
Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Security & Risk Analysis
wordpress.org/plugins/chat-viberUnlimited customer support tool that allows visitors to engage using Viber.
Is Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Safe to Use in 2026?
Generally Safe
Score 99/100Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode has a strong security track record. Known vulnerabilities have been patched promptly.
The 'chat-viber' plugin version 1.7.10 demonstrates a generally good security posture with robust implementation of access controls and output sanitization. The static analysis reveals a significant number of capability checks and nonce checks, indicating a proactive approach to securing entry points. The high percentage of properly escaped outputs further mitigates the risk of Cross-Site Scripting (XSS) vulnerabilities. Taint analysis shows no identified flows with unsanitized paths, which is a very positive sign regarding the handling of potentially malicious input.
However, the presence of the `unserialize` function is a notable concern. While not directly flagged as vulnerable in the static or taint analysis, `unserialize` is inherently risky when processing untrusted data, as it can lead to object injection vulnerabilities if not handled with extreme care. The plugin's history includes one medium-severity CVE related to XSS, which, although currently patched, highlights a past weakness in input sanitization or output encoding. The fact that the last vulnerability was in early 2025 suggests it's a relatively recent issue and might indicate a pattern of previously overlooked vulnerabilities.
Overall, the plugin has a strong foundation in security best practices. The primary area of caution lies in the `unserialize` function, which should be carefully reviewed for potential misuse. The historical CVE, while patched, serves as a reminder to maintain vigilance, especially concerning input handling and output escaping.
Key Concerns
- Presence of 'unserialize' function
- One past medium CVE (XSS)
Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Attack Surface
AJAX Handlers 7
Shortcodes 1
WordPress Hooks 53
Maintenance & Trust
Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Alternatives
Chat Floating Button BY XD
chat-floating-button-by-xd
Floating button for chatting with your visitors via WhatsApp.
TalkJS
talkjs
Launch production-ready chat in minutes with a powerful API, feature-rich SDKs, and a fully customizable design.
Paldesk – Live Chat & Helpdesk
paldesk-live-chat-helpdesk
Powerful live chat & helpdesk plugin made for your WordPress website. Convert leads to sales & help customers in real time - it's free!
Simple Chat Bot
simple-chat-bot
A user-friendly chatbot plugin for WordPress that enables seamless communication with your visitors via WhatsApp.
Simple Contact Button
simple-contact-button
Simple Contact Button: Add a customizable contact button to your website, allowing visitors to connect with you instantly and easily.
Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Developer Profile
7 plugins · 710 total installs
How We Detect Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/chat-viber/admin/assets/css/style.css/wp-content/plugins/chat-viber/admin/assets/js/script.js/wp-content/plugins/chat-viber/inc/assets/css/chat-viber-style.css/wp-content/plugins/chat-viber/inc/assets/js/chat-viber.js/wp-content/plugins/chat-viber/admin/assets/js/script.js/wp-content/plugins/chat-viber/inc/assets/js/chat-viber.jschat-viber/inc/assets/css/chat-viber-style.css?ver=chat-viber/inc/assets/js/chat-viber.js?ver=chat-viber/admin/assets/css/style.css?ver=chat-viber/admin/assets/js/script.js?ver=HTML / DOM Fingerprints
viber-chat-supportchat-viber-get-pro-textCannot access directly.data-viber-chat-support