
Chat Plus – Unofficial Addon to disable chat on page and more Security & Risk Analysis
wordpress.org/plugins/chat-plusUnofficial Addon for Facebook Customer Chat. Added useful functions including disable chat in some pages, css class for CTA button to show chat, auto …
Is Chat Plus – Unofficial Addon to disable chat on page and more Safe to Use in 2026?
Generally Safe
Score 85/100Chat Plus – Unofficial Addon to disable chat on page and more has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'chat-plus' plugin version 0.1 exhibits a mixed security posture. On the positive side, it has a very small attack surface, with only one shortcode and no AJAX handlers or REST API routes. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all its SQL queries and performing capability checks. The absence of any recorded vulnerabilities in its history is also a strong indicator of a well-maintained or less-targeted plugin. However, the static analysis reveals a significant concern regarding output escaping. With only 22% of its outputs properly escaped, there's a high likelihood of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered directly without proper sanitization. This is the primary weakness in an otherwise seemingly secure plugin.
Given the limited scope of the analysis (zero taint flows) and the absence of known CVEs, it's difficult to definitively assess critical vulnerabilities. However, the low percentage of properly escaped output presents a tangible risk. The plugin has a single entry point (shortcode) with no explicit mention of authentication or capability checks for it, which could be a latent risk depending on its functionality. The presence of a nonce check is positive, but its scope and effectiveness are not detailed.
In conclusion, 'chat-plus' v0.1 shows promise with its minimal attack surface, secure SQL practices, and lack of vulnerability history. The crucial area for improvement and a significant risk factor is the inadequate output escaping. Addressing this would greatly enhance the plugin's overall security. Further investigation into the shortcode's implementation and the context of its output escaping would be beneficial.
Key Concerns
- Low percentage of properly escaped output
Chat Plus – Unofficial Addon to disable chat on page and more Security Vulnerabilities
Chat Plus – Unofficial Addon to disable chat on page and more Code Analysis
Output Escaping
Chat Plus – Unofficial Addon to disable chat on page and more Attack Surface
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
Chat Plus – Unofficial Addon to disable chat on page and more Maintenance & Trust
Maintenance Signals
Community Trust
Chat Plus – Unofficial Addon to disable chat on page and more Alternatives
Cresta Social Messenger
cresta-facebook-messenger
Allow your users and customers to contact you via Facebook Messenger with a single click.
Leaddevs Messenger Live Chatbot
leaddevs-chatbot
Leaddevs Messenger Live Chatbot
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
chaty
WhatsApp chat, Facebook Messenger, Telegram, TikTok, Instagram, Email, Line, WeChat Phone call, SMS, 20+ live chat icons & WhatsApp chat pop up 💬
Facebook Chat Plugin – Live Chat Plugin for WordPress
facebook-messenger-customer-chat
The Facebook Chat Plugin makes it easy for your website visitors to chat with you and ask you questions, even if they don't have Messenger.
Chat Plus – Unofficial Addon to disable chat on page and more Developer Profile
1 plugin · 0 total installs
How We Detect Chat Plus – Unofficial Addon to disable chat on page and more
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/chat-plus/style.css/wp-content/plugins/chat-plus/scripts/js.cookie.min.js/wp-content/plugins/chat-plus/script.js/wp-content/plugins/chat-plus/style.css?ver=/wp-content/plugins/chat-plus/scripts/js.cookie.min.js?ver=/wp-content/plugins/chat-plus/script.js?ver=HTML / DOM Fingerprints
fbcp-cta-buttonfbcp-messenger-logofbcp-open-chatfbcp_variables<button class="fbcp-cta-button"><a class="fbcp-messenger-logo fbcp-open-chat" href="/"><img src="