
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist Security & Risk Analysis
wordpress.org/plugins/bit-assistFloating sticky chat button for WhatsApp Chat, Facebook Messenger, Telegram, Instagram, SMS, Call, Discord chat, TikTok, Line & 30+ channels
Is Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist Safe to Use in 2026?
Generally Safe
Score 95/100Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of bit-assist v1.7.0 reveals a generally strong focus on secure coding practices. The plugin demonstrates a positive commitment to using prepared statements for all SQL queries and a high percentage of properly escaped output, minimizing risks of SQL injection and cross-site scripting originating from standard output operations. The absence of a significant attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events is also a positive sign, reducing potential entry points for attackers. However, the historical vulnerability data presents a significant concern. The plugin has a history of 7 medium-severity CVEs, with common types including missing authorization, path traversal, and SQL injection. This indicates a pattern of recurring security flaws, even if they are currently patched. The existence of these past vulnerabilities, particularly those related to authorization and path manipulation, suggests potential weaknesses in how user input is validated and how access controls are implemented, despite the static analysis not identifying explicit unhandled entry points or dangerous functions in this specific version.
Key Concerns
- History of 7 medium severity CVEs
- 0 capability checks found
- 1 nonce check found (potentially insufficient)
- 19% of outputs not properly escaped
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Bit Assist <= 1.5.11 - Missing Authorization
Bit Assist <= 1.5.4 - Unauthenticated Path Traversal
Bit Assist <= 1.5.2 - Path Traversal to Authenticated (Subscriber+) Arbitrary File Read via fileID Parameter
Bit Assist <= 1.5.2 - Path Traversal to Authenticated (Administrator+) Arbitrary File Read via downloadResponseFile Function
Bit Assist <= 1.5.2 - Authenticated (Subscriber+) SQL Injection via id Parameter
Bit Assist <= 1.1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting
Bit Assist <= 1.1.8 - Authenticated (Administrator+) Stored Cross-Site Scripting
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist Code Analysis
SQL Query Safety
Output Escaping
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist Attack Surface
WordPress Hooks 2
Maintenance & Trust
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist Maintenance & Trust
Maintenance Signals
Community Trust
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist Alternatives
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
chaty
WhatsApp chat, Facebook Messenger, Telegram, TikTok, Instagram, Email, Line, WeChat Phone call, SMS, 20+ live chat icons & WhatsApp chat pop up 💬
Cresta Help Chat
cresta-whatsapp-chat
Allow your users and customers to contact you via WhatsApp with a single click.
Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons
sticky-chat-widget
Social chat buttons with WhatsApp, Messenger, WeChat, Telegram, Instagram, TikTok, Zalo & more — plus SMS, Call button, Contact form, and 20+ icons.
Social Chat Widget (⚡ by Callbell)
callbell-chat-widget
WhatsApp free live chat button to connect and communicate with your website visitors
Widget Click to Chat
widgetwhats-app
100% FREE Responsive WhatsApp Chat Widget with page targeting and floating button style. Fully Customizable!
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist Developer Profile
5 plugins · 39K total installs
How We Detect Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bit-assist/iframe/assets/index.css/wp-content/plugins/bit-assist/iframe/assets/index.jshttps://fonts.googleapis.com/css2?family=Outfit:wght@200;300;400;500;600;700&display=swapbit-assist/iframe/assets/index.css?ver=bit-assist/iframe/assets/index.js?ver=HTML / DOM Fingerprints
hideid="widgetWrapper"id="contentWrapper"id="widgetBubbleRow"id="widgetBubbleWrapper"id="widgetBubble"id="widget-img"+1 morewindow.bitapps_assist