
AGY Social Security & Risk Analysis
wordpress.org/plugins/agy-socialAdds a Whatsapp icon to the website footer.
Is AGY Social Safe to Use in 2026?
Generally Safe
Score 92/100AGY Social has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "agy-social" v1.4 plugin exhibits a remarkably clean static analysis profile, with no identified dangerous functions, SQL queries executed without prepared statements, or unescaped output. The absence of file operations, external HTTP requests, and any form of taint analysis findings further strengthens its perceived security posture. Crucially, the plugin has no recorded vulnerabilities (CVEs) and a minimal attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack proper authentication or permission checks. This indicates a strong adherence to secure coding practices where implemented.
Despite the excellent static analysis and vulnerability history, the complete absence of nonce checks and capability checks across all potential entry points (even though there are none currently exposed) represents a theoretical concern. If future versions introduce new functionalities, particularly AJAX handlers or REST API routes, the lack of these essential security mechanisms could become a significant risk. The plugin's current security is heavily reliant on its limited attack surface. A comprehensive vulnerability history of zero also suggests it may not have been subjected to extensive security auditing or that its functionality is too basic to attract attackers.
In conclusion, "agy-social" v1.4 appears to be a highly secure plugin in its current state, largely due to its minimal attack surface and robust static analysis findings. The main weakness is the theoretical risk associated with the complete absence of nonce and capability checks, which could become a concern if the plugin's functionality expands. It is a good practice to ensure these checks are in place as new features are added.
Key Concerns
- Missing nonce checks
- Missing capability checks
AGY Social Security Vulnerabilities
AGY Social Release Timeline
AGY Social Code Analysis
Output Escaping
AGY Social Attack Surface
WordPress Hooks 6
Maintenance & Trust
AGY Social Maintenance & Trust
Maintenance Signals
Community Trust
AGY Social Alternatives
Simple Webchat
quick-whatsapp
Ermöglicht es Webseitenbesuchern, Sie direkt über WhatsApp zu kontaktieren.
Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button
button-contact-vr
Powerful platform with Live Chat, AI Chatbots, and Real-Time Visitor Monitoring! Also, create Call, Email, SMS, & Contact buttons to increase conv …
Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons
sticky-chat-widget
Social chat buttons with WhatsApp, Messenger, WeChat, Telegram, Instagram, TikTok, Zalo & more — plus SMS, Call button, Contact form, and 20+ icons.
Click to Call or Chat Buttons
click-to-call-or-chat-buttons
This plugin adds Phone Call and WhatsApp button on your webpage.
Notifications for Forms & WordPress Actions
notifier
Send WhatsApp notifications for form submissions from CF7, Gravity Forms, WPForms and more and WordPress actions using WhatsApp Business API
AGY Social Developer Profile
1 plugin · 20 total installs
How We Detect AGY Social
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/agy-social/assets/style.cssagy-social/assets/style.css?ver=HTML / DOM Fingerprints
switchsliderrolagemimgmenorname="agysocial_footer_enabled"name="agysocial_footer_number"name="agysocial_footer_position"name="agysocial_footer_style"