
Online Contact Widget-多合一在线客服插件 Security & Risk Analysis
wordpress.org/plugins/online-contact-widgetOnline Contact Widget(多合一在线客服插件),旨在为WordPress网站提供一系列可配置在线客服支持,包括QQ、微信(微信号、公众号和小程序QR-code)、电话、Email和工单等。
Is Online Contact Widget-多合一在线客服插件 Safe to Use in 2026?
Generally Safe
Score 100/100Online Contact Widget-多合一在线客服插件 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'online-contact-widget' plugin version 1.3.0 presents a mixed security posture. While it has a clean vulnerability history with no recorded CVEs and a good percentage of SQL queries utilizing prepared statements, there are significant concerns regarding its attack surface. A substantial number of AJAX handlers lack authentication checks, creating potential entry points for unauthorized actions if not properly secured at the application level. The taint analysis, although limited in scope, did reveal one flow with unsanitized paths, which warrants further investigation to understand its potential impact. The plugin also shows a moderate percentage of output escaping issues, suggesting a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with extreme care throughout the application.
Despite the absence of historical vulnerabilities, the static analysis highlights areas that could be exploited. The large number of unprotected AJAX endpoints is a primary concern, as it directly increases the plugin's attack surface. The moderate rate of improperly escaped output also suggests potential XSS risks. The plugin's strengths lie in its lack of dangerous functions, its generally good use of prepared statements for SQL, and its complete absence of bundled libraries, which can often introduce outdated or vulnerable dependencies. Overall, while the plugin doesn't exhibit known critical flaws, its unprotected entry points and output escaping deficiencies require attention to mitigate potential security risks.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized path in taint flow
- Improper output escaping
Online Contact Widget-多合一在线客服插件 Security Vulnerabilities
Online Contact Widget-多合一在线客服插件 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Online Contact Widget-多合一在线客服插件 Attack Surface
AJAX Handlers 7
WordPress Hooks 47
Scheduled Events 1
Maintenance & Trust
Online Contact Widget-多合一在线客服插件 Maintenance & Trust
Maintenance Signals
Community Trust
Online Contact Widget-多合一在线客服插件 Alternatives
Social Live Chat Helpdesk – MyAlice
myaliceai
Engage customers at every stage of their journey through Live Chat, WhatsApp, Telegram, Line, Viber, Instagram, and Facebook Messenger, and boost sale …
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Pulsating Chat Button
amin-chat-button
WhatsApp or Telegram Chat🔥. Adds a pulsating WhatsApp or Telegram button 🍀 to your website. Fast and easy installation. Setting up target id GTM and Y …
Mobile Contact Line
mobile-contact-line
Simple plugin that allow you add mobile contact line to your wordpress site
Easy Sticky Buttons
easy-sticky-buttons
With the Easy Sticky Buttons plugin, you can add 1 to 4 sticky buttons at the bottom of your site's mobile view.
Online Contact Widget-多合一在线客服插件 Developer Profile
11 plugins · 17K total installs
How We Detect Online Contact Widget-多合一在线客服插件
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/online-contact-widget/css/style.css/wp-content/plugins/online-contact-widget/js/ocw.js/wp-content/plugins/online-contact-widget/js/ocw.jsonline-contact-widget/style.css?ver=online-contact-widget/js/ocw.js?ver=HTML / DOM Fingerprints
ocw-whatsappocw-telegramocw-lineocw-messengerocw-viberocw-signalocw-qqocw-wechat+6 moredata-ocw-iddata-ocw-typeocw_settingsocw_contact