
Contact Group Button Security & Risk Analysis
wordpress.org/plugins/contact-group-buttonAdd group contact phone, sms, facebook messages, zalo... to website. Display in desktop, laptop, table, phone and more.
Is Contact Group Button Safe to Use in 2026?
Generally Safe
Score 85/100Contact Group Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "contact-group-button" v1.0.0 plugin exhibits a generally good security posture based on the provided static analysis, with no identified attack surface through AJAX handlers, REST API routes, shortcodes, or cron events. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its security. Notably, all SQL queries are using prepared statements, which is a strong indicator of secure database interaction. However, a significant concern arises from the complete lack of output escaping for all identified output points. This means that any data rendered by the plugin could potentially be exploited for cross-site scripting (XSS) attacks if that data originates from an untrusted source or user input. The plugin's vulnerability history is also clean, with no recorded CVEs, which is a positive sign. Despite the lack of immediate critical vulnerabilities, the unescaped output presents a clear and present risk that requires immediate attention. The plugin's strengths lie in its limited attack surface and secure database practices, but its weakness in output sanitization is a critical oversight.
Key Concerns
- Output not properly escaped
Contact Group Button Security Vulnerabilities
Contact Group Button Code Analysis
Output Escaping
Contact Group Button Attack Surface
WordPress Hooks 4
Maintenance & Trust
Contact Group Button Maintenance & Trust
Maintenance Signals
Community Trust
Contact Group Button Alternatives
Mobile Contact Line
mobile-contact-line
Simple plugin that allow you add mobile contact line to your wordpress site
AMP
amp
An easier path to great Page Experience for everyone. Powered by AMP.
Max Mega Menu
megamenu
An easy to use mega menu plugin. Written the WordPress way.
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
AMP for WP – Accelerated Mobile Pages
accelerated-mobile-pages
AMP for WP is the most recommended AMP plugin by the community. Automatically add Accelerated Mobile Pages (Google AMP Project) functionality on your …
Contact Group Button Developer Profile
1 plugin · 20 total installs
How We Detect Contact Group Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-group-button/assets/css/contact-group-button-admin.css/wp-content/plugins/contact-group-button/assets/css/contact-group-button.css/wp-content/plugins/contact-group-button/assets/css/font-awesome.min.css/wp-content/plugins/contact-group-button/assets/js/contact-group-button-admin.js/wp-content/plugins/contact-group-button/assets/js/drag-contact-group-button.js/wp-content/plugins/contact-group-button/assets/js/contact-group-button-admin.js/wp-content/plugins/contact-group-button/assets/js/drag-contact-group-button.jscontact-group-button/style.css?ver=contact-group-button/script.js?ver=HTML / DOM Fingerprints
p-group-contact-button-container<!-- Start --><!-- End --><!-- Contact Group Button --><!-- Contact Group Button -->contact-group-button-text-1contact-group-button-text-2contact-group-button-textcolourmepp_options