
Joinchat Security & Risk Analysis
wordpress.org/plugins/creame-whatsapp-meWhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Is Joinchat Safe to Use in 2026?
Generally Safe
Score 100/100Joinchat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "creame-whatsapp-me" plugin v6.0.10 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and generally escaping output effectively (90%). The absence of known historical vulnerabilities and critical taint flows is also encouraging. However, significant concerns arise from its attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks. This creates a substantial risk of unauthorized actions being performed by unauthenticated users. While there are nonce and capability checks present, their effectiveness is negated if the entry points themselves are not protected by authorization mechanisms.
The lack of historical vulnerabilities could indicate either a history of good security practices or simply a lack of past scrutiny. Given the current findings of unprotected AJAX handlers, it's crucial to assume the latter until further review. The primary weakness lies in the exposed AJAX endpoints, which represent a direct path for attackers to potentially exploit. The plugin's strengths in SQL and output handling are overshadowed by this critical oversight in its entry point security.
Key Concerns
- AJAX handlers without auth checks
- Large attack surface without auth
Joinchat Security Vulnerabilities
Joinchat Release Timeline
Joinchat Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Joinchat Attack Surface
AJAX Handlers 2
WordPress Hooks 114
Maintenance & Trust
Joinchat Maintenance & Trust
Maintenance Signals
Community Trust
Joinchat Alternatives
Floating Contact Button for MAX and Telegram
floating-contact-button-for-max-and-telegram
A lightweight floating contact button for WordPress with support for Telegram, WhatsApp, Facebook Messenger and MAX.
SmartLink Chatbox
smartlink-chatbox
Add floating chat buttons for WhatsApp, Telegram, Phone, and custom links. Fully customizable, lightweight, and responsive.
Scriptriz Smart Chat
scriptriz-smart-chat
Adds a floating WhatsApp and Telegram chat button to your WordPress website.
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
chaty
WhatsApp chat, Facebook Messenger, Telegram, TikTok, Instagram, Email, Line, WeChat Phone call, SMS, 20+ live chat icons & WhatsApp chat pop up 💬
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist
bit-assist
Floating sticky chat button for WhatsApp Chat, Facebook Messenger, Telegram, Instagram, SMS, Call, Discord chat, TikTok, Line & 30+ channels
Joinchat Developer Profile
3 plugins · 701K total installs
How We Detect Joinchat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/creame-whatsapp-me/admin/css/joinchat-onboard.css/wp-content/plugins/creame-whatsapp-me/admin/css/joinchat-onboard.min.css/wp-content/plugins/creame-whatsapp-me/admin/js/joinchat-onboard.js/wp-content/plugins/creame-whatsapp-me/admin/js/joinchat-onboard.min.js/wp-content/plugins/creame-whatsapp-me/admin/img/joinchat.svg/wp-content/plugins/creame-whatsapp-me/admin/js/joinchat-onboard.js/wp-content/plugins/creame-whatsapp-me/admin/js/joinchat-onboard.min.jscreame-whatsapp-me/admin/css/joinchat-onboard.css?ver=creame-whatsapp-me/admin/css/joinchat-onboard.min.css?ver=creame-whatsapp-me/admin/js/joinchat-onboard.js?ver=creame-whatsapp-me/admin/js/joinchat-onboard.min.js?ver=HTML / DOM Fingerprints
joinchat__dialogjoinchat-headerjcadminbar<!-- phpcs:ignore -->clipPathdefspathJOINCHAT_VERSIONJOINCHAT_SLUGJOINCHAT_FILEJOINCHAT_DIRJOINCHAT_BASENAMEjc_common