025
PHP min version5.6.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Ace Social Chat Developer Profile

Acewebx

7 plugins · 340 total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
330 days
View full developer profile
Detection Fingerprints

How We Detect Ace Social Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ace-social-chat/admin/css/ace-social-chat-admin.css/wp-content/plugins/ace-social-chat/admin/js/ace-social-chat-admin.js
Script Paths
https://use.fontawesome.com/releases/v5.7.2/css/all.css
Version Parameters
ace-social-chat-admin.css?ver=ace-social-chat-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
ace_member_box_shortcace_member_box_shortc_content
HTML Comments
<!-- Ace Social Chat --><!-- Shortcode for Ace Social Chat --><!-- Agent ShortCode -->
Data Attributes
data-plugin-name="Ace_Social_Chat"data-plugin-version="1.0.8"
JS Globals
window.ace_social_chat_settings
Shortcode Output
[ace_wtsp_agent id=
FAQ

Frequently Asked Questions about Ace Social Chat