
Buttonizer – Live Chat, AI Chatbot, & Chat Widgets Security & Risk Analysis
wordpress.org/plugins/button-contact-vrPowerful platform with Live Chat, AI Chatbots, and Real-Time Visitor Monitoring! Also, create Call, Email, SMS, & Contact buttons to increase conv …
Is Buttonizer – Live Chat, AI Chatbot, & Chat Widgets Safe to Use in 2026?
Generally Safe
Score 98/100Buttonizer – Live Chat, AI Chatbot, & Chat Widgets has a strong security track record. Known vulnerabilities have been patched promptly.
The "button-contact-vr" plugin, version 5.0.6, exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query preparation and output escaping, a significant concern arises from its attack surface. With 10 total entry points, a disproportionate 9 are found to be unprotected, meaning they lack proper authorization checks. This creates a substantial risk, as unauthenticated users could potentially interact with these endpoints.
The static analysis also reveals taint flows with unsanitized paths, indicating a potential for vulnerabilities where user-supplied data could be mishandled. Although no critical or high severity taint flows were found, and the plugin has no currently unpatched CVEs, the history of 3 medium severity CVEs, all related to Cross-site Scripting (XSS), is a worrying pattern. This suggests a recurring issue with how user input is processed, even if recent versions have addressed specific instances.
In conclusion, the plugin has strengths in secure coding for SQL and output handling. However, the high number of unprotected REST API routes and the historical XSS vulnerabilities represent significant weaknesses that require attention to mitigate potential risks.
Key Concerns
- High number of unprotected REST API routes
- Taint flows with unsanitized paths found
- History of medium severity XSS CVEs
Buttonizer – Live Chat, AI Chatbot, & Chat Widgets Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Button contact VR <= 4.7.9.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Button contact VR <= 4.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
Button contact VR <= 4.7 - Authenticated (Admin+) Stored Cross-Site Scripting
Buttonizer – Live Chat, AI Chatbot, & Chat Widgets Code Analysis
Output Escaping
Data Flow Analysis
Buttonizer – Live Chat, AI Chatbot, & Chat Widgets Attack Surface
REST API Routes 9
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
Buttonizer – Live Chat, AI Chatbot, & Chat Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Buttonizer – Live Chat, AI Chatbot, & Chat Widgets Alternatives
Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons
chatway-live-chat
AI chatbot & live chat for customer support, FAQ, chat buttons including WhatsApp with Chatway live chat. iOS & Android apps available 💬
Lime Connect (formerly Userlike) – WordPress Live Chat plugin
userlike
Free live chat plugin to chat with the visitors of your website. Integrate a beautiful and fully customizable chat box. Hosted in Europe.
Live Chat & AI Chatbots – onWebChat
onwebchat
Enhance customer service with instant 24/7 AI-powered replies. Now with WooCommerce integration, so your chatbot understands your products and helps c …
AI Chatbot for WordPress by Customerly
customerly
AI Chatbot to support customers, create engaging messages and send automated emails.
Social Intents – Live Chat
live-chat-support-by-social-intents
AI Chatbot & Live Chat plugin for WordPress. Chat with visitors using ChatGPT, Claude, Gemini, Slack, Teams, and Google Chat.
Buttonizer – Live Chat, AI Chatbot, & Chat Widgets Developer Profile
3 plugins · 190K total installs
How We Detect Buttonizer – Live Chat, AI Chatbot, & Chat Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/button-contact-vr/assets/app/index.css/wp-content/plugins/button-contact-vr/assets/app/index.js/wp-content/plugins/button-contact-vr/app/autoloader.phpbutton-contact-vr/style.css?ver=button-contact-vr/script.js?ver=button-contact-vr/assets/app/index.css?ver=button-contact-vr/assets/app/index.js?ver=HTML / DOM Fingerprints
bz-buttonizer-pro-dialogbz-editor-containerbz-settings-containerbz-support-containerdata-editor-framedata-buttonizer-actionbuttonizer_adminBZContactButton/wp-json/buttonizer/v1/settings/wp-json/buttonizer/v1/buttons