
Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button Security & Risk Analysis
wordpress.org/plugins/button-contact-vrPowerful platform with Live Chat, AI Chatbots, and Real-Time Visitor Monitoring! Also, create Call, Email, SMS, & Contact buttons to increase conv …
Is Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button Safe to Use in 2026?
Generally Safe
Score 98/100Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "button-contact-vr" plugin, version 5.0.6, exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query preparation and output escaping, a significant concern arises from its attack surface. With 10 total entry points, a disproportionate 9 are found to be unprotected, meaning they lack proper authorization checks. This creates a substantial risk, as unauthenticated users could potentially interact with these endpoints.
The static analysis also reveals taint flows with unsanitized paths, indicating a potential for vulnerabilities where user-supplied data could be mishandled. Although no critical or high severity taint flows were found, and the plugin has no currently unpatched CVEs, the history of 3 medium severity CVEs, all related to Cross-site Scripting (XSS), is a worrying pattern. This suggests a recurring issue with how user input is processed, even if recent versions have addressed specific instances.
In conclusion, the plugin has strengths in secure coding for SQL and output handling. However, the high number of unprotected REST API routes and the historical XSS vulnerabilities represent significant weaknesses that require attention to mitigate potential risks.
Key Concerns
- High number of unprotected REST API routes
- Taint flows with unsanitized paths found
- History of medium severity XSS CVEs
Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Button contact VR <= 4.7.9.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Button contact VR <= 4.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
Button contact VR <= 4.7 - Authenticated (Admin+) Stored Cross-Site Scripting
Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button Release Timeline
Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button Code Analysis
Output Escaping
Data Flow Analysis
Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button Attack Surface
REST API Routes 9
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button Maintenance & Trust
Maintenance Signals
Community Trust
Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button Alternatives
Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons
chatway-live-chat
AI chatbot agent & live chat for customer support, FAQ, chat buttons including WhatsApp with Chatway live chat. iOS & Android apps available 💬
LinkFlow Chat – AI Chatbot With Social Media Buttons
linkflow-chat
LinkFlow Chat adds AI to WordPress for smart chats, with handoff to WhatsApp or social media to boost satisfaction and grow your followers.
Simple Chat Bot
simple-chat-bot
A user-friendly chatbot plugin for WordPress that enables seamless communication with your visitors via WhatsApp.
Tidio – Live Chat & AI Chatbots
tidio-live-chat
Add Tidio Live Chat to your WordPress for free to answer customers’ questions, engage website visitors, generate leads, and increase sales.
Crisp – Live Chat and Chatbot
crisp
A Free, one-click-to-install, Live Chat and chatbot plugin. No coding skills are required. Used by more than 30 000 customers on WordPress.
Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button Developer Profile
3 plugins · 180K total installs
How We Detect Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/button-contact-vr/assets/app/index.css/wp-content/plugins/button-contact-vr/assets/app/index.js/wp-content/plugins/button-contact-vr/app/autoloader.phpbutton-contact-vr/style.css?ver=button-contact-vr/script.js?ver=button-contact-vr/assets/app/index.css?ver=button-contact-vr/assets/app/index.js?ver=HTML / DOM Fingerprints
bz-buttonizer-pro-dialogbz-editor-containerbz-settings-containerbz-support-containerdata-editor-framedata-buttonizer-actionbuttonizer_adminBZContactButton/wp-json/buttonizer/v1/settings/wp-json/buttonizer/v1/buttons