
Floating Contact Button for MAX and Telegram Security & Risk Analysis
wordpress.org/plugins/floating-contact-button-for-max-and-telegramA lightweight floating contact button for WordPress with support for Telegram, WhatsApp, Facebook Messenger and MAX.
Is Floating Contact Button for MAX and Telegram Safe to Use in 2026?
Generally Safe
Score 100/100Floating Contact Button for MAX and Telegram has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "floating-contact-button-for-max-and-telegram" plugin version 1.1.1 reveals a generally strong security posture. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events without proper authorization checks indicates a minimal attack surface. Furthermore, the code signals show no dangerous functions, no raw SQL queries, and a high percentage of properly escaped output, all positive indicators. The presence of capability checks further strengthens the security framework.
Taint analysis also shows no flows with unsanitized paths, and the vulnerability history is clean, with zero known CVEs. This suggests the plugin has been developed with security in mind and has not historically presented significant security risks. However, the complete absence of nonce checks is a notable omission. While the current configuration might not expose this weakness due to the lack of interactive entry points, it represents a potential area for future risk if the plugin's functionality evolves to include user-interactive features that could be exploited through cross-site request forgery.
In conclusion, the plugin currently exhibits excellent security practices. The lack of identified vulnerabilities and a tightly controlled attack surface are commendable. The primary concern is the absence of nonce checks, which, while not currently exploitable, should be addressed to ensure future-proofing and robust defense against potential cross-site request forgery attacks if the plugin's features expand.
Key Concerns
- Missing Nonce Checks
Floating Contact Button for MAX and Telegram Security Vulnerabilities
Floating Contact Button for MAX and Telegram Code Analysis
Output Escaping
Floating Contact Button for MAX and Telegram Attack Surface
WordPress Hooks 7
Maintenance & Trust
Floating Contact Button for MAX and Telegram Maintenance & Trust
Maintenance Signals
Community Trust
Floating Contact Button for MAX and Telegram Alternatives
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Contactus
contactus
Free website widget for chatting with your visitors via WhatsApp, Facebook Messenger, Viber and Telegram.
Floating Contact Buttons
degx-floating-buttons
Add customizable WhatsApp and Phone floating buttons to your WordPress website.
Push Anything To Social
phongmy-push-anything-to-social
This's plugins help Owner push order from Woocommerce to Facebook messenger quickly base On CallmeBot API
SmartLink Chatbox
smartlink-chatbox
Add floating chat buttons for WhatsApp, Telegram, Phone, and custom links. Fully customizable, lightweight, and responsive.
Floating Contact Button for MAX and Telegram Developer Profile
1 plugin · 600 total installs
How We Detect Floating Contact Button for MAX and Telegram
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/floating-contact-button-for-max-and-telegram/assets/css/admin.css/wp-content/plugins/floating-contact-button-for-max-and-telegram/assets/js/admin-sortable.js/wp-content/plugins/floating-contact-button-for-max-and-telegram/assets/js/frontend.js/wp-content/plugins/floating-contact-button-for-max-and-telegram/assets/js/admin-sortable.js/wp-content/plugins/floating-contact-button-for-max-and-telegram/assets/js/frontend.jsfloating-contact-button-for-max-and-telegram/assets/css/admin.css?ver=floating-contact-button-for-max-and-telegram/assets/js/admin-sortable.js?ver=floating-contact-button-for-max-and-telegram/assets/js/frontend.js?ver=HTML / DOM Fingerprints
max-button-adminmax-button-cardmax-button-card-contentdata-button