
Form to Chat App ⚡️ Security & Risk Analysis
wordpress.org/plugins/form-to-chatAdd a beautiful form widget & receive responses from customers on chat apps like WhatsApp.
Is Form to Chat App ⚡️ Safe to Use in 2026?
Mostly Safe
Score 76/100Form to Chat App ⚡️ is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The 'form-to-chat' plugin v1.2.5 demonstrates several positive security practices, including a low total number of entry points and a high percentage of properly escaped output. It also utilizes prepared statements for all SQL queries and includes nonce and capability checks on most of its interaction points. However, the presence of two known CVEs, with one currently unpatched, is a significant concern. The common vulnerability type of Cross-Site Scripting (XSS) indicated by the historical CVEs suggests that user-supplied data may not always be handled securely, even with the otherwise good output escaping practices seen in the static analysis. The lack of any taint analysis results could indicate a limited scope of analysis or that no critical flaws were found in the analyzed flows, but it doesn't negate the historical XSS issues.
While the static analysis shows a relatively clean codebase with no dangerous functions, file operations, or direct SQL injection risks, the historical vulnerability data, particularly the unpatched XSS vulnerability, elevates the overall risk profile. The plugin appears to have a history of XSS issues, and the fact that one remains unpatched is a direct and present danger to WordPress sites using this version. The plugin has a good foundation in some security aspects, but the unresolved vulnerability history demands caution.
Key Concerns
- Unpatched CVE
- Historical CVEs indicating XSS
Form to Chat App ⚡️ Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Form to Chat App <= 1.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Form to Chat App <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Form to Chat App ⚡️ Code Analysis
Output Escaping
Form to Chat App ⚡️ Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Form to Chat App ⚡️ Maintenance & Trust
Maintenance Signals
Community Trust
Form to Chat App ⚡️ Alternatives
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Social Chat – Click To Chat App Button
wp-whatsapp-chat
WhatsApp Chat🔥 allows you to enhance customer engagement! Integrate "WhatsApp" or "WhatsApp Business" with a single click.
WP Chat App
wp-whatsapp
Integrate WhatsApp experience directly into your WordPress website.
OneClick Chat to Order
oneclick-whatsapp-order
Transform your WooCommerce store with seamless WhatsApp integration. Enable customers to order products instantly via WhatsApp with enhanced features.
Contact Form to Chat Apps | Click to Chat to Order – FormyChat
social-contact-form
Connect contact forms and WooCommerce to WhatsApp by live click to chat. Send form data to WhatsApp Business for instant customer engagement
Form to Chat App ⚡️ Developer Profile
2 plugins · 3K total installs
How We Detect Form to Chat App ⚡️
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/form-to-chat/whatsform-logo.pngHTML / DOM Fingerprints
noticelogodata-whatsform-id<iframe src="https://whatsform.com/" width="" height="" frameBorder="0" allowfullscreen ></iframe>