
OneClick Chat to Order Security & Risk Analysis
wordpress.org/plugins/oneclick-whatsapp-orderTransform your WooCommerce store with seamless WhatsApp integration. Enable customers to order products instantly via WhatsApp with enhanced features.
Is OneClick Chat to Order Safe to Use in 2026?
Generally Safe
Score 92/100OneClick Chat to Order has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the "oneclick-whatsapp-order" v1.1.0 plugin reveals a mixed security posture. While the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and performing capability checks on its entry points, there are notable areas of concern. The output escaping is only 69% proper, indicating a significant risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data might not be adequately neutralized before being displayed. The absence of taint analysis results is also a weakness, as it means potential data flow vulnerabilities may have been missed. Furthermore, the plugin has a concerning history of six known CVEs, with past vulnerabilities including Missing Authorization, Exposure of Sensitive Information, and Cross-Site Scripting. Although no CVEs are currently unpatched, this historical pattern suggests recurring security weaknesses that require diligent monitoring and timely updates.
Key Concerns
- Output escaping is only 69% proper
- Vulnerability history: 6 known CVEs
- Vulnerability history: 1 high severity CVE
- Vulnerability history: 4 medium severity CVEs
- Vulnerability history: 1 low severity CVE
- Bundled outdated library: Select2
OneClick Chat to Order Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
OneClick Chat to Order <= 1.0.9 - Missing Authorization to Authenticated (Editor+) Plugin Settings Update
OneClick Chat to Order <= 1.0.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Exposure
OneClick Chat to Order <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
OneClick Chat to Order <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
OneClick Chat to Order <= 1.0.4.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
OneClick Chat to Order <= 1.0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
OneClick Chat to Order Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
OneClick Chat to Order Attack Surface
Shortcodes 5
WordPress Hooks 71
Maintenance & Trust
OneClick Chat to Order Maintenance & Trust
Maintenance Signals
Community Trust
OneClick Chat to Order Alternatives
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Social Chat – Click To Chat App Button
wp-whatsapp-chat
WhatsApp Chat🔥 allows you to enhance customer engagement! Integrate "WhatsApp" or "WhatsApp Business" with a single click.
WP Chat App
wp-whatsapp
Integrate WhatsApp experience directly into your WordPress website.
Contact Form to Chat Apps | Click to Chat to Order – FormyChat
social-contact-form
Connect contact forms and WooCommerce to WhatsApp by live click to chat. Send form data to WhatsApp Business for instant customer engagement
Animated Floating Chat Button
animated-floating-chat-button
Adds an animated floating chat button to the WordPress site, making communication easier.
OneClick Chat to Order Developer Profile
4 plugins · 41K total installs
How We Detect OneClick Chat to Order
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oneclick-whatsapp-order/assets/css/main-style.css/wp-content/plugins/oneclick-whatsapp-order/assets/js/wa-single-button.js/wp-content/plugins/oneclick-whatsapp-order/assets/css/admin-style.css/wp-content/plugins/oneclick-whatsapp-order/assets/css/select2.min.css/wp-content/plugins/oneclick-whatsapp-order/assets/js/admin-main.js/wp-content/plugins/oneclick-whatsapp-order/assets/js/select2.min.js/wp-content/plugins/oneclick-whatsapp-order/assets/js/select2-helper.js/wp-content/plugins/oneclick-whatsapp-order/assets/js/wp-color-picker-alpha.min.js+1 more/wp-content/plugins/oneclick-whatsapp-order/assets/js/wa-single-button.js/wp-content/plugins/oneclick-whatsapp-order/assets/js/admin-main.js/wp-content/plugins/oneclick-whatsapp-order/assets/js/select2.min.js/wp-content/plugins/oneclick-whatsapp-order/assets/js/select2-helper.js/wp-content/plugins/oneclick-whatsapp-order/assets/js/wp-color-picker-alpha.min.js/wp-content/plugins/oneclick-whatsapp-order/assets/js/wp-color-picker-init.jsoneclick-whatsapp-order/assets/css/main-style.css?ver=oneclick-whatsapp-order/assets/js/wa-single-button.js?ver=oneclick-whatsapp-order/assets/css/admin-style.css?ver=oneclick-whatsapp-order/assets/css/select2.min.css?ver=oneclick-whatsapp-order/assets/js/admin-main.js?ver=oneclick-whatsapp-order/assets/js/select2.min.js?ver=oneclick-whatsapp-order/assets/js/select2-helper.js?ver=oneclick-whatsapp-order/assets/js/wp-color-picker-alpha.min.js?ver=oneclick-whatsapp-order/assets/js/wp-color-picker-init.js?ver=HTML / DOM Fingerprints
wa_order_stylewa_order_style_adminwa_order_selet2_stylewa_order_js_adminwa_order_js_select2wa_order_select2_helperwp-color-picker-alphawp-color-picker-init<!-- Make sure we don't expose any info if called directly --><!-- @since 1.0.5 --><!-- Check if the FeaturesUtil class exists in the \Automattic\WooCommerce\Utilities namespace. --><!-- Declare compatibility with custom order tables using the FeaturesUtil class. -->+12 moreOCTO_NAMEOCTO_VERSIONOCTO_FILEOCTO_BASEOCTO_DIROCTO_URL+1 more