
Floating Contact Button Security & Risk Analysis
wordpress.org/plugins/madnesschat-buttonAdd a lightweight floating WhatsApp chat button (click to chat) with styles, triggers, responsive options, and optional GDPR consent.
Is Floating Contact Button Safe to Use in 2026?
Generally Safe
Score 100/100Floating Contact Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The madnesschat-button plugin v1.1.1 demonstrates a generally strong security posture with a significant emphasis on secure coding practices. The complete absence of known CVEs, both historical and current, is a very positive indicator of the plugin's maintainer's diligence. Furthermore, the code analysis reveals that all SQL queries are properly prepared, and there are no direct file operations or external HTTP requests, which significantly reduces the attack surface for common web vulnerabilities. The presence of both nonce and capability checks on its AJAX handlers further bolsters its defenses against unauthorized actions.
However, the static analysis does highlight a couple of areas for concern. Specifically, the taint analysis identified two flows with unsanitized paths, flagged with a high severity. While the absence of critical severity taint flows is encouraging, these high-severity flows represent a potential risk for attackers to manipulate application behavior or gain unauthorized access if exploited. Additionally, a notable portion (33%) of the plugin's output is not properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly rendered in the front-end without adequate sanitization. The plugin has a moderate attack surface with six AJAX handlers, but importantly, all are protected by authentication checks, mitigating the risk associated with direct entry points.
Key Concerns
- High severity unsanitized taint flows
- Significant amount of unescaped output
Floating Contact Button Security Vulnerabilities
Floating Contact Button Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Floating Contact Button Attack Surface
AJAX Handlers 6
WordPress Hooks 19
Maintenance & Trust
Floating Contact Button Maintenance & Trust
Maintenance Signals
Community Trust
Floating Contact Button Alternatives
MameTech Chat Button
mametech-chat-button
Add a professional floating chat button to your website for WhatsApp and other messaging services with advanced features.
Floating Contact Button for MAX and Telegram
floating-contact-button-for-max-and-telegram
A lightweight floating contact button for WordPress with support for Telegram, WhatsApp, Facebook Messenger and MAX.
Floating Contact Buttons
degx-floating-buttons
Add customizable WhatsApp and Phone floating buttons to your WordPress website.
ChatFlow – Click To Chat Widget for Website
chatflow-chat-widget
Add the ability for your visitor to start chat with you on Facebook Messenger and WhatsApp directly from your website.
Advanced Contact Button
advanced-contact-button
Add beautiful floating contact buttons (Call, Email, WhatsApp, WeChat) to your WordPress website with customizable settings.
Floating Contact Button Developer Profile
1 plugin · 0 total installs
How We Detect Floating Contact Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/madnesschat-button/assets/css/frontend.css/wp-content/plugins/madnesschat-button/assets/js/frontend.js/wp-content/plugins/madnesschat-button/assets/css/gdpr.css/wp-content/plugins/madnesschat-button/assets/js/gdpr.js/wp-content/plugins/madnesschat-button/assets/css/animate.min.css/wp-content/plugins/madnesschat-button/assets/css/tooltip.css/wp-content/plugins/madnesschat-button/assets/js/tooltip.js/wp-content/plugins/madnesschat-button/assets/js/custom-icon.js/wp-content/plugins/madnesschat-button/assets/js/frontend.js/wp-content/plugins/madnesschat-button/assets/css/frontend.css?ver=/wp-content/plugins/madnesschat-button/assets/js/frontend.js?ver=/wp-content/plugins/madnesschat-button/assets/css/gdpr.css?ver=/wp-content/plugins/madnesschat-button/assets/js/gdpr.js?ver=/wp-content/plugins/madnesschat-button/assets/css/animate.min.css?ver=/wp-content/plugins/madnesschat-button/assets/css/tooltip.css?ver=/wp-content/plugins/madnesschat-button/assets/js/tooltip.js?ver=/wp-content/plugins/madnesschat-button/assets/js/custom-icon.js?ver=HTML / DOM Fingerprints
mcnb-whatsapp-buttonmcnb-gdpr-modalmcnb-gdpr-accept-btnmcnb-gdpr-decline-btnmcnb-tooltipdata-mcnb-optionsmcnb_frontend_options