
GetShoutbox Security & Risk Analysis
wordpress.org/plugins/proxymis-shoutbox-comGetShoutbox is a WP plugin to easily add a real time shoutbox chat into your blog.
Is GetShoutbox Safe to Use in 2026?
Generally Safe
Score 100/100GetShoutbox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The proxymis-shoutbox-com plugin v1.1.0 demonstrates a strong security posture based on the provided static analysis. The plugin does not appear to have any critical or high-severity vulnerabilities in its code, with a near-perfect output escaping rate and a complete lack of dangerous functions or raw SQL queries. The absence of known CVEs in its history further reinforces this positive assessment, suggesting a history of secure development or prompt patching of any past issues.
However, the analysis does reveal a few minor areas for improvement. The lack of nonce checks on the identified shortcodes is a potential concern, as it could open the door to CSRF attacks if these shortcodes perform sensitive operations. While the plugin does implement capability checks for these shortcodes, the absence of nonces means that an attacker could potentially trick a logged-in user into triggering these actions without their explicit consent, provided they can be lured to a crafted page or interact with a malicious element.
Overall, the plugin is well-secured with robust practices like prepared SQL statements and proper output escaping. The vulnerability history being clean is a significant strength. The main area of concern is the missing nonce validation on shortcodes, which is a standard security practice to mitigate CSRF vulnerabilities. Addressing this would further solidify the plugin's security.
Key Concerns
- Shortcodes lack nonce checks
GetShoutbox Security Vulnerabilities
GetShoutbox Release Timeline
GetShoutbox Code Analysis
Output Escaping
GetShoutbox Attack Surface
Shortcodes 2
WordPress Hooks 2
Maintenance & Trust
GetShoutbox Maintenance & Trust
Maintenance Signals
Community Trust
GetShoutbox Alternatives
Get Chat App
get-chat-app
Add a WhatsApp chat button to your website in seconds. Allow visitors to simply tap to chat through WhatsApp and other different platforms.
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
chaty
WhatsApp chat, Facebook Messenger, Telegram, TikTok, Instagram, Email, Line, WeChat Phone call, SMS, 20+ live chat icons & WhatsApp chat pop up 💬
Facebook Chat Plugin – Live Chat Plugin for WordPress
facebook-messenger-customer-chat
The Facebook Chat Plugin makes it easy for your website visitors to chat with you and ask you questions, even if they don't have Messenger.
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist
bit-assist
Floating sticky chat button for WhatsApp Chat, Facebook Messenger, Telegram, Instagram, SMS, Call, Discord chat, TikTok, Line & 30+ channels
GetShoutbox Developer Profile
6 plugins · 150 total installs
How We Detect GetShoutbox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
getshoutbox-preview-containergetshoutbox-wrapper<!-- Plugin Name: GetShoutbox -->data-current-user-iddata-site-urldata-site-tokendata-chat-urldata-plugin-urlGetShoutboxPlugin[getshoutbox[shoutbox