Novera Smart Chat Security & Risk Analysis

wordpress.org/plugins/novera-smart-chat

WhatsApp Floating Chat Button with Analytics, UTM Tracking, GA4 & Conversion Tools

10 active installs v1.0.1 PHP 7.4+ WP 5.0+ Updated Aug 21, 2025
analyticschatfloating-buttonutm-trackingwhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Novera Smart Chat Safe to Use in 2026?

Generally Safe

Score 100/100

Novera Smart Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The 'novera-smart-chat' plugin v1.0.1 exhibits a generally good security posture, with strong adherence to secure coding practices. The plugin demonstrates a commendable effort in utilizing prepared statements for SQL queries (95%) and performing proper output escaping (99%). The presence of nonce and capability checks on its limited number of AJAX entry points further strengthens its defenses, and the absence of a vulnerability history suggests responsible development. However, the taint analysis reveals two flows with unsanitized paths, indicating a potential risk of path traversal or similar vulnerabilities. While these are flagged as high severity, the absence of active exploitation or public CVEs means the immediate risk is currently theoretical but requires attention.

Despite these concerns, the plugin's strengths in SQL and output handling, along with its clean vulnerability record, paint a picture of a plugin that is largely secure. The limited attack surface, with all entry points appearing to have some form of authentication, is a significant positive. The primary focus for improvement should be on thoroughly sanitizing the identified unsanitized path flows to mitigate potential exploitation vectors. Addressing these specific taint analysis findings will further enhance the plugin's robust security framework.

Key Concerns

  • High severity unsanitized taint flows
  • File operations found
Vulnerabilities
None known

Novera Smart Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Novera Smart Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
100 prepared
Unescaped Output
2
155 escaped
Nonce Checks
7
Capability Checks
3
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

95% prepared105 total queries

Output Escaping

99% escaped157 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
<stats-page> (templates\stats-page.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Novera Smart Chat Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_novera_smart_chat_track_clicknovera-smart-chat.php:66
noprivwp_ajax_novera_smart_chat_track_clicknovera-smart-chat.php:67
WordPress Hooks 8
actioninitnovera-smart-chat.php:41
actionplugins_loadednovera-smart-chat.php:46
actionadmin_menunovera-smart-chat.php:56
actionadmin_initnovera-smart-chat.php:57
actionadmin_enqueue_scriptsnovera-smart-chat.php:58
actionwp_enqueue_scriptsnovera-smart-chat.php:62
actionwp_footernovera-smart-chat.php:63
actionwp_dashboard_setupnovera-smart-chat.php:70
Maintenance & Trust

Novera Smart Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 21, 2025
PHP min version7.4
Downloads308

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Novera Smart Chat Developer Profile

Hüseyin Ege Ermiş

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Novera Smart Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/novera-smart-chat/assets/admin.js/wp-content/plugins/novera-smart-chat/assets/admin.css/wp-content/plugins/novera-smart-chat/assets/chart.umd.min.js/wp-content/plugins/novera-smart-chat/assets/frontend.js/wp-content/plugins/novera-smart-chat/assets/frontend.css
Script Paths
/wp-content/plugins/novera-smart-chat/assets/admin.js/wp-content/plugins/novera-smart-chat/assets/chart.umd.min.js/wp-content/plugins/novera-smart-chat/assets/frontend.js
Version Parameters
novera-smart-chat/assets/admin.js?ver=novera-smart-chat/assets/admin.css?ver=novera-smart-chat/assets/chart.umd.min.js?ver=novera-smart-chat/assets/frontend.js?ver=novera-smart-chat/assets/frontend.css?ver=

HTML / DOM Fingerprints

CSS Classes
novera-smart-chat-tab-buttonnovera-smart-chat-tab-contentnsc-chat-buttonnsc-chat-button-wrappernsc-chat-windownsc-chat-headernsc-chat-bodynsc-chat-footer+9 more
HTML Comments
<!-- Novera Smart Chat Settings --><!-- Novera Smart Chat Statistics Widget --><!-- Novera Smart Chat Frontend Script --><!-- Novera Smart Chat Initialized -->
Data Attributes
data-tabdata-phonedata-messagedata-button-textdata-button-colordata-position+14 more
JS Globals
NoveraSmartChatConfignovera_smart_chat_ajax_objectNoveraSmartChatFrontend
REST Endpoints
/wp-json/novera-smart-chat/v1/track
FAQ

Frequently Asked Questions about Novera Smart Chat