
OT Zalo – Zalo Chat Widget, Follow widget Security & Risk Analysis
wordpress.org/plugins/ot-zaloOT Zalo - Zalo Chat Widget, Follow widget
Is OT Zalo – Zalo Chat Widget, Follow widget Safe to Use in 2026?
Generally Safe
Score 85/100OT Zalo – Zalo Chat Widget, Follow widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ot-zalo" v1.1.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL queries (all using prepared statements), file operations, external HTTP requests, and taint flows with unsanitized paths are all positive indicators. The fact that all identified entry points (AJAX, REST API, shortcodes, cron events) are either non-existent or have proper authentication/permission checks is a significant strength. However, a notable concern is the low percentage of properly escaped output. With 61 outputs and only 41% properly escaped, there's a high risk of cross-site scripting (XSS) vulnerabilities, especially if the data being output originates from user input and is not sufficiently sanitized before display. The complete lack of vulnerability history, while seemingly positive, could also indicate limited testing or reporting, rather than absolute security. Overall, while the foundational security practices related to data handling and access control appear strong, the unescaped output presents a clear and significant risk that needs immediate attention.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks implemented
- No capability checks implemented
OT Zalo – Zalo Chat Widget, Follow widget Security Vulnerabilities
OT Zalo – Zalo Chat Widget, Follow widget Code Analysis
Output Escaping
OT Zalo – Zalo Chat Widget, Follow widget Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
OT Zalo – Zalo Chat Widget, Follow widget Maintenance & Trust
Maintenance Signals
Community Trust
OT Zalo – Zalo Chat Widget, Follow widget Alternatives
OT Zalo – Zalo Chat Widget, Follow widget Developer Profile
4 plugins · 10K total installs
How We Detect OT Zalo – Zalo Chat Widget, Follow widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ot-zalo/assets/css/style.css/wp-content/plugins/ot-zalo/assets/js/script.jshttps://sp.zalo.me/plugins/sdk.jsot-zalo/assets/css/style.css?ver=ot-zalo/assets/js/script.js?ver=HTML / DOM Fingerprints
zalo-chat-widgetzalo-share-buttondata-oaiddata-welcome-messagedata-autopopupdata-hrefdata-layoutdata-color+1 more[zalo_share][zalo_share url=