
Inquiry Button for WooCommerce Security & Risk Analysis
wordpress.org/plugins/inquiry-button-for-woocommerceAdds a customizable WhatsApp inquiry button to WooCommerce product pages.
Is Inquiry Button for WooCommerce Safe to Use in 2026?
Generally Safe
Score 92/100Inquiry Button for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of inquiry-button-for-woocommerce v1.1 reveals a plugin with a seemingly strong security posture regarding its identified attack surface. There are no AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits potential entry points for malicious actors. Furthermore, the code demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and ensuring all output is properly escaped. The absence of file operations and external HTTP requests further reduces the plugin's attack surface and potential for exploitation.
The lack of any recorded CVEs, past or present, and the absence of critical or high severity taint flows further bolster this positive assessment. This history suggests a development team that is either highly security-conscious or has not yet encountered exploitable vulnerabilities. However, the complete absence of nonce checks and capability checks is a notable concern. While the current attack surface is minimal, any future additions or changes that introduce new entry points without these fundamental security mechanisms could introduce significant risks. This oversight, despite the current minimal attack surface, is a weakness that warrants attention for maintaining robust security in the long term.
In conclusion, inquiry-button-for-woocommerce v1.1 appears to be a secure plugin based on the provided static analysis and vulnerability history, primarily due to its limited attack surface and strong adherence to secure coding practices for SQL and output. The primary weakness lies in the complete omission of nonce and capability checks, which, while not currently exploitable given the lack of entry points, represents a potential future risk if the plugin evolves.
Key Concerns
- Missing nonce checks
- Missing capability checks
Inquiry Button for WooCommerce Security Vulnerabilities
Inquiry Button for WooCommerce Code Analysis
Output Escaping
Inquiry Button for WooCommerce Attack Surface
WordPress Hooks 4
Maintenance & Trust
Inquiry Button for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Inquiry Button for WooCommerce Alternatives
Animated Floating Chat Button
animated-floating-chat-button
Adds an animated floating chat button to the WordPress site, making communication easier.
Spoki – Chat Buttons and WooCommerce Notifications
spoki
WhatsApp full integration for your website! Recover Abandoned Carts, send Order Notifications and add WhatsApp Buttons.
Bubble Chat
bubble-chat
Add a bubble chat so your users can contact you directly faster and more efficiently
Watso – Basic Help Chat Button
watso-basic-chat
Lightweight and blazing-fast WhatsApp chat button for WordPress with full customization, UTM tracking, multi-agent support, and scheduling.
JCWP Add Quote button in product page
jcwp-add-quote-button-in-product-page
A plugin that adds a WhatsApp quote button on the WooCommerce product and shop page.
Inquiry Button for WooCommerce Developer Profile
2 plugins · 50 total installs
How We Detect Inquiry Button for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/inquiry-button-for-woocommerce/css/front.cssinquiry-button-for-woocommerce/css/front.css?ver=1.1HTML / DOM Fingerprints
nkg_wp_btnwhatsapp_iconname="inqubufo_whatsapp_enable"name="inqubufo_whatsapp_number"name="inqubufo_whatsapp_message"name="inqubufo_whatsapp_button_text"