OneClick WP Hello Security & Risk Analysis

wordpress.org/plugins/oneclick-whatsapp-hello

Make your audience contact you directly and easily on WhatsApp with a single click.

30 active installs v0.1.0 PHP 5.6+ WP 4.1+ Updated Unknown
chatcontactwhatsappwoocommercewoocommerce-whatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OneClick WP Hello Safe to Use in 2026?

Generally Safe

Score 100/100

OneClick WP Hello has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "oneclick-whatsapp-hello" plugin v0.1.0 exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities in its history, no dangerous functions identified, and no external HTTP requests. The static analysis also shows no critical or high severity taint flows and no file operations, which are generally good indicators. However, several areas raise concerns. A significant portion of output is not properly escaped (42%), presenting a potential risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the plugin uses raw SQL queries without prepared statements, which is a common pathway for SQL Injection attacks. The absence of nonce checks and capability checks across all entry points is a critical oversight, leaving the plugin vulnerable to unauthorized actions, especially considering the presence of shortcodes that could potentially be triggered by unauthenticated users or through malicious links.

Key Concerns

  • Raw SQL queries without prepared statements
  • Significant portion of outputs not properly escaped
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

OneClick WP Hello Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

OneClick WP Hello Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
24
33 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

58% escaped57 total outputs
Attack Surface

OneClick WP Hello Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[wa-hello] includes\whatsapp-hello-button.php:211
[gdpr] includes\whatsapp-hello-gdpr.php:23
WordPress Hooks 13
actionadmin_initadmin\wa-hello-admin.php:23
actionadmin_menuadmin\wa-hello-admin.php:25
actionadmin_noticesincludes\whatsapp-hello-button.php:25
filterwp_headincludes\whatsapp-hello-button.php:104
filterwp_headincludes\whatsapp-hello-button.php:162
filterwp_headincludes\whatsapp-hello-button.php:178
filterwp_headincludes\whatsapp-hello-button.php:233
actionwa_hello_action_pluginincludes\whatsapp-hello-gdpr.php:24
actionplugins_loadedwhatsapp-hello.php:34
actionwp_enqueue_scriptswhatsapp-hello.php:46
actionadmin_enqueue_scriptswhatsapp-hello.php:53
actionplugins_loadedwhatsapp-hello.php:65
filterplugin_action_linkswhatsapp-hello.php:75
Maintenance & Trust

OneClick WP Hello Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedUnknown
PHP min version5.6
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

OneClick WP Hello Developer Profile

Walter Pinem

4 plugins · 41K total installs

82
trust score
Avg Security Score
92/100
Avg Patch Time
73 days
View full developer profile
Detection Fingerprints

How We Detect OneClick WP Hello

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/oneclick-whatsapp-hello/assets/css/main-style.css/wp-content/plugins/oneclick-whatsapp-hello/assets/css/brands.min.css/wp-content/plugins/oneclick-whatsapp-hello/assets/css/solid.min.css/wp-content/plugins/oneclick-whatsapp-hello/assets/css/admin-style.css

HTML / DOM Fingerprints

CSS Classes
floating_button
Data Attributes
wa_hello-admin-select2
FAQ

Frequently Asked Questions about OneClick WP Hello