DirectChat – Floating Chat Button Security & Risk Analysis

wordpress.org/plugins/directchat-floating-button

DirectChat is the smartest WhatsApp chat plugin for WordPress. Connect with visitors, increase sales, and provide support instantly.

0 active installs v1.0.7 PHP 7.4+ WP 5.0+ Updated Unknown
chat-buttonclick-to-chatfloating-chatsupportwhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DirectChat – Floating Chat Button Safe to Use in 2026?

Generally Safe

Score 100/100

DirectChat – Floating Chat Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The directchat-floating-button plugin version 1.0.7 exhibits a strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points suggests a minimal attack surface. Furthermore, the code signals indicate the absence of dangerous functions, direct SQL queries (all use prepared statements), file operations, and external HTTP requests. This indicates a responsible approach to coding practices by the developers. The vulnerability history shows no recorded CVEs, which is a positive indicator of the plugin's overall security track record. The fact that there are no recorded vulnerabilities, let alone critical or high severity ones, suggests consistent security awareness. However, a potential concern lies in the output escaping, where 29% of outputs are not properly escaped. While not immediately exploitable without a clear attack vector, this could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is outputted without proper sanitization. Additionally, the lack of nonce and capability checks, while not necessarily a direct vulnerability given the limited attack surface, signifies a missed opportunity to implement fundamental WordPress security measures, which could be a weakness if the plugin's functionality were to expand in the future without corresponding security enhancements. Overall, the plugin is commendably secure with a clean vulnerability history and minimal attack surface, but the unescaped output represents a minor area for improvement.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

DirectChat – Floating Chat Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DirectChat – Floating Chat Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
15 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped21 total outputs
Attack Surface

DirectChat – Floating Chat Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_enqueue_scriptsdirectchat.php:39
actionadmin_initdirectchat.php:55
actionadmin_menudirectchat.php:124
actionwp_footerdirectchat.php:178
Maintenance & Trust

DirectChat – Floating Chat Button Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.4
Downloads165

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

DirectChat – Floating Chat Button Developer Profile

Nitish Verma

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DirectChat – Floating Chat Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/directchat-floating-button/assets/style.css/wp-content/plugins/directchat-floating-button/assets/script.js
Script Paths
/wp-content/plugins/directchat-floating-button/assets/script.js
Version Parameters
directchat-floating-button/assets/style.css?ver=directchat-floating-button/assets/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
dcfbbtn-wrapperdcfbbtn-leftdcfbbtn-rightdcfbbtn-v-alldcfbbtn-v-mobiledcfbbtn-v-desktopdcfbbtn-tooltipdcfbbtn-main+2 more
Data Attributes
id="dcfbbtn-main-box"
JS Globals
dcfbbtn_plugin_data
FAQ

Frequently Asked Questions about DirectChat – Floating Chat Button