Group chat for WordPress – Minnit Chat Security & Risk Analysis

wordpress.org/plugins/minnit-chat

Cloud-based chat using your WordPress accounts. Minnit uses SSO to allow you and your WordPress users to communicate with one another.

600 active installs v4.1.4 PHP + WP 3.4+ Updated Mar 11, 2026
chatchat-groupchatboxchatroomgroup-chat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Group chat for WordPress – Minnit Chat Safe to Use in 2026?

Generally Safe

Score 100/100

Group chat for WordPress – Minnit Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 23d ago
Risk Assessment

The Minnit Chat plugin, version 4.1.4, exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and avoids dangerous functions, file operations, and external HTTP requests. The absence of known CVEs and a clean vulnerability history are also strong indicators of a well-maintained and secure plugin. However, there are significant concerns regarding its attack surface and output escaping.

The plugin exposes two REST API routes without any permission callbacks, creating a direct entry point for unauthenticated access. Furthermore, the static analysis revealed two taint flows with unsanitized paths, which, although not classified as critical or high severity, represent potential vulnerabilities if exploited. The extremely low percentage of properly escaped output (17%) is a major red flag, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data could be injected into the page without proper sanitization.

In conclusion, while the plugin has a clean vulnerability history and implements good database practices, the lack of authentication on REST API routes and the pervasive issue with output escaping present substantial security risks. These areas require immediate attention to harden the plugin's security.

Key Concerns

  • REST API routes without permission callbacks
  • Taint flows with unsanitized paths
  • Low percentage of properly escaped output
  • No nonce checks on entry points
Vulnerabilities
None known

Group chat for WordPress – Minnit Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Group chat for WordPress – Minnit Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
2 escaped
Nonce Checks
0
Capability Checks
15
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

17% escaped12 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
redirectIfNotLoggedIn (sso_oauth2_authorize_template.php:9)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Group chat for WordPress – Minnit Chat Attack Surface

Entry Points2
Unprotected2

REST API Routes 2

POST/wp-json/minnit-chat/v1/sso/oauth2/access_tokenminnitchat.php:722
GET/wp-json/minnit-chat/v1/sso/oauth2/get_userinfominnitchat.php:728
WordPress Hooks 9
actionwp_enqueue_scriptsminnitchat.php:12
actionadmin_enqueue_scriptsminnitchat.php:13
actionwp_enqueue_scriptsminnitchat.php:67
actionadmin_enqueue_scriptsminnitchat.php:83
actionadmin_menuminnitchat.php:103
actionadmin_initminnitchat.php:104
actionenqueue_block_editor_assetsminnitchat.php:599
actionrest_api_initminnitchat.php:721
actiontemplate_includeminnitchat.php:755
Maintenance & Trust

Group chat for WordPress – Minnit Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version
Downloads36K

Community Trust

Rating90/100
Number of ratings6
Active installs600
Developer Profile

Group chat for WordPress – Minnit Chat Developer Profile

minnitchat

1 plugin · 600 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Group chat for WordPress – Minnit Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/minnit-chat/minnitwpadmin.js/wp-content/plugins/minnit-chat/minnit.js/wp-content/plugins/minnit-chat/minnit.css/wp-content/plugins/minnit-chat/minnitcolorpick.js
Script Paths
plugins/minnit-chat/minnitwpadmin.js?minnitversion=4.1.4plugins/minnit-chat/minnit.js?minnitversion=4.1.4plugins/minnit-chat/minnitcolorpick.js?minnitversion=4.1.4
Version Parameters
minnitwpadmin.js?minnitversion=4.1.4minnit.js?minnitversion=4.1.4minnit.css?minnitversion=4.1.4minnitcolorpick.js?minnitversion=4.1.4

HTML / DOM Fingerprints

CSS Classes
hiddenwrap
Data Attributes
id="add-minnit-header"id="no-gutenberg"id="no-gutenberg-step-2"class="hidden"id="no-gutenberg-input"id="no-gutenberg-button"+6 more
JS Globals
minnitChatOptions
FAQ

Frequently Asked Questions about Group chat for WordPress – Minnit Chat