Floating Contact Button for MAX and Telegram Security & Risk Analysis

wordpress.org/plugins/floating-contact-button-for-max-and-telegram

A lightweight floating contact button for WordPress with support for Telegram, WhatsApp, Facebook Messenger and MAX.

600 active installs v1.1.1 PHP 7.0+ WP 5.0+ Updated Mar 3, 2026
contact-buttonfacebook-messengerfloating-buttontelegramwhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Floating Contact Button for MAX and Telegram Safe to Use in 2026?

Generally Safe

Score 100/100

Floating Contact Button for MAX and Telegram has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The static analysis of the "floating-contact-button-for-max-and-telegram" plugin version 1.1.1 reveals a generally strong security posture. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events without proper authorization checks indicates a minimal attack surface. Furthermore, the code signals show no dangerous functions, no raw SQL queries, and a high percentage of properly escaped output, all positive indicators. The presence of capability checks further strengthens the security framework.

Taint analysis also shows no flows with unsanitized paths, and the vulnerability history is clean, with zero known CVEs. This suggests the plugin has been developed with security in mind and has not historically presented significant security risks. However, the complete absence of nonce checks is a notable omission. While the current configuration might not expose this weakness due to the lack of interactive entry points, it represents a potential area for future risk if the plugin's functionality evolves to include user-interactive features that could be exploited through cross-site request forgery.

In conclusion, the plugin currently exhibits excellent security practices. The lack of identified vulnerabilities and a tightly controlled attack surface are commendable. The primary concern is the absence of nonce checks, which, while not currently exploitable, should be addressed to ensure future-proofing and robust defense against potential cross-site request forgery attacks if the plugin's features expand.

Key Concerns

  • Missing Nonce Checks
Vulnerabilities
None known

Floating Contact Button for MAX and Telegram Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Floating Contact Button for MAX and Telegram Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
31 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped33 total outputs
Attack Surface

Floating Contact Button for MAX and Telegram Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedfloating-contact-button-for-max-and-telegram.php:22
filterplugin_row_metafloating-contact-button-for-max-and-telegram.php:55
actionadmin_menuincludes\admin.php:20
actionadmin_enqueue_scriptsincludes\admin.php:45
actionadmin_initincludes\admin.php:292
actionwp_enqueue_scriptsincludes\frontend.php:35
actionwp_footerincludes\frontend.php:165
Maintenance & Trust

Floating Contact Button for MAX and Telegram Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 3, 2026
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs600
Developer Profile

Floating Contact Button for MAX and Telegram Developer Profile

Alexander Alekseenko

1 plugin · 600 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Floating Contact Button for MAX and Telegram

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/floating-contact-button-for-max-and-telegram/assets/css/admin.css/wp-content/plugins/floating-contact-button-for-max-and-telegram/assets/js/admin-sortable.js/wp-content/plugins/floating-contact-button-for-max-and-telegram/assets/js/frontend.js
Script Paths
/wp-content/plugins/floating-contact-button-for-max-and-telegram/assets/js/admin-sortable.js/wp-content/plugins/floating-contact-button-for-max-and-telegram/assets/js/frontend.js
Version Parameters
floating-contact-button-for-max-and-telegram/assets/css/admin.css?ver=floating-contact-button-for-max-and-telegram/assets/js/admin-sortable.js?ver=floating-contact-button-for-max-and-telegram/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
max-button-adminmax-button-cardmax-button-card-content
Data Attributes
data-button
FAQ

Frequently Asked Questions about Floating Contact Button for MAX and Telegram