Desperado Product Inquiry Buttons for WooCommerce Security & Risk Analysis

wordpress.org/plugins/desperado-product-inquiry-buttons

Add WhatsApp, Viber, Telegram, SMS and Email inquiry buttons to your WooCommerce product pages.

0 active installs v1.0 PHP 7.4+ WP 5.8+ Updated Unknown
contactinquiryproductwhatsappwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Desperado Product Inquiry Buttons for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Desperado Product Inquiry Buttons for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "desperado-product-inquiry-buttons" v1.0 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, proper handling of SQL queries with prepared statements, and a high percentage of properly escaped output are strong indicators of secure coding practices. Furthermore, the lack of identified vulnerabilities in its history suggests a well-maintained and secure plugin over time.

However, there are a few areas for concern. The presence of a shortcode without any explicitly mentioned authentication or capability checks is a potential entry point that could be exploited if it interacts with user-supplied data. The static analysis also reports zero nonce checks, which is a critical security mechanism for preventing Cross-Site Request Forgery (CSRF) attacks, especially for any functionality that performs state-changing actions. While the taint analysis found no issues, the lack of comprehensive analysis flows might mean that subtle vulnerabilities could be missed.

In conclusion, while the plugin has positive security attributes, the lack of nonce checks and potential unauthenticated shortcode execution are significant weaknesses that require attention. Addressing these specific issues would further strengthen the plugin's security profile.

Key Concerns

  • Shortcode without auth checks
  • Missing nonce checks
Vulnerabilities
None known

Desperado Product Inquiry Buttons for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Desperado Product Inquiry Buttons for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
103 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped104 total outputs
Attack Surface

Desperado Product Inquiry Buttons for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[desperado_inquiry_buttons] includes\class-desperado-frontend-display.php:17
WordPress Hooks 9
actionadmin_noticesdesperado-product-inquiry-buttons.php:28
actionplugins_loadeddesperado-product-inquiry-buttons.php:56
filterkses_allowed_protocolsdesperado-product-inquiry-buttons.php:59
actionadmin_menuincludes\class-desperado-admin-settings.php:13
actionadmin_initincludes\class-desperado-admin-settings.php:14
actionadmin_enqueue_scriptsincludes\class-desperado-admin-settings.php:15
actioninitincludes\class-desperado-core.php:13
actionwp_enqueue_scriptsincludes\class-desperado-core.php:21
actionwoocommerce_single_product_summaryincludes\class-desperado-frontend-display.php:14
Maintenance & Trust

Desperado Product Inquiry Buttons for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.4
Downloads155

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Desperado Product Inquiry Buttons for WooCommerce Developer Profile

desperadohouse

4 plugins · 200 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Desperado Product Inquiry Buttons for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/desperado-product-inquiry-buttons/assets/css/admin.css/wp-content/plugins/desperado-product-inquiry-buttons/assets/js/admin.js
Script Paths
/wp-content/plugins/desperado-product-inquiry-buttons/assets/js/admin.js
Version Parameters
desperado-product-inquiry-buttons/assets/css/admin.css?ver=desperado-product-inquiry-buttons/assets/js/admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-viber-numberdata-whatsapp-numberdata-telegram-numberdata-sms-numberdata-email-addressdata-viber-button-text+11 more
JS Globals
DESPERADO_PIB_PLUGIN_URLDESPERADO_PIB_PLUGIN_VERSION
FAQ

Frequently Asked Questions about Desperado Product Inquiry Buttons for WooCommerce