Form to Chat App ⚡️ Security & Risk Analysis

wordpress.org/plugins/form-to-chat

Add a beautiful form widget & receive responses from customers on chat apps like WhatsApp.

2K active installs v1.2.5 PHP 5.5+ WP 4.5+ Updated Nov 28, 2025
click-to-chatwhatsapp-form
76
B · Generally Safe
CVEs total2
Unpatched1
Last CVEJan 4, 2026
Safety Verdict

Is Form to Chat App ⚡️ Safe to Use in 2026?

Mostly Safe

Score 76/100

Form to Chat App ⚡️ is generally safe to use. 2 past CVEs were resolved. Keep it updated.

2 known CVEs 1 unpatched Last CVE: Jan 4, 2026Updated 4mo ago
Risk Assessment

The 'form-to-chat' plugin v1.2.5 demonstrates several positive security practices, including a low total number of entry points and a high percentage of properly escaped output. It also utilizes prepared statements for all SQL queries and includes nonce and capability checks on most of its interaction points. However, the presence of two known CVEs, with one currently unpatched, is a significant concern. The common vulnerability type of Cross-Site Scripting (XSS) indicated by the historical CVEs suggests that user-supplied data may not always be handled securely, even with the otherwise good output escaping practices seen in the static analysis. The lack of any taint analysis results could indicate a limited scope of analysis or that no critical flaws were found in the analyzed flows, but it doesn't negate the historical XSS issues.

While the static analysis shows a relatively clean codebase with no dangerous functions, file operations, or direct SQL injection risks, the historical vulnerability data, particularly the unpatched XSS vulnerability, elevates the overall risk profile. The plugin appears to have a history of XSS issues, and the fact that one remains unpatched is a direct and present danger to WordPress sites using this version. The plugin has a good foundation in some security aspects, but the unresolved vulnerability history demands caution.

Key Concerns

  • Unpatched CVE
  • Historical CVEs indicating XSS
Vulnerabilities
2

Form to Chat App ⚡️ Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2026-22463medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Form to Chat App <= 1.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 4, 2026Unpatched
CVE-2024-31258medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Form to Chat App <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 5, 2024 Patched in 1.1.7 (7d)
Code Analysis
Analyzed Mar 16, 2026

Form to Chat App ⚡️ Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
58 escaped
Nonce Checks
2
Capability Checks
11
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

94% escaped62 total outputs
Attack Surface

Form to Chat App ⚡️ Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_whatsform_submit_uninstall_reason_actionwhatsform.php:452

Shortcodes 1

[whatsform] whatsform.php:154
WordPress Hooks 10
actionadmin_initinpost-snippet.php:12
actionsave_postinpost-snippet.php:37
actionactivated_pluginwhatsform.php:56
actionadmin_noticeswhatsform.php:117
actionadmin_initwhatsform.php:129
actionadmin_menuwhatsform.php:215
actionadmin_initwhatsform.php:309
actionadmin_enqueue_scriptswhatsform.php:403
actionwp_headwhatsform.php:472
actionshutdownwhatsform.php:487
Maintenance & Trust

Form to Chat App ⚡️ Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version5.5
Downloads39K

Community Trust

Rating94/100
Number of ratings10
Active installs2K
Developer Profile

Form to Chat App ⚡️ Developer Profile

Micro.company

2 plugins · 3K total installs

92
trust score
Avg Security Score
88/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Form to Chat App ⚡️

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/form-to-chat/whatsform-logo.png

HTML / DOM Fingerprints

CSS Classes
noticelogo
Data Attributes
data-whatsform-id
Shortcode Output
<iframe src="https://whatsform.com/" width="" height="" frameBorder="0" allowfullscreen ></iframe>
FAQ

Frequently Asked Questions about Form to Chat App ⚡️