Plug Chat Security & Risk Analysis

wordpress.org/plugins/plug-chat

Plugchat comes with facebook messenger chatting option in your WordPress website.

10 active installs v1.0.2 PHP 7.0+ WP 5.0+ Updated Nov 26, 2022
chatbot-pluginfacebook-chatbotmessengerplugchatwordpress-chatbot-plugin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Plug Chat Safe to Use in 2026?

Generally Safe

Score 85/100

Plug Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

Based on the provided static analysis, 'plug-chat' v1.0.2 exhibits a generally positive security posture. The absence of any detected dangerous functions, SQL injection vulnerabilities through prepared statements, file operations, external HTTP requests, and a clean taint analysis suggest a well-secured codebase. Furthermore, the plugin has no known CVEs, indicating a history of responsible development or minimal exposure.

However, there are areas of concern that warrant attention. A significant weakness lies in the complete lack of nonce and capability checks across all entry points. This means that any potential entry point, even if currently zero, could become a security risk if added in future versions without proper authorization mechanisms. Additionally, the output escaping is only properly implemented for 57% of outputs, leaving nearly half of the plugin's outputs potentially vulnerable to cross-site scripting (XSS) attacks.

In conclusion, while 'plug-chat' v1.0.2 benefits from a strong foundation in secure coding practices regarding SQL and dangerous functions, the absence of authentication and authorization checks and insufficient output escaping are notable weaknesses. These oversight areas create a potential for future vulnerabilities, particularly XSS, and highlight the need for diligent security reviews during development.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Insufficient output escaping (43% unescaped)
Vulnerabilities
None known

Plug Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Plug Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

57% escaped23 total outputs
Attack Surface

Plug Chat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initplugchat.php:21
actionadmin_menuplugchat.php:24
actionwp_enqueue_scriptsplugchat.php:80
actionadmin_enqueue_scriptsplugchat.php:92
actionwp_footerplugchat.php:102
Maintenance & Trust

Plug Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 26, 2022
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Plug Chat Developer Profile

themeshape

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Plug Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/plug-chat/assets/css/style.css/wp-content/plugins/plug-chat/assets/js/script.js/wp-content/plugins/plug-chat/assets/css/admin-style.css/wp-content/plugins/plug-chat/assets/js/admin-script.js
Script Paths
/wp-content/plugins/plug-chat/assets/js/script.js/wp-content/plugins/plug-chat/assets/js/admin-script.js
Version Parameters
plugchat/assets/css/style.css?ver=plugchat/assets/js/script.js?ver=wp-color-pickeradmin-styleplugchat/assets/css/admin-style.css?ver=plugchat/assets/js/admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
chat-btnplugs-inputplugs-reply
Data Attributes
page_idtheme_colorlogged_in_greetinglogged_out_greeting
JS Globals
jQuery
Shortcode Output
<div class='fb-customerchat'
FAQ

Frequently Asked Questions about Plug Chat