
Hello24 – Order on Chat, Abandoned cart recovery & Marketing Automation Security & Risk Analysis
wordpress.org/plugins/hello24-order-on-chat-abandoned-cart-recovery-marketing-automationGain 5X more revenue by Abandoned cart recovery, Add Chat Button, Marketing automation, Resell/Upsell/Cross-sell using Whatsapp API
Is Hello24 – Order on Chat, Abandoned cart recovery & Marketing Automation Safe to Use in 2026?
Generally Safe
Score 100/100Hello24 – Order on Chat, Abandoned cart recovery & Marketing Automation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hello24-order-on-chat-abandoned-cart-recovery-marketing-automation" plugin version 1.6.9 presents a mixed security posture. While a significant majority of SQL queries are protected by prepared statements and all output is properly escaped, several critical areas raise concerns. The presence of 8 AJAX handlers without authentication checks and one REST API route lacking permission callbacks represent substantial attack vectors that could be exploited by unauthenticated users.
Furthermore, the static analysis identified the use of the `unserialize` function, which is a known source of vulnerabilities when dealing with untrusted input. Although taint analysis did not reveal critical or high severity unsanitized flows, the potential for serialized data exploitation remains a significant risk. The plugin's vulnerability history is clean, indicating a lack of publicly known exploits or past issues, which is positive. However, this does not mitigate the risks identified in the current code analysis.
In conclusion, while the plugin demonstrates good practices in areas like output escaping and prepared statements, the substantial number of unprotected entry points (AJAX and REST API) and the presence of `unserialize` create a notable risk profile. The absence of historical vulnerabilities is encouraging, but proactive mitigation of the identified code weaknesses is essential to ensure the plugin's security.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Dangerous function unserialize used
- No Nonce checks on AJAX
- Limited capability checks
Hello24 – Order on Chat, Abandoned cart recovery & Marketing Automation Security Vulnerabilities
Hello24 – Order on Chat, Abandoned cart recovery & Marketing Automation Release Timeline
Hello24 – Order on Chat, Abandoned cart recovery & Marketing Automation Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Hello24 – Order on Chat, Abandoned cart recovery & Marketing Automation Attack Surface
AJAX Handlers 8
REST API Routes 32
WordPress Hooks 45
Maintenance & Trust
Hello24 – Order on Chat, Abandoned cart recovery & Marketing Automation Maintenance & Trust
Maintenance Signals
Community Trust
Hello24 – Order on Chat, Abandoned cart recovery & Marketing Automation Alternatives
Abandoned Checkout Recovery & Order Notifications for WooCommerce
abandoned-checkout-recovery-order-notifications-for-woocommerce
Send WhatsApp notifications for recovering abandoned carts, double confirming CoD orders and for other order & shipment updates! Also, send out yo …
Social Chat Widget (⚡ by Callbell)
callbell-chat-widget
WhatsApp free live chat button to connect and communicate with your website visitors
Spoki – Chat Buttons and WooCommerce Notifications
spoki
WhatsApp full integration for your website! Recover Abandoned Carts, send Order Notifications and add WhatsApp Buttons.
Order & Abandoned Cart Notifications for WooCommerce
order-notifications-for-woocommerce
Send WhatsApp notifications for WooCommerce orders, order status updates and abandoned cart recovery using the official WhatsApp Business API.
BusinessOnBot
businessonbot
Boosts D2C brands via WhatsApp & Instagram, maximizing user acquisition & growth through platform potential.
Hello24 – Order on Chat, Abandoned cart recovery & Marketing Automation Developer Profile
1 plugin · 10 total installs
How We Detect Hello24 – Order on Chat, Abandoned cart recovery & Marketing Automation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hello24-order-on-chat-apps/build/css/main.css/wp-content/plugins/hello24-order-on-chat-apps/build/js/app.js/wp-content/plugins/hello24-order-on-chat-apps/build/js/app.jshello24-order-on-chat-apps/build/css/main.css?ver=hello24-order-on-chat-apps/build/js/app.js?ver=HTML / DOM Fingerprints
hello24-chat-iconh24-chat-widgethello24-chat-minimize-buttonhello24-widget-wrapperhello24-chat-message-wrapperdata-h24-wcdata-h24-wphello24_dataH24Chat/wp-json/hello24/v1/settings/wp-json/hello24/v1/sync[hello24_chat_button]