product-support-now Security & Risk Analysis

wordpress.org/plugins/product-support-now

Add a link to web-whatsapp chat on each product, with information about the product. It allows asign the work schedule up to 2 employees.

40 active installs v1.0.0 PHP 7.0+ WP 4.7+ Updated May 21, 2021
action-buttoncommentssupportwoowoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is product-support-now Safe to Use in 2026?

Generally Safe

Score 85/100

product-support-now has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The static analysis of product-support-now v1.0.0 reveals a promising security posture concerning common web vulnerabilities. The absence of observable AJAX handlers, REST API routes, shortcodes, and cron events suggests a minimal attack surface, which is further strengthened by the lack of detected dangerous functions, file operations, or external HTTP requests. The fact that all SQL queries utilize prepared statements is a significant strength. However, the low percentage of properly escaped output (35%) is a notable concern, indicating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed to the user. The complete absence of nonce and capability checks across all entry points is a critical oversight, leaving any potential (even if currently hidden) entry points vulnerable to CSRF and unauthorized access attacks.

The vulnerability history for product-support-now is remarkably clean, with no known CVEs recorded. This suggests that the plugin has either been developed with strong security practices from the outset or has had a history of quick and effective patching. However, the absence of vulnerabilities does not guarantee future safety. The lack of any recorded vulnerabilities makes it difficult to infer patterns in common vulnerability types. While the current code analysis shows no critical taint flows, the significant number of unescaped outputs and the missing authorization checks are weaknesses that could be exploited if new entry points or unhandled data flows are introduced in future versions or if existing ones are discovered.

In conclusion, product-support-now v1.0.0 demonstrates good practices in areas like SQL injection prevention and limiting its direct attack surface. The clean vulnerability history is a positive sign. However, the significant lack of output escaping and the complete absence of nonce and capability checks represent substantial security risks that need immediate attention. These weaknesses could be leveraged to execute XSS attacks or bypass authorization mechanisms, especially if the plugin's functionality is expanded or if hidden entry points are found. The current analysis provides a baseline, but the identified weaknesses necessitate a proactive approach to remediation.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
  • Low Percentage of Output Escaping
Vulnerabilities
None known

product-support-now Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

product-support-now Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

35% escaped20 total outputs
Attack Surface

product-support-now Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuinc\BH_PLGN_PSN-admin.php:11
actionadmin_initinc\BH_PLGN_PSN-admin.php:12
actionwoocommerce_after_add_to_cart_forminc\BH_PLGN_PSN-widget.php:19
actionwoocommerce_after_shop_loop_item_titleinc\BH_PLGN_PSN-widget.php:20
Maintenance & Trust

product-support-now Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 21, 2021
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

product-support-now Developer Profile

dfrankortiz

3 plugins · 5K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect product-support-now

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-support-now/assets/css/psn-style.css/wp-content/plugins/product-support-now/assets/js/psn-scripts.js/wp-content/plugins/product-support-now/assets/img/psn-logo.png
Script Paths
/wp-content/plugins/product-support-now/assets/js/psn-scripts.js
Version Parameters
product-support-now/assets/css/psn-style.css?ver=product-support-now/assets/js/psn-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
psn-whatsapp-buttonbh-psn-whatsapp-icon
Data Attributes
data-product-iddata-product-namedata-product-url
JS Globals
psn_ajax_object
Shortcode Output
[product_support_now_chat]
FAQ

Frequently Asked Questions about product-support-now