Wechat Contacts Support Chat for Mobile Security & Risk Analysis

wordpress.org/plugins/nz-wechat-qr-code-support-chat

This plugin adds a sticky box in your website to hold QR code of your contact so your website visitors can easily scan and chat to you on wechat.

10 active installs v1.0 PHP + WP 4.0+ Updated Jul 22, 2016
direct-support-chat-on-wechatsupport-chatwebsite-support-chat-via-wechatwechat-qr-code-support-chatwechat-support-chat
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wechat Contacts Support Chat for Mobile Safe to Use in 2026?

Generally Safe

Score 85/100

Wechat Contacts Support Chat for Mobile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "nz-wechat-qr-code-support-chat" v1.0 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any discovered CVEs, coupled with a lack of identified dangerous functions, file operations, or external HTTP requests, suggests careful development practices in these areas. The exclusive use of prepared statements for SQL queries is a significant strength, mitigating risks of SQL injection. However, a notable concern arises from the output escaping, where only 63% of outputs are properly escaped, leaving a portion vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the complete absence of nonce and capability checks, particularly when considering potential future additions to the attack surface, represents a significant oversight. While the current attack surface is minimal (zero entry points), this lack of fundamental security checks on any potential interaction points is a weakness that could be exploited if new features are added or existing ones become accessible.

Key Concerns

  • Incomplete output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Wechat Contacts Support Chat for Mobile Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wechat Contacts Support Chat for Mobile Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

63% escaped19 total outputs
Attack Surface

Wechat Contacts Support Chat for Mobile Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menunz-wechat-qr-code-support-chat.php:13
actionadmin_initnz-wechat-qr-code-support-chat.php:18
actionwp_footernz-wechat-qr-code-support-chat.php:91
actionwp_enqueue_scriptsnz-wechat-qr-code-support-chat.php:95
actionwp_enqueue_scriptsnz-wechat-qr-code-support-chat.php:100
Maintenance & Trust

Wechat Contacts Support Chat for Mobile Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedJul 22, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Wechat Contacts Support Chat for Mobile Developer Profile

syednazrulhassan

10 plugins · 540 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wechat Contacts Support Chat for Mobile

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nz-wechat-qr-code-support-chat/assets/css/wechat.css/wp-content/plugins/nz-wechat-qr-code-support-chat/assets/js/wechat.js
Script Paths
/wp-content/plugins/nz-wechat-qr-code-support-chat/assets/js/wechat.js
Version Parameters
nz-wechat-qr-code-support-chat/assets/js/wechat.js?ver=1

HTML / DOM Fingerprints

CSS Classes
beforeafter
FAQ

Frequently Asked Questions about Wechat Contacts Support Chat for Mobile