Online Contact Widget-多合一在线客服插件 Security & Risk Analysis

wordpress.org/plugins/online-contact-widget

Online Contact Widget(多合一在线客服插件),旨在为WordPress网站提供一系列可配置在线客服支持,包括QQ、微信(微信号、公众号和小程序QR-code)、电话、Email和工单等。

800 active installs v1.3.0 PHP + WP 6.0+ Updated Oct 15, 2025
lineqqtelegramwechatwhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Online Contact Widget-多合一在线客服插件 Safe to Use in 2026?

Generally Safe

Score 100/100

Online Contact Widget-多合一在线客服插件 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The 'online-contact-widget' plugin version 1.3.0 presents a mixed security posture. While it has a clean vulnerability history with no recorded CVEs and a good percentage of SQL queries utilizing prepared statements, there are significant concerns regarding its attack surface. A substantial number of AJAX handlers lack authentication checks, creating potential entry points for unauthorized actions if not properly secured at the application level. The taint analysis, although limited in scope, did reveal one flow with unsanitized paths, which warrants further investigation to understand its potential impact. The plugin also shows a moderate percentage of output escaping issues, suggesting a risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with extreme care throughout the application.

Despite the absence of historical vulnerabilities, the static analysis highlights areas that could be exploited. The large number of unprotected AJAX endpoints is a primary concern, as it directly increases the plugin's attack surface. The moderate rate of improperly escaped output also suggests potential XSS risks. The plugin's strengths lie in its lack of dangerous functions, its generally good use of prepared statements for SQL, and its complete absence of bundled libraries, which can often introduce outdated or vulnerable dependencies. Overall, while the plugin doesn't exhibit known critical flaws, its unprotected entry points and output escaping deficiencies require attention to mitigate potential security risks.

Key Concerns

  • Unprotected AJAX handlers
  • Unsanitized path in taint flow
  • Improper output escaping
Vulnerabilities
None known

Online Contact Widget-多合一在线客服插件 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Online Contact Widget-多合一在线客服插件 Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
38 prepared
Unescaped Output
77
101 escaped
Nonce Checks
5
Capability Checks
8
File Operations
4
External Requests
8
Bundled Libraries
0

SQL Query Safety

88% prepared43 total queries

Output Escaping

57% escaped178 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
wp_init (wbm\wbm.php:173)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Online Contact Widget-多合一在线客服插件 Attack Surface

Entry Points7
Unprotected4

AJAX Handlers 7

authwp_ajax_wb_ocw_optionsclasses\admin.class.php:666
authwp_ajax_owc_recaptchaclasses\captcha.class.php:35
noprivwp_ajax_owc_recaptchaclasses\captcha.class.php:36
authwp_ajax_ocw_contactclasses\contact.class.php:21
authwp_ajax_wb_ocw_apiclasses\front.class.php:17
noprivwp_ajax_wb_ocw_apiclasses\front.class.php:18
authwp_ajax_wbp_apiwbm\wbm.php:39
WordPress Hooks 47
actionplugins_loadedclasses\admin.class.php:638
filterall_pluginsclasses\admin.class.php:642
filterplugin_action_linksclasses\admin.class.php:659
actionadmin_menuclasses\admin.class.php:660
actionadmin_enqueue_scriptsclasses\admin.class.php:662
filterplugin_row_metaclasses\admin.class.php:664
filterocw_sms_send_resultclasses\admin.class.php:1208
actionocw_new_concatclasses\contact.class.php:16
actionadmin_menuclasses\contact.class.php:19
filterbody_classclasses\faq\tpl\taxonomy.php:12
actioninitclasses\faq.class.php:21
filterpost_type_linkclasses\faq.class.php:22
filtertemplate_includeclasses\faq.class.php:24
filterdisable_categories_dropdownclasses\faq.class.php:157
actionparse_tax_queryclasses\faq.class.php:160
filterwbm_js_cnfclasses\front.class.php:21
filterwbm_menuclasses\front.class.php:35
actionwbm_head_ocwclasses\front.class.php:45
actionwbm_content_ocwclasses\front.class.php:55
actionwp_footerclasses\front.class.php:88
actionwp_enqueue_scriptsclasses\front.class.php:89
actionwp_enqueue_scriptsclasses\front.class.php:90
actionwp_enqueue_scriptsclasses\front.class.php:92
actionocw_new_concatclasses\mail.class.php:27
actionocw_mail_sendclasses\mail.class.php:28
actionphpmailer_initclasses\mail.class.php:82
filterwp_mailclasses\mail.class.php:83
actionwp_mail_failedclasses\mail.class.php:123
actionphpmailer_initclasses\mail.class.php:137
filterwp_mailclasses\mail.class.php:155
actionocw_send_smsclasses\sms.class.php:16
actionocw_send_sms_testclasses\sms.class.php:19
actionocw_new_concatclasses\sms.class.php:25
actionplugins_loadedwbm\wbm.php:33
filterget_wbm_cnfwbm\wbm.php:40
filterset_wbm_cnfwbm\wbm.php:41
actioninitwbm\wbm.php:46
actionwbm_headwbm\wbm.php:47
actionwbm_headerwbm\wbm.php:48
actionwbm_get_menuwbm\wbm.php:50
actionwbm_contentwbm\wbm.php:51
actionwbm_footerwbm\wbm.php:52
actionwbm_header_logowbm\wbm.php:53
actionwbm_content_homewbm\wbm.php:55
filterscript_loader_tagwbm\wbm.php:57
filterwbm_scriptwbm\wbm.php:60
filterwbm_stylewbm\wbm.php:72

Scheduled Events 1

ocw_mail_send
Maintenance & Trust

Online Contact Widget-多合一在线客服插件 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 15, 2025
PHP min version
Downloads13K

Community Trust

Rating0/100
Number of ratings0
Active installs800
Developer Profile

Online Contact Widget-多合一在线客服插件 Developer Profile

wbolt.com

11 plugins · 17K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
202 days
View full developer profile
Detection Fingerprints

How We Detect Online Contact Widget-多合一在线客服插件

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/online-contact-widget/css/style.css/wp-content/plugins/online-contact-widget/js/ocw.js
Script Paths
/wp-content/plugins/online-contact-widget/js/ocw.js
Version Parameters
online-contact-widget/style.css?ver=online-contact-widget/js/ocw.js?ver=

HTML / DOM Fingerprints

CSS Classes
ocw-whatsappocw-telegramocw-lineocw-messengerocw-viberocw-signalocw-qqocw-wechat+6 more
Data Attributes
data-ocw-iddata-ocw-type
JS Globals
ocw_settingsocw_contact
FAQ

Frequently Asked Questions about Online Contact Widget-多合一在线客服插件