Click n Chat (Chat Widget Integration) Security & Risk Analysis

wordpress.org/plugins/click-n-chat

All-in-one floating chat widget with social platforms, smart auto replies, AI chatbot integration, analytics tracking, and full customization.

0 active installs v1.1.0 PHP 5.6.4+ WP 5.0+ Updated Unknown
chat-widgetclick-to-chatlive-chatsocial-chatwhatsapp-chat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Click n Chat (Chat Widget Integration) Safe to Use in 2026?

Generally Safe

Score 100/100

Click n Chat (Chat Widget Integration) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'click-n-chat' v1.1.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding output escaping, with 100% of outputs properly escaped, and it has no known historical vulnerabilities. The majority of SQL queries utilize prepared statements, which is a strong defense against SQL injection. However, there are notable areas of concern stemming from the static analysis. The presence of two AJAX handlers without authentication checks creates a significant attack surface, especially considering the taint analysis revealed two flows with unsanitized paths, which could potentially be triggered through these unprotected entry points. While there are no critical or high severity taint flows explicitly stated, the combination of unsanitized paths and unprotected AJAX endpoints warrants caution.

The lack of any recorded CVEs is a positive indicator, suggesting the plugin has historically been relatively secure. However, this does not negate the risks identified in the current version's code. The plugin's strengths lie in its robust output handling and SQL practices. Its weaknesses are primarily in the insufficient authentication for certain AJAX endpoints and the identified unsanitized path flows, which represent direct opportunities for attackers. Therefore, while the plugin has some good security foundations, the identified vulnerabilities in its attack surface and data handling introduce moderate risks.

Key Concerns

  • AJAX handlers without auth checks
  • Flows with unsanitized paths
Vulnerabilities
None known

Click n Chat (Chat Widget Integration) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Click n Chat (Chat Widget Integration) Code Analysis

Dangerous Functions
0
Raw SQL Queries
19
26 prepared
Unescaped Output
1
864 escaped
Nonce Checks
16
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

58% prepared45 total queries

Output Escaping

100% escaped865 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

10 flows2 with unsanitized paths
click_n_chat_update_lead_list_action_handler (admin\ajax\click_n_chat_ajax_lead_list.php:6)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Click n Chat (Chat Widget Integration) Attack Surface

Entry Points19
Unprotected2

AJAX Handlers 18

authwp_ajax_click_n_chat_update_lead_list_actionadmin\ajax\click_n_chat_ajax_lead_list.php:65
noprivwp_ajax_click_n_chat_update_lead_list_actionadmin\ajax\click_n_chat_ajax_lead_list.php:66
authwp_ajax_click_n_chat_update_lead_list_export_actionadmin\ajax\click_n_chat_ajax_lead_list_export.php:58
noprivwp_ajax_click_n_chat_update_lead_list_export_actionadmin\ajax\click_n_chat_ajax_lead_list_export.php:59
authwp_ajax_click_n_chat_update_suggestions_actionadmin\ajax\click_n_chat_ajax_update_suggestions.php:28
noprivwp_ajax_click_n_chat_update_suggestions_actionadmin\ajax\click_n_chat_ajax_update_suggestions.php:29
authwp_ajax_click_n_chat_update_matching_percenage_actionadmin\ajax\click_n_chat_ajax_user_update_matching_percenage.php:21
noprivwp_ajax_click_n_chat_update_matching_percenage_actionadmin\ajax\click_n_chat_ajax_user_update_matching_percenage.php:22
authwp_ajax_click_n_chat_update_user_position_actionadmin\ajax\click_n_chat_ajax_user_update_position.php:28
noprivwp_ajax_click_n_chat_update_user_position_actionadmin\ajax\click_n_chat_ajax_user_update_position.php:29
authwp_ajax_click_n_chat_update_user_status_actionadmin\ajax\click_n_chat_ajax_user_update_status.php:26
noprivwp_ajax_click_n_chat_update_user_status_actionadmin\ajax\click_n_chat_ajax_user_update_status.php:27
authwp_ajax_click_n_chat_get_ai_actionincludes\ajax\click_n_chat_ajax_get_ai_reply.php:82
noprivwp_ajax_click_n_chat_get_ai_actionincludes\ajax\click_n_chat_ajax_get_ai_reply.php:83
authwp_ajax_click_n_chat_get_auto_reply_actionincludes\ajax\click_n_chat_ajax_get_auto_reply.php:75
noprivwp_ajax_click_n_chat_get_auto_reply_actionincludes\ajax\click_n_chat_ajax_get_auto_reply.php:76
authwp_ajax_click_n_chat_update_lead_actionincludes\ajax\click_n_chat_ajax_update_lead.php:41
noprivwp_ajax_click_n_chat_update_lead_actionincludes\ajax\click_n_chat_ajax_update_lead.php:42

Shortcodes 1

[cnc_chatbot_widget] includes\parts\click_n_chat_widget.php:15
WordPress Hooks 6
actionadmin_menuadmin\includes\click_n_chat_menu.php:17
actionadmin_enqueue_scriptsadmin\includes\click_n_chat_menu.php:18
actionwp_enqueue_scriptsincludes\parts\click_n_chat_analytics.php:9
actionwp_footerincludes\parts\click_n_chat_popup.php:9
actionwp_enqueue_scriptsincludes\parts\click_n_chat_popup.php:10
actionwidgets_initincludes\parts\click_n_chat_widget.php:159
Maintenance & Trust

Click n Chat (Chat Widget Integration) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version5.6.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Click n Chat (Chat Widget Integration) Developer Profile

Adeel Abbasi

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Click n Chat (Chat Widget Integration)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/click-n-chat/admin/assets/css/simple-line-icons.css/wp-content/plugins/click-n-chat/admin/assets/css/admin-style.css/wp-content/plugins/click-n-chat/admin/assets/css/intlTelInput.min.css/wp-content/plugins/click-n-chat/assets/images/cnccalliconsmall20.png/wp-content/plugins/click-n-chat/assets/images/cncsicon.png
Version Parameters
click-n-chat/admin/assets/css/simple-line-icons.css?ver=click-n-chat/admin/assets/css/admin-style.css?ver=click-n-chat/admin/assets/css/intlTelInput.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
cnc-headercnc-header-titlecnc-nav-tabnav-tab-is-activecnc-tab-content
Data Attributes
data-nonce="activate-app"
JS Globals
CLICK_N_CHAT_DIR_URL
FAQ

Frequently Asked Questions about Click n Chat (Chat Widget Integration)