
FCChat Widget Security & Risk Analysis
wordpress.org/plugins/fcchatAn interface for real time chat, video conferencing, instant messaging, and more.
Is FCChat Widget Safe to Use in 2026?
Mostly Safe
Score 83/100FCChat Widget is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The fcchat plugin v3.8.6.6 exhibits a mixed security posture. While it demonstrates good practices in areas such as avoiding raw SQL queries and having a seemingly small attack surface with no exposed entry points, significant concerns arise from the code analysis.
The static analysis reveals a very low percentage (3%) of properly escaped output, suggesting a high likelihood of cross-site scripting (XSS) vulnerabilities. Furthermore, all identified taint flows involve unsanitized paths, indicating that user-supplied data is not being properly validated or neutralized before being used in potentially sensitive operations. The presence of 15 file operations without clear security context in the provided data is also a point of concern.
The vulnerability history is particularly alarming. The existence of a past critical vulnerability classified as 'Unrestricted Upload of File with Dangerous Type' is a serious red flag. Although there are currently no unpatched CVEs, the nature of the past vulnerability, coupled with the taint analysis findings, suggests a potential for similar issues if not mitigated. The outdated bundled jQuery library (v1.2.6) is another weakness, as older library versions often contain known security flaws.
In conclusion, while the plugin has some strengths, the prevalent output escaping issues, unsanitized taint flows, and the history of a critical vulnerability point to a significant risk. The lack of demonstrated capability checks on potential entry points (despite zero identified entry points) and the outdated bundled library further exacerbate these concerns, requiring careful consideration and potential remediation.
Key Concerns
- Low output escaping percentage
- Taint flows with unsanitized paths
- Bundled outdated jQuery library
- Past critical vulnerability (Unrestricted Upload)
- Presence of file operations without clear sanitization context
FCChat Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
FCChat Widget < 2.2.13.7 - Arbitrary File Upload
FCChat Widget Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
FCChat Widget Attack Surface
WordPress Hooks 6
Maintenance & Trust
FCChat Widget Maintenance & Trust
Maintenance Signals
Community Trust
FCChat Widget Alternatives
GTChatPro Live Chat Plugin
gtchatpro
Convert Your Leads To Customers Seamlessly
Tawk.To Live Chat
tawkto-live-chat
(OFFICIAL tawk.to plugin) Instantly chat with visitors on your website with the free tawk.to chat widget. Website: http://tawk.to
LeadConnector
leadconnector
LeadConnector: It helps you to add the LeadConnector chat widget and the LeadConnector funnel pages to your WordPress website.
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist
bit-assist
Floating sticky chat button for WhatsApp Chat, Facebook Messenger, Telegram, Instagram, SMS, Call, Discord chat, TikTok, Line & 30+ channels
Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons
sticky-chat-widget
Social chat buttons with WhatsApp, Messenger, WeChat, Telegram, Instagram, TikTok, Zalo & more — plus SMS, Call button, Contact form, and 20+ icons.
FCChat Widget Developer Profile
2 plugins · 20 total installs
How We Detect FCChat Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fcchat/js/import.google.loader.js/wp-content/plugins/fcchat/js/import.config.alt.php/wp-content/plugins/fcchat/js/import.libs.js/wp-content/plugins/fcchat/js/import.includes.js/wp-content/plugins/fcchat/js/install.prep.js/wp-content/plugins/fcchat/js/embed.js/wp-content/plugins/fcchat/js/import.google.loader.js/wp-content/plugins/fcchat/js/import.config.alt.php/wp-content/plugins/fcchat/js/import.libs.js/wp-content/plugins/fcchat/js/import.includes.js/wp-content/plugins/fcchat/js/install.prep.js/wp-content/plugins/fcchat/js/embed.jsHTML / DOM Fingerprints
FCChatConfiggetObjsetOptionmergeOptionmergeBlockgetCSSProp<div id="fc_package"><script type="text/javascript" src=""></script><script type="text/javascript" ></script></div><script type="text/javascript" src=""></script>