All-in-one contact buttons – WPSHARE247 Security & Risk Analysis

wordpress.org/plugins/all-in-one-contact-buttons-wpshare247

Floating click to contact buttons All-In-One Tạo nút liên hệ gôm tất cả vào trong một nút duy nhất bao gồm: số hotline, zalo, facebook, messenger, ema …

4K active installs v1.7 PHP 5.6+ WP 4.9+ Updated May 9, 2025
call-buttoncall-now-buttoncontact-all-in-oneiconquick-call-button
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is All-in-one contact buttons – WPSHARE247 Safe to Use in 2026?

Generally Safe

Score 100/100

All-in-one contact buttons – WPSHARE247 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The static analysis of the 'all-in-one-contact-buttons-wpshare247' plugin version 1.7 reveals a generally strong security posture in terms of its attack surface and common vulnerability indicators. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits potential entry points for attackers. The absence of dangerous functions, file operations, external HTTP requests, and bundled libraries further contributes to a cleaner codebase. Additionally, the plugin demonstrates good output escaping practices with 91% of outputs properly escaped and no critical or high severity taint flows were detected. This indicates a proactive effort to prevent common web vulnerabilities.

However, a notable concern arises from the single SQL query identified, which is not using prepared statements. This represents a potential risk for SQL injection vulnerabilities, even if the overall attack surface is small. While the vulnerability history is clean with no recorded CVEs, this does not guarantee future safety and should be monitored. The lack of nonce and capability checks on its limited entry points, though currently minimal in impact due to the zero entry points, could become a concern if functionality is added without these security measures.

In conclusion, this plugin exhibits a promising security foundation with a minimal attack surface and good output escaping. The primary area of improvement lies in addressing the unescaped SQL query to fully mitigate the risk of injection attacks. Continued vigilance regarding vulnerability history and adherence to WordPress security best practices, especially if new features are introduced, will be crucial for maintaining its security.

Key Concerns

  • Raw SQL query without prepared statements
Vulnerabilities
None known

All-in-one contact buttons – WPSHARE247 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

All-in-one contact buttons – WPSHARE247 Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
22
231 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

91% escaped253 total outputs
Attack Surface

All-in-one contact buttons – WPSHARE247 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_headinc\class.setting.page.php:16
actionadmin_menuinc\class.setting.page.php:17
actionadmin_initinc\class.setting.page.php:18
actionadmin_enqueue_scriptsinc\class.setting.page.php:19
filterplugin_action_linksinc\class.setting.page.php:20
actionplugins_loadedinc\class.setting.page.php:21
actionactivated_plugininc\class.setting.page.php:22
actionws247_aio_ct_add_my_oiconsinc\class.setting.page.php:23
actionws247_aio_ct_add_beforeinc\class.setting.page.php:24
actionws247_aio_ct_add_afterinc\class.setting.page.php:25
actionwp_enqueue_scriptsinc\theme_functions.php:16
actionwp_footerinc\theme_functions.php:17
Maintenance & Trust

All-in-one contact buttons – WPSHARE247 Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedMay 9, 2025
PHP min version5.6
Downloads52K

Community Trust

Rating100/100
Number of ratings1
Active installs4K
Developer Profile

All-in-one contact buttons – WPSHARE247 Developer Profile

Website366.com

7 plugins · 5K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect All-in-one contact buttons – WPSHARE247

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/all-in-one-contact-buttons-wpshare247/inc/aio_ct_button_admin_css.css/wp-content/plugins/all-in-one-contact-buttons-wpshare247/inc/js/fancybox/dist/jquery.fancybox.min.css/wp-content/plugins/all-in-one-contact-buttons-wpshare247/inc/js/font-awesome-4.7.0/css/font-awesome.min.css/wp-content/plugins/all-in-one-contact-buttons-wpshare247/inc/admin_aio_ct_button.js/wp-content/plugins/all-in-one-contact-buttons-wpshare247/inc/js/fancybox/dist/jquery.fancybox.min.js
Script Paths
/wp-content/plugins/all-in-one-contact-buttons-wpshare247/inc/admin_aio_ct_button.js/wp-content/plugins/all-in-one-contact-buttons-wpshare247/inc/js/fancybox/dist/jquery.fancybox.min.js
Version Parameters
/wp-content/plugins/all-in-one-contact-buttons-wpshare247/inc/aio_ct_button_admin_css.css?ver=/wp-content/plugins/all-in-one-contact-buttons-wpshare247/inc/js/fancybox/dist/jquery.fancybox.min.css?ver=/wp-content/plugins/all-in-one-contact-buttons-wpshare247/inc/js/font-awesome-4.7.0/css/font-awesome.min.css?ver=/wp-content/plugins/all-in-one-contact-buttons-wpshare247/inc/admin_aio_ct_button.js?ver=/wp-content/plugins/all-in-one-contact-buttons-wpshare247/inc/js/fancybox/dist/jquery.fancybox.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
tr-icon-groupws247-aio-ct-button
HTML Comments
<!-- Ws247_aio_ct_button Plugin -->
Data Attributes
ws247_aio_ct_button-fields-groupWS247_AIO_CT_BUTTON_SETTING_PAGE_SLUG
JS Globals
WS247_AIO_CT_BUTTON_TEXTDOMAINWS247_AIO_CT_BUTTON_PREFIXWS247_AIO_CT_BUTTON_PLUGIN_INC_ASSETS_URL
FAQ

Frequently Asked Questions about All-in-one contact buttons – WPSHARE247