
Block Editor for ManyChat Security & Risk Analysis
wordpress.org/plugins/block-editor-for-manychatEasily add ManyChat widgets to your site.
Is Block Editor for ManyChat Safe to Use in 2026?
Generally Safe
Score 85/100Block Editor for ManyChat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "block-editor-for-manychat" plugin version 1.0.5 appears to be relatively strong based on the static analysis provided. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points suggests a limited attack surface. Furthermore, the use of prepared statements for all SQL queries and the lack of dangerous functions are positive indicators of secure coding practices.
However, a significant concern arises from the fact that 100% of the identified output locations are not properly escaped. This represents a substantial risk for potential Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the site through unsanitized output. The presence of an external HTTP request, while not inherently problematic, also warrants attention to ensure it is handled securely and does not introduce further vulnerabilities. The vulnerability history being clear of any known CVEs is a good sign, but this should not lead to complacency, especially given the identified output escaping issue.
In conclusion, while the plugin demonstrates good practices in areas like SQL handling and limiting its attack surface, the critical weakness in output escaping presents a significant security risk that needs immediate attention. The lack of recorded vulnerabilities in the past is positive, but the static analysis reveals a clear and actionable area for improvement.
Key Concerns
- Output not properly escaped
- External HTTP request without context
Block Editor for ManyChat Security Vulnerabilities
Block Editor for ManyChat Code Analysis
Output Escaping
Block Editor for ManyChat Attack Surface
WordPress Hooks 15
Maintenance & Trust
Block Editor for ManyChat Maintenance & Trust
Maintenance Signals
Community Trust
Block Editor for ManyChat Alternatives
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
chaty
WhatsApp chat, Facebook Messenger, Telegram, TikTok, Instagram, Email, Line, WeChat Phone call, SMS, 20+ live chat icons & WhatsApp chat pop up 💬
All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements
mystickyelements
Get leads with a floating contact form tab, chat & social buttons like Facebook Messenger, WhatsApp, Viber, Telegram, Twitter, Instagram & more 🎉
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist
bit-assist
Floating sticky chat button for WhatsApp Chat, Facebook Messenger, Telegram, Instagram, SMS, Call, Discord chat, TikTok, Line & 30+ channels
Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons
sticky-chat-widget
Social chat buttons with WhatsApp, Messenger, WeChat, Telegram, Instagram, TikTok, Zalo & more — plus SMS, Call button, Contact form, and 20+ icons.
Block Editor for ManyChat Developer Profile
1 plugin · 100 total installs
How We Detect Block Editor for ManyChat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-editor-for-manychat/js/gutenberg.js/wp-content/plugins/block-editor-for-manychat/css/gutenberg.css/wp-content/plugins/block-editor-for-manychat/admin/css/wp-manychat-admin.css/wp-content/plugins/block-editor-for-manychat/admin/js/wp-manychat-admin.jswp-blockswp-elementwp-datablock-editor-for-manychat/admin/css/wp-manychat-admin.css?ver=block-editor-for-manychat/admin/js/wp-manychat-admin.js?ver=block-editor-for-manychat/js/gutenberg.js?ver=block-editor-for-manychat/css/gutenberg.css?ver=HTML / DOM Fingerprints
id="fb-page-id"