Firebase Support & Chat Management Security & Risk Analysis

wordpress.org/plugins/admin-chat-box

Firebase Support & Chat Management, real-time communication tool for WordPress powered by Firebase for secure and scalable interaction.

0 active installs v3.1.1 PHP 5.6+ WP 5.0+ Updated Dec 6, 2025
admin-chat-boxchatchat-formfirebaseform
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Firebase Support & Chat Management Safe to Use in 2026?

Generally Safe

Score 100/100

Firebase Support & Chat Management has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'admin-chat-box' plugin v3.1.1 exhibits a strong security posture in several key areas. The static analysis reveals excellent adherence to security best practices, with 100% of output being properly escaped, no file operations, and a significant majority of SQL queries utilizing prepared statements. The absence of dangerous functions and bundled libraries is also a positive sign. Furthermore, the plugin has a clean vulnerability history with zero recorded CVEs, suggesting consistent security development. The comprehensive use of nonce and capability checks on its entry points (AJAX handlers and REST API routes) indicates a well-protected attack surface.

However, the analysis does flag some areas for attention. The presence of four taint flows with unsanitized paths, classified as high severity, represents the most significant risk. While these flows did not result in critical vulnerabilities, they indicate potential pathways for attackers to inject malicious data, particularly if external HTTP requests or other input vectors are not meticulously handled downstream. The external HTTP request, while only one, is also a potential point of concern if not securely implemented.

Overall, 'admin-chat-box' v3.1.1 is a well-developed plugin from a security perspective, demonstrating robust input validation and output sanitization in most areas. The primary concern lies with the identified high-severity taint flows, which require careful review to ensure they do not pose an exploitable risk. The lack of historical vulnerabilities is a strong indicator of developer diligence, but the identified taint flows suggest ongoing vigilance is still necessary.

Key Concerns

  • High severity taint flows with unsanitized paths
  • External HTTP request present
Vulnerabilities
None known

Firebase Support & Chat Management Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Firebase Support & Chat Management Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
56 prepared
Unescaped Output
0
167 escaped
Nonce Checks
22
Capability Checks
14
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

93% prepared60 total queries

Output Escaping

100% escaped167 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

11 flows4 with unsanitized paths
test_firebase_connection (inc\ACB_AjaxHandler.php:153)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Firebase Support & Chat Management Attack Surface

Entry Points33
Unprotected0

AJAX Handlers 29

authwp_ajax_acb_data_truncateinc\ACB_AjaxHandler.php:18
noprivwp_ajax_acb_data_truncateinc\ACB_AjaxHandler.php:19
authwp_ajax_show_user_inputed_datainc\ACB_AjaxHandler.php:22
noprivwp_ajax_show_user_inputed_datainc\ACB_AjaxHandler.php:23
authwp_ajax_acb_save_firebase_configinc\ACB_AjaxHandler.php:26
authwp_ajax_acb_test_firebase_connectioninc\ACB_AjaxHandler.php:27
authwp_ajax_acb_firebase_authinc\ACB_AjaxHandler.php:28
authwp_ajax_acb_get_all_usersinc\ACB_AjaxHandler.php:31
authwp_ajax_acb_get_usersinc\ACB_AjaxHandler.php:32
noprivwp_ajax_acb_get_usersinc\ACB_AjaxHandler.php:33
authwp_ajax_acb_toggle_user_agentinc\ACB_AjaxHandler.php:34
authwp_ajax_acb_sync_firebase_usersinc\ACB_AjaxHandler.php:35
authwp_ajax_acb_get_support_settingsinc\ACB_AjaxHandler.php:36
noprivwp_ajax_acb_get_support_settingsinc\ACB_AjaxHandler.php:37
authwp_ajax_acb_get_widget_settingsinc\ACB_AjaxHandler.php:38
noprivwp_ajax_acb_get_widget_settingsinc\ACB_AjaxHandler.php:39
authwp_ajax_acb_save_widget_settingsinc\ACB_AjaxHandler.php:40
authwp_ajax_acb_save_support_settingsinc\ACB_AjaxHandler.php:41
authwp_ajax_acb_check_user_admin_statusinc\ACB_AjaxHandler.php:42
noprivwp_ajax_acb_check_user_admin_statusinc\ACB_AjaxHandler.php:43
authwp_ajax_acb_firebase_authinc\ACB_FirebaseService.php:35
noprivwp_ajax_acb_firebase_authinc\ACB_FirebaseService.php:36
authwp_ajax_acb_save_messageinc\ACB_FirebaseService.php:37
noprivwp_ajax_acb_save_messageinc\ACB_FirebaseService.php:38
authwp_ajax_acb_get_messagesinc\ACB_FirebaseService.php:39
noprivwp_ajax_acb_get_messagesinc\ACB_FirebaseService.php:40
authwp_ajax_acb_get_usersinc\ACB_FirebaseService.php:41
noprivwp_ajax_acb_get_usersinc\ACB_FirebaseService.php:42
authwp_ajax_acb_save_firebase_configinc\ACB_FirebaseService.php:43

REST API Routes 2

POST/wp-json/acb/v1/firebasecredentialsinc\ACB_Route.php:37
GET/wp-json/acb/v1/getfirebasecredentialsinc\ACB_Route.php:46

Shortcodes 2

[acb_chat_widget] inc\ACB_Shortcode.php:33
[acb_chat] inc\ACB_Shortcode.php:34
WordPress Hooks 10
actionplugins_loadedadmin_chat_box.php:59
actionactivated_pluginadmin_chat_box.php:60
actionadmin_menuinc\ACB_AdminDashboard.php:26
actioninitinc\ACB_DbTables.php:32
actionadmin_enqueue_scriptsinc\ACB_Enqueue.php:28
actionwp_enqueue_scriptsinc\ACB_FrontendWidget.php:25
actionwp_footerinc\ACB_FrontendWidget.php:26
actionrest_api_initinc\ACB_Route.php:26
actioninitinc\ACB_Shortcode.php:25
actionwp_enqueue_scriptsinc\ACB_Shortcode.php:26
Maintenance & Trust

Firebase Support & Chat Management Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 6, 2025
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Firebase Support & Chat Management Developer Profile

Sabbir Sam

3 plugins · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Firebase Support & Chat Management

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/admin-chat-box/build/style-index.css/wp-content/plugins/admin-chat-box/assets/library/all.min.css/wp-content/plugins/admin-chat-box/build/index.js/wp-content/plugins/admin-chat-box/build/users-index.js/wp-content/plugins/admin-chat-box/build/settings-index.js
Script Paths
/wp-content/plugins/admin-chat-box/build/index.js/wp-content/plugins/admin-chat-box/build/users-index.js/wp-content/plugins/admin-chat-box/build/settings-index.js
Version Parameters
/wp-content/plugins/admin-chat-box/build/style-index.css?ver=/wp-content/plugins/admin-chat-box/assets/library/all.min.css?ver=/wp-content/plugins/admin-chat-box/build/index.js?ver=/wp-content/plugins/admin-chat-box/build/users-index.js?ver=/wp-content/plugins/admin-chat-box/build/settings-index.js?ver=

HTML / DOM Fingerprints

JS Globals
appLocalizer
REST Endpoints
/wp-json/
FAQ

Frequently Asked Questions about Firebase Support & Chat Management