Chat Button For WooCommerce Security & Risk Analysis

wordpress.org/plugins/chat-button-for-woocommerce

This simple plugin will add a WhatsApp chat button in WooCommerce single product page next to Add to Cart button. Button will be visible only when pro …

40 active installs v1.0 PHP 7.0+ WP 5.0+ Updated May 17, 2021
whatsappwoowoo-commerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Chat Button For WooCommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Chat Button For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

Based on the static analysis, the 'chat-button-for-woocommerce' plugin v1.0 presents a mixed security posture. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events, along with no detected dangerous functions, SQL queries without prepared statements, file operations, or external HTTP requests, indicates a potentially small attack surface and adherence to some secure coding practices regarding data handling and execution.

However, a significant concern arises from the 100% of analyzed outputs not being properly escaped. This lack of output escaping creates a substantial risk for Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site through user-supplied data that is later displayed. The lack of any identified nonce checks or capability checks across all potential entry points also means that even if entry points were discovered, they might not be adequately protected against unauthorized actions or access.

The vulnerability history is clean, with no known CVEs recorded for this plugin. This is a positive indicator, suggesting a history of reasonable security. However, the current static analysis reveals critical weaknesses, particularly in output escaping, which could lead to new vulnerabilities regardless of past history. The overall security is hampered by the critical output escaping flaw, which outweighs the apparent strengths in other areas.

Key Concerns

  • Output escaping: 0% properly escaped
  • Nonce checks: 0
  • Capability checks: 0
Vulnerabilities
None known

Chat Button For WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Chat Button For WooCommerce Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Chat Button For WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Chat Button For WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwoocommerce_after_add_to_cart_buttonchat-button-for-woocommerce.php:56
filterwoocommerce_get_settings_generalchat-button-for-woocommerce.php:110
Maintenance & Trust

Chat Button For WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 17, 2021
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Chat Button For WooCommerce Developer Profile

Zeeshan Elahi

2 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Chat Button For WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
buttonbtn
Data Attributes
wcbs_whatsapp_numberwcbs_button_textwcbs_messagewcbs_whatsapp_button_class
Shortcode Output
<a href="https://wa.me/?text=Chat with us</a>
FAQ

Frequently Asked Questions about Chat Button For WooCommerce