Chat Without Contact Security & Risk Analysis

wordpress.org/plugins/chat-without-contact

A custom WhatsApp Web plugin that send text message without saving contact number on mobile devise. just enter mobile number and text then send throug …

0 active installs v1.0 PHP 7.2+ WP 5.2+ Updated Mar 29, 2023
message-to-unkown-contactwhatsapp-message-without-saving-the-phone-numberwhatsapp-pluginwhatsapp-without-apiwhatsapp-without-contact
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Chat Without Contact Safe to Use in 2026?

Generally Safe

Score 85/100

Chat Without Contact has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "chat-without-contact" v1.0 plugin exhibits a strong security posture based on the static analysis. The absence of dangerous functions, external HTTP requests, file operations, and the exclusive use of prepared statements for SQL queries are all positive indicators. Furthermore, 100% of output is properly escaped, and there are no recorded vulnerabilities in its history. This suggests the developers have followed good security practices.

However, the analysis does reveal a potential area of concern: the lack of any nonce or capability checks across all identified entry points. While the attack surface is currently small (one shortcode) and there are no AJAX handlers or REST API routes without authentication, this reliance on the absence of checks rather than explicit security measures presents a future risk. If the plugin's functionality were to expand or if new entry points were introduced without proper security, it could become vulnerable to various attacks.

In conclusion, the plugin is currently very secure due to its limited scope and robust coding practices. The primary weakness lies in the complete absence of explicit authorization and security checks. This is a significant oversight that, while not immediately exploitable given the current state, represents a latent risk that should be addressed in future development to ensure continued security as the plugin evolves.

Key Concerns

  • No nonce checks on any entry points
  • No capability checks on any entry points
Vulnerabilities
None known

Chat Without Contact Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Chat Without Contact Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Chat Without Contact Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wawc_form] chat-without-contact.php:28
Maintenance & Trust

Chat Without Contact Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedMar 29, 2023
PHP min version7.2
Downloads687

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Chat Without Contact Developer Profile

Sumanta

3 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Chat Without Contact

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chat-without-contact/contact-form.php
Version Parameters
chat-without-contact/style.css?ver=chat-without-contact/script.js?ver=

HTML / DOM Fingerprints

Shortcode Output
<div class="wawc-form-container">
FAQ

Frequently Asked Questions about Chat Without Contact