Inquiry Button for WooCommerce Security & Risk Analysis

wordpress.org/plugins/inquiry-button-for-woocommerce

Adds a customizable WhatsApp inquiry button to WooCommerce product pages.

50 active installs v1.1 PHP 7.4+ WP 6.3+ Updated Feb 14, 2025
buttoninquirywhatsappwoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Inquiry Button for WooCommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Inquiry Button for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of inquiry-button-for-woocommerce v1.1 reveals a plugin with a seemingly strong security posture regarding its identified attack surface. There are no AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits potential entry points for malicious actors. Furthermore, the code demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and ensuring all output is properly escaped. The absence of file operations and external HTTP requests further reduces the plugin's attack surface and potential for exploitation.

The lack of any recorded CVEs, past or present, and the absence of critical or high severity taint flows further bolster this positive assessment. This history suggests a development team that is either highly security-conscious or has not yet encountered exploitable vulnerabilities. However, the complete absence of nonce checks and capability checks is a notable concern. While the current attack surface is minimal, any future additions or changes that introduce new entry points without these fundamental security mechanisms could introduce significant risks. This oversight, despite the current minimal attack surface, is a weakness that warrants attention for maintaining robust security in the long term.

In conclusion, inquiry-button-for-woocommerce v1.1 appears to be a secure plugin based on the provided static analysis and vulnerability history, primarily due to its limited attack surface and strong adherence to secure coding practices for SQL and output. The primary weakness lies in the complete omission of nonce and capability checks, which, while not currently exploitable given the lack of entry points, represents a potential future risk if the plugin evolves.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Inquiry Button for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Inquiry Button for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
21 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped21 total outputs
Attack Surface

Inquiry Button for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuinquiry-button-for-woocommerce.php:23
actionadmin_initinquiry-button-for-woocommerce.php:24
actionwoocommerce_after_add_to_cart_buttoninquiry-button-for-woocommerce.php:25
actionwp_enqueue_scriptsinquiry-button-for-woocommerce.php:27
Maintenance & Trust

Inquiry Button for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 14, 2025
PHP min version7.4
Downloads853

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Inquiry Button for WooCommerce Developer Profile

Nimesh Gorfad

2 plugins · 50 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Inquiry Button for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/inquiry-button-for-woocommerce/css/front.css
Version Parameters
inquiry-button-for-woocommerce/css/front.css?ver=1.1

HTML / DOM Fingerprints

CSS Classes
nkg_wp_btnwhatsapp_icon
Data Attributes
name="inqubufo_whatsapp_enable"name="inqubufo_whatsapp_number"name="inqubufo_whatsapp_message"name="inqubufo_whatsapp_button_text"
FAQ

Frequently Asked Questions about Inquiry Button for WooCommerce