
Click To Email – Chat Bubble & Mail Button for WP Security & Risk Analysis
wordpress.org/plugins/click-to-mailAdd a "Click to Mail" bubble to your site—let visitors email you in 3 clicks with custom subject, body, CC/BCC, and timezone-based availability.
Is Click To Email – Chat Bubble & Mail Button for WP Safe to Use in 2026?
Generally Safe
Score 100/100Click To Email – Chat Bubble & Mail Button for WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "click-to-mail" plugin v1.2.10 exhibits a generally good security posture, with all identified entry points (AJAX handlers and shortcodes) having proper authentication and permission checks. The code analysis shows a low number of SQL queries, with a majority utilizing prepared statements, and a high percentage of properly escaped outputs, indicating good defensive coding practices. The absence of file operations and external HTTP requests also reduces the potential attack surface. Furthermore, the plugin has no recorded vulnerabilities or CVEs, suggesting a history of stable and secure development.
Despite the positive indicators, a single critical "dangerous function" identified in the code analysis (unserialize) warrants attention. While no taint flows directly exploit this function in the provided analysis, its presence introduces a theoretical risk. If user-supplied data is ever passed to `unserialize` without strict validation, it could lead to object injection vulnerabilities. The plugin's lack of vulnerability history is reassuring but does not completely negate the inherent risks associated with potentially insecure functions. Overall, the plugin is reasonably secure, but the `unserialize` function represents a potential area for improvement and closer monitoring.
Key Concerns
- Presence of unserialize function
Click To Email – Chat Bubble & Mail Button for WP Security Vulnerabilities
Click To Email – Chat Bubble & Mail Button for WP Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Click To Email – Chat Bubble & Mail Button for WP Attack Surface
AJAX Handlers 7
Shortcodes 1
WordPress Hooks 37
Maintenance & Trust
Click To Email – Chat Bubble & Mail Button for WP Maintenance & Trust
Maintenance Signals
Community Trust
Click To Email – Chat Bubble & Mail Button for WP Alternatives
WP Mailto Links – Protect Email Addresses
wp-mailto-links
Protect & encode email addresses safely from spambots & spamming. Easy to use - encodes emails out-of-the-box.
Contact Form 7 to Mailjet
cf7-to-mailjet
Link Contact Form 7 with Mailjet contact list
DBD Mailto Encoder
dbd-mailto-encoder
Spam is one of the most frustrating things about the internet.
wk-email-antibot
wk-email-antibot
Simply enables WordPress shortcode for easily letting you camouflage an email address, hiding it from crawling spiders and bots.
Hellodialog
hellodialog
Wordpress plugin to include opt-in forms for Hellodialog's email marketing application.
Click To Email – Chat Bubble & Mail Button for WP Developer Profile
7 plugins · 710 total installs
How We Detect Click To Email – Chat Bubble & Mail Button for WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/click-to-mail/assets/css/style.css/wp-content/plugins/click-to-mail/assets/js/click-to-mail.js/wp-content/plugins/click-to-mail/view/blocks/build/index.js/wp-content/plugins/click-to-mail/view/blocks/build/index.asset.php/wp-content/plugins/click-to-mail/assets/js/click-to-mail.js/wp-content/plugins/click-to-mail/view/blocks/build/index.jsclick-to-mail/assets/css/style.css?ver=click-to-mail/assets/js/click-to-mail.js?ver=click-to-mail/view/blocks/build/index.js?ver=HTML / DOM Fingerprints
ctm-chat-bubblectm-chat-bodyctm-chat-inputctm-chat-send-btnctm-chat-avatarctm-chat-messagectm-chat-responsectm-chat-user+2 moredata-ctm-iddata-ctm-typedata-ctm-textdata-ctm-emaildata-ctm-subjectdata-ctm-body+3 morectm_init_chat_bubbles[click_to_mail_chat_bubble][click_to_mail_button]