
DirectChat – Floating Chat Button Security & Risk Analysis
wordpress.org/plugins/directchat-floating-buttonDirectChat is the smartest WhatsApp chat plugin for WordPress. Connect with visitors, increase sales, and provide support instantly.
Is DirectChat – Floating Chat Button Safe to Use in 2026?
Generally Safe
Score 100/100DirectChat – Floating Chat Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The directchat-floating-button plugin version 1.0.7 exhibits a strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points suggests a minimal attack surface. Furthermore, the code signals indicate the absence of dangerous functions, direct SQL queries (all use prepared statements), file operations, and external HTTP requests. This indicates a responsible approach to coding practices by the developers. The vulnerability history shows no recorded CVEs, which is a positive indicator of the plugin's overall security track record. The fact that there are no recorded vulnerabilities, let alone critical or high severity ones, suggests consistent security awareness. However, a potential concern lies in the output escaping, where 29% of outputs are not properly escaped. While not immediately exploitable without a clear attack vector, this could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is outputted without proper sanitization. Additionally, the lack of nonce and capability checks, while not necessarily a direct vulnerability given the limited attack surface, signifies a missed opportunity to implement fundamental WordPress security measures, which could be a weakness if the plugin's functionality were to expand in the future without corresponding security enhancements. Overall, the plugin is commendably secure with a clean vulnerability history and minimal attack surface, but the unescaped output represents a minor area for improvement.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
DirectChat – Floating Chat Button Security Vulnerabilities
DirectChat – Floating Chat Button Code Analysis
Output Escaping
DirectChat – Floating Chat Button Attack Surface
WordPress Hooks 4
Maintenance & Trust
DirectChat – Floating Chat Button Maintenance & Trust
Maintenance Signals
Community Trust
DirectChat – Floating Chat Button Alternatives
Animated Floating Chat Button
animated-floating-chat-button
Adds an animated floating chat button to the WordPress site, making communication easier.
TOCHAT.BE
tochat-be
Add a free WhatsApp click-to-chat button to your WordPress site. Easily connect your WhatsApp account and start chatting with customers instantly.
Chat Button Ninetyseven Infotech
chat-button-nsi
Chat Button Ninetyseven Infotech | Chat Button Ninetyseven Infotech for WordPress allows your customers to open a conversation from your website direc …
Tap Chat
tap-chat
Lightweight WhatsApp chat button with welcome bubble, working hours, page controls. GDPR-friendly, no tracking.
Watso – Basic Help Chat Button
watso-basic-chat
Lightweight and blazing-fast WhatsApp chat button for WordPress with full customization, UTM tracking, multi-agent support, and scheduling.
DirectChat – Floating Chat Button Developer Profile
1 plugin · 0 total installs
How We Detect DirectChat – Floating Chat Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/directchat-floating-button/assets/style.css/wp-content/plugins/directchat-floating-button/assets/script.js/wp-content/plugins/directchat-floating-button/assets/script.jsdirectchat-floating-button/assets/style.css?ver=directchat-floating-button/assets/script.js?ver=HTML / DOM Fingerprints
dcfbbtn-wrapperdcfbbtn-leftdcfbbtn-rightdcfbbtn-v-alldcfbbtn-v-mobiledcfbbtn-v-desktopdcfbbtn-tooltipdcfbbtn-main+2 moreid="dcfbbtn-main-box"dcfbbtn_plugin_data