Chat Plus – Unofficial Addon to disable chat on page and more Security & Risk Analysis

wordpress.org/plugins/chat-plus

Unofficial Addon for Facebook Customer Chat. Added useful functions including disable chat in some pages, css class for CTA button to show chat, auto …

0 active installs v0.1 PHP 5.2.4+ WP 3.9+ Updated May 12, 2021
chatfacebookfacebook-chatfacebook-messengermessaging
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Chat Plus – Unofficial Addon to disable chat on page and more Safe to Use in 2026?

Generally Safe

Score 85/100

Chat Plus – Unofficial Addon to disable chat on page and more has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The 'chat-plus' plugin version 0.1 exhibits a mixed security posture. On the positive side, it has a very small attack surface, with only one shortcode and no AJAX handlers or REST API routes. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all its SQL queries and performing capability checks. The absence of any recorded vulnerabilities in its history is also a strong indicator of a well-maintained or less-targeted plugin. However, the static analysis reveals a significant concern regarding output escaping. With only 22% of its outputs properly escaped, there's a high likelihood of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered directly without proper sanitization. This is the primary weakness in an otherwise seemingly secure plugin.

Given the limited scope of the analysis (zero taint flows) and the absence of known CVEs, it's difficult to definitively assess critical vulnerabilities. However, the low percentage of properly escaped output presents a tangible risk. The plugin has a single entry point (shortcode) with no explicit mention of authentication or capability checks for it, which could be a latent risk depending on its functionality. The presence of a nonce check is positive, but its scope and effectiveness are not detailed.

In conclusion, 'chat-plus' v0.1 shows promise with its minimal attack surface, secure SQL practices, and lack of vulnerability history. The crucial area for improvement and a significant risk factor is the inadequate output escaping. Addressing this would greatly enhance the plugin's overall security. Further investigation into the shortcode's implementation and the context of its output escaping would be beneficial.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Chat Plus – Unofficial Addon to disable chat on page and more Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Chat Plus – Unofficial Addon to disable chat on page and more Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
2 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

22% escaped9 total outputs
Attack Surface

Chat Plus – Unofficial Addon to disable chat on page and more Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[fbcp_cta_button] chat-plus.php:129
WordPress Hooks 16
actioninitchat-plus.php:27
filterplugin_action_linkschat-plus.php:28
filterplugin_row_metachat-plus.php:30
actionplugins_loadedchat-plus.php:32
actioninitchat-plus.php:33
actionwp_enqueue_scriptschat-plus.php:34
actionadmin_noticeschat-plus.php:140
actionwp_enqueue_scriptschat-plus.php:144
actionget_headerchat-plus.php:145
actionload-post.phpmetabox.php:25
actionload-post-new.phpmetabox.php:26
actionadd_meta_boxesmetabox.php:35
actionsave_postmetabox.php:36
actionadmin_menuoptions.php:16
actionadmin_enqueue_scriptsoptions.php:37
actionadmin_initoptions.php:40
Maintenance & Trust

Chat Plus – Unofficial Addon to disable chat on page and more Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 12, 2021
PHP min version5.2.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Chat Plus – Unofficial Addon to disable chat on page and more Developer Profile

Concentric Digital

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Chat Plus – Unofficial Addon to disable chat on page and more

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chat-plus/style.css
Script Paths
/wp-content/plugins/chat-plus/scripts/js.cookie.min.js/wp-content/plugins/chat-plus/script.js
Version Parameters
/wp-content/plugins/chat-plus/style.css?ver=/wp-content/plugins/chat-plus/scripts/js.cookie.min.js?ver=/wp-content/plugins/chat-plus/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
fbcp-cta-buttonfbcp-messenger-logofbcp-open-chat
JS Globals
fbcp_variables
Shortcode Output
<button class="fbcp-cta-button"><a class="fbcp-messenger-logo fbcp-open-chat" href="/"><img src="
FAQ

Frequently Asked Questions about Chat Plus – Unofficial Addon to disable chat on page and more