Fay Chat Security & Risk Analysis

wordpress.org/plugins/fay-chat

Fay Chat allows you to integrate your WhatsApp directly into your website.

0 active installs v2.0.3 PHP 7.2+ WP 5.2+ Updated May 1, 2024
chatlive-chatsocial-chatwhatsappwhatsapp-chat
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fay Chat Safe to Use in 2026?

Generally Safe

Score 92/100

Fay Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The fay-chat plugin v2.0.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, has a very high percentage of properly escaped output, and has no recorded historical vulnerabilities. This suggests a development team that is aware of common web security pitfalls and has a history of producing relatively secure code. However, a significant concern arises from its attack surface. The plugin exposes two AJAX handlers, and critically, both lack any authentication checks. This means that any unauthenticated user can trigger these functions, potentially leading to unintended actions or information disclosure depending on their implementation. The absence of taint analysis data and the lack of specific code signals like dangerous functions, file operations, or external HTTP requests are neutral indicators, as they don't explicitly show vulnerabilities but also don't confirm the absence of potential issues in areas not explicitly tested by these signals. The bundled Freemius library also warrants attention, as outdated bundled libraries can be a vector for vulnerabilities if not kept current.

In conclusion, while the plugin has a clean vulnerability history and good practices in SQL and output handling, the unprotected AJAX endpoints represent a clear and immediate risk. This could be a critical oversight that attackers can exploit. The focus should be on securing these entry points to bring the plugin's security in line with its otherwise positive code quality indicators.

Key Concerns

  • AJAX handlers without auth checks
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
None known

Fay Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Fay Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
66 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

92% escaped72 total outputs
Attack Surface
2 unprotected

Fay Chat Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_fay_chat_ajax_actioninc\ajax-call.php:5
noprivwp_ajax_fay_chat_ajax_actioninc\ajax-call.php:6
WordPress Hooks 12
actionadmin_enqueue_scriptsfay-chat.php:71
actionwp_enqueue_scriptsfay-chat.php:98
actionwp_footerfay-chat.php:279
actionwp_footerfay-chat.php:394
filterenter_title_herefay-chat.php:396
actioninitfay-chat.php:464
actionwoocommerce_after_add_to_cart_formfay-chat.php:466
actionsave_postfay-chat.php:626
actionadmin_noticesfay-chat.php:661
actionadd_meta_boxesinc\matabox\agent.php:10
actionadmin_headinc\matabox\agent.php:11
actionsave_postinc\matabox\agent.php:12
Maintenance & Trust

Fay Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 1, 2024
PHP min version7.2
Downloads832

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Fay Chat Developer Profile

fayjur

2 plugins · 0 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fay Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fay-chat/assets/css/faychat-chat.css/wp-content/plugins/fay-chat/assets/css/style.css/wp-content/plugins/fay-chat/assets/js/fontawesome-6.5.2.js
Script Paths
/wp-content/plugins/fay-chat/assets/js/fontawesome-6.5.2.js
Version Parameters
faychat-chat.css?ver=style.css?ver=fontawesome-6.5.2.js?ver=

HTML / DOM Fingerprints

CSS Classes
faychat-ayoan_whatsapp_chatbox_containerfaychat-rs-openChatfaychat-ayoan_whatsapp_chatboxfaychat-widget-wrapperfaychat-widget-headerfaychat-header-titlefaychat-header-contentfaychat-widget-body+8 more
Data Attributes
faychat_titlefaychat_descriptionfaychat_iconfaychat_coloradditional_options_phoneadditional_options_designation
FAQ

Frequently Asked Questions about Fay Chat