
product-support-now Security & Risk Analysis
wordpress.org/plugins/product-support-nowAdd a link to web-whatsapp chat on each product, with information about the product. It allows asign the work schedule up to 2 employees.
Is product-support-now Safe to Use in 2026?
Generally Safe
Score 85/100product-support-now has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of product-support-now v1.0.0 reveals a promising security posture concerning common web vulnerabilities. The absence of observable AJAX handlers, REST API routes, shortcodes, and cron events suggests a minimal attack surface, which is further strengthened by the lack of detected dangerous functions, file operations, or external HTTP requests. The fact that all SQL queries utilize prepared statements is a significant strength. However, the low percentage of properly escaped output (35%) is a notable concern, indicating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed to the user. The complete absence of nonce and capability checks across all entry points is a critical oversight, leaving any potential (even if currently hidden) entry points vulnerable to CSRF and unauthorized access attacks.
The vulnerability history for product-support-now is remarkably clean, with no known CVEs recorded. This suggests that the plugin has either been developed with strong security practices from the outset or has had a history of quick and effective patching. However, the absence of vulnerabilities does not guarantee future safety. The lack of any recorded vulnerabilities makes it difficult to infer patterns in common vulnerability types. While the current code analysis shows no critical taint flows, the significant number of unescaped outputs and the missing authorization checks are weaknesses that could be exploited if new entry points or unhandled data flows are introduced in future versions or if existing ones are discovered.
In conclusion, product-support-now v1.0.0 demonstrates good practices in areas like SQL injection prevention and limiting its direct attack surface. The clean vulnerability history is a positive sign. However, the significant lack of output escaping and the complete absence of nonce and capability checks represent substantial security risks that need immediate attention. These weaknesses could be leveraged to execute XSS attacks or bypass authorization mechanisms, especially if the plugin's functionality is expanded or if hidden entry points are found. The current analysis provides a baseline, but the identified weaknesses necessitate a proactive approach to remediation.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
- Low Percentage of Output Escaping
product-support-now Security Vulnerabilities
product-support-now Code Analysis
Output Escaping
product-support-now Attack Surface
WordPress Hooks 4
Maintenance & Trust
product-support-now Maintenance & Trust
Maintenance Signals
Community Trust
product-support-now Alternatives
chat-me-now
chat-me-now
Floating button that opens the WhatsApp chat to the technical support on turn. It allows asign the work schedule up to 2 employees.
mPDF add-on for RTL and Unicode Support
mpdf-addon-for-pdf-invoices
RTL and Unicode support add-on for WebToffee WooCommerce Gift Cards, WebToffee WooCommerce Request a Quote and WooCommerce PDF Invoices, Packing Slips …
MxChat – AI Chatbot & Content Generation for WordPress
mxchat-basic
The best free AI chatbot and content generation plugin for WordPress. Train ChatGPT, Claude, Gemini, or Grok on your website content.
Live Chat & AI Chatbots – onWebChat
onwebchat
Enhance customer service with instant 24/7 AI-powered replies. Now with WooCommerce integration, so your chatbot understands your products and helps c …
CIO Custom Fields Importer
custom-fields-csv-xml-importer
Simple, easy, fast and flexible, this add-on to WP All Import processes large data sets from any XML or CSV files to any contents.
product-support-now Developer Profile
3 plugins · 5K total installs
How We Detect product-support-now
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/product-support-now/assets/css/psn-style.css/wp-content/plugins/product-support-now/assets/js/psn-scripts.js/wp-content/plugins/product-support-now/assets/img/psn-logo.png/wp-content/plugins/product-support-now/assets/js/psn-scripts.jsproduct-support-now/assets/css/psn-style.css?ver=product-support-now/assets/js/psn-scripts.js?ver=HTML / DOM Fingerprints
psn-whatsapp-buttonbh-psn-whatsapp-icondata-product-iddata-product-namedata-product-urlpsn_ajax_object[product_support_now_chat]