Futy.io Leadbots Security & Risk Analysis

wordpress.org/plugins/futy-widget

Turn your website visitors into leads with the Futy Leadbot: WhatsApp Chat, E-mail Form, Request Quote Chatbot, Phone button, Callback request, Contac …

2K active installs v2.0.10 PHP 5.6+ WP 1.5.1+ Updated Feb 20, 2025
chatbotleadbotwhatsappwhatsapp-businesswhatsapp-support
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Futy.io Leadbots Safe to Use in 2026?

Generally Safe

Score 92/100

Futy.io Leadbots has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The futy-widget plugin v2.0.10 exhibits a generally strong security posture based on the provided static analysis. The absence of any detectable AJAX handlers, REST API routes, shortcodes, or cron events with exposed entry points is a significant strength, minimizing the potential attack surface. Furthermore, the plugin demonstrates good coding practices by utilizing prepared statements for all SQL queries and a high percentage (89%) of properly escaped output, which mitigates common injection and cross-site scripting vulnerabilities. The presence of nonce and capability checks, while minimal, indicates an awareness of WordPress security best practices.

However, a notable concern arises from the taint analysis, which revealed two flows with unsanitized paths. While these flows did not reach a critical or high severity in the provided analysis, unsanitized paths are a potential indicator of vulnerabilities, especially if they involve user-supplied input. The two external HTTP requests also represent a potential risk, as they could be exploited if the target servers are compromised or if the plugin does not properly validate the responses. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting a mature and well-maintained codebase, but it's important to remember that past security is not a guarantee of future security.

In conclusion, futy-widget v2.0.10 appears to be a relatively secure plugin due to its limited attack surface and good input/output handling. The primary area for caution lies in the identified unsanitized paths in the taint analysis, which warrant further investigation to ensure they do not pose a risk. The external HTTP requests are a minor concern that should be monitored. The plugin's clean vulnerability history is a testament to its developers' diligence.

Key Concerns

  • Unsanitized paths in taint analysis
  • External HTTP requests present
Vulnerabilities
None known

Futy.io Leadbots Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Futy.io Leadbots Release Timeline

v2.0.10Current
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.2.0
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Futy.io Leadbots Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
25 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

89% escaped28 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
options_page_render (admin\settings.php:16)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Futy.io Leadbots Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedfuty-widget.php:58
actionadmin_menufuty-widget.php:59
actionplugins_loadedfuty-widget.php:60
actionadmin_enqueue_scriptsfuty-widget.php:61
actionwp_footerfuty-widget.php:64
Maintenance & Trust

Futy.io Leadbots Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 20, 2025
PHP min version5.6
Downloads18K

Community Trust

Rating100/100
Number of ratings21
Active installs2K
Developer Profile

Futy.io Leadbots Developer Profile

futy

1 plugin · 2K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Futy.io Leadbots

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/futy-widget/assets/css/admin.css
Script Paths
/wp-content/plugins/futy-widget/assets/js/futy-io.min.js/wp-content/plugins/futy-widget/assets/js/futy-widget.min.js
Version Parameters
futy-widget/assets/css/admin.css?ver=futy-widget/assets/js/futy-io.min.js?ver=futy-widget/assets/js/futy-widget.min.js?ver=

HTML / DOM Fingerprints

JS Globals
data
FAQ

Frequently Asked Questions about Futy.io Leadbots