Add Chat App Button Security & Risk Analysis

wordpress.org/plugins/add-whatsapp-button

Add Chat App Button enables adding a customizeable click-to-chat button that opens a chat on WhatsApp. This plugin is not affiliated with WhatsApp or …

2K active installs v2.1.9 PHP 5.4+ WP 7.0+ Updated Mar 18, 2026
buttonwhatsappwhatsapp-button
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 20, 2024
Download
Safety Verdict

Is Add Chat App Button Safe to Use in 2026?

Generally Safe

Score 99/100

Add Chat App Button has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Nov 20, 2024Updated 2mo ago
Risk Assessment

The 'add-whatsapp-button' plugin v2.1.8 demonstrates a generally strong security posture, particularly concerning its handling of SQL queries, lack of external HTTP requests, and file operations. The plugin adheres to good practices by utilizing prepared statements for all SQL queries and has a small, protected attack surface with a single AJAX handler that appears to have nonce checks, although capability checks are notably absent. However, a significant concern is the 25% of output that is not properly escaped, indicating a potential risk of Cross-Site Scripting (XSS) vulnerabilities. This is further underscored by the plugin's vulnerability history, which includes a medium-severity XSS vulnerability as its last recorded CVE. While currently no CVEs are unpatched, the pattern of XSS vulnerabilities suggests that output sanitization needs to be improved to prevent future exploitations. The absence of capability checks on the AJAX handler, while not explicitly showing an issue in the static analysis, represents a potential weakness that could be exploited if other security layers are bypassed.

Key Concerns

  • Unescaped output detected
  • Missing capability checks on AJAX handler
  • Previous XSS vulnerabilities
Vulnerabilities
1 published

Add Chat App Button Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-52489medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Add Chat App Button <= 2.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

Nov 20, 2024 Patched in 2.1.8 (7d)
Version History

Add Chat App Button Release Timeline

v2.1.9Current
v2.1.8
v2.1.71 CVE
v2.1.61 CVE
v2.1.51 CVE
v2.1.31 CVE
v2.1.21 CVE
v2.1.11 CVE
v2.1.01 CVE
v2.0.51 CVE
v2.0.41 CVE
v2.0.31 CVE
v2.0.21 CVE
v2.0.11 CVE
v2.0.01 CVE
v1.2.31 CVE
v1.2.21 CVE
v1.2.11 CVE
v1.21 CVE
v1.1.31 CVE
Code Analysis
Analyzed Mar 16, 2026

Add Chat App Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
50
149 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped199 total outputs
Attack Surface

Add Chat App Button Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_dismiss_admin_noticevendors\persist-admin-notices-dismissal\persist-admin-notices-dismissal.php:47
WordPress Hooks 17
actionadmin_menuadmin\settings.php:16
actionadmin_initadmin\settings.php:17
actionadmin_noticesadmin\settings.php:20
actionadmin_enqueue_scriptsadmin\settings.php:43
actionadmin_enqueue_scriptsadmin\settings.php:52
actionadmin_noticesadmin\settings.php:116
actionwp_enqueue_scriptsincludes\scripts-manager.php:14
actionwp_headincludes\styles-manager.php:19
actionadmin_headincludes\styles-manager.php:25
actionadmin_enqueue_scriptsincludes\styles-manager.php:27
actioninitplugin.php:60
actionplugins_loadedplugin.php:62
actionadmin_initplugin.php:109
filterplugin_action_links_add-whatsapp-button/add-whatsapp-button.phpplugin.php:114
actionwp_footerplugin.php:171
actionadmin_enqueue_scriptsvendors\persist-admin-notices-dismissal\persist-admin-notices-dismissal.php:46
filterpand_dismiss_notice_js_urlvendors\persist-admin-notices-dismissal\persist-admin-notices-dismissal.php:57
Maintenance & Trust

Add Chat App Button Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 18, 2026
PHP min version5.4
Downloads66K

Community Trust

Rating96/100
Number of ratings13
Active installs2K
Developer Profile

Add Chat App Button Developer Profile

udidol

1 plugin · 2K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Add Chat App Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-whatsapp-button/css/frontend.css/wp-content/plugins/add-whatsapp-button/css/admin.css/wp-content/plugins/add-whatsapp-button/js/frontend.js/wp-content/plugins/add-whatsapp-button/js/admin.js/wp-content/plugins/add-whatsapp-button/css/style-templates/wab-icon-styled.css/wp-content/plugins/add-whatsapp-button/css/style-templates/wab-icon-plain.css/wp-content/plugins/add-whatsapp-button/css/style-templates/wab-side-rectangle.css/wp-content/plugins/add-whatsapp-button/css/style-templates/wab-side-chat.css+9 more
Script Paths
/wp-content/plugins/add-whatsapp-button/js/frontend.js/wp-content/plugins/add-whatsapp-button/js/admin.js
Version Parameters
add-whatsapp-button/css/frontend.css?ver=add-whatsapp-button/css/admin.css?ver=add-whatsapp-button/js/frontend.js?ver=add-whatsapp-button/js/admin.js?ver=add-whatsapp-button/css/style-templates/wab-icon-styled.css?ver=add-whatsapp-button/css/style-templates/wab-icon-plain.css?ver=add-whatsapp-button/css/style-templates/wab-side-rectangle.css?ver=add-whatsapp-button/css/style-templates/wab-side-chat.css?ver=add-whatsapp-button/css/style-templates/wab-side-classic.css?ver=add-whatsapp-button/css/style-templates/wab-side-minimal.css?ver=add-whatsapp-button/css/style-templates/wab-side-minimal-red.css?ver=add-whatsapp-button/css/style-templates/wab-side-minimal-black.css?ver=add-whatsapp-button/css/style-templates/wab-side-minimal-white.css?ver=add-whatsapp-button/css/style-templates/wab-side-minimal-circle.css?ver=add-whatsapp-button/css/style-templates/wab-side-minimal-circle-red.css?ver=add-whatsapp-button/css/style-templates/wab-side-minimal-circle-black.css?ver=add-whatsapp-button/css/style-templates/wab-side-minimal-circle-white.css?ver=

HTML / DOM Fingerprints

CSS Classes
awb-hideawb-displaynoneawb-preview-wrapperwab-icon-plainwab-icon-styledwab-side-rectanglewab-side-chatwab-side-classic+8 more
HTML Comments
<!-- Main wrapper start --><!-- The preview button --><!-- The settings form -->
Data Attributes
data-awb-button-typedata-awb-button-textdata-awb-button-urldata-awb-icon-sizedata-awb-button-bg-colordata-awb-button-text-color+17 more
JS Globals
window.awb_frontend_scriptswindow.awb_admin_scripts
Shortcode Output
[add_whatsapp_button]
FAQ

Frequently Asked Questions about Add Chat App Button