Simple Webchat Security & Risk Analysis

wordpress.org/plugins/quick-whatsapp

Ermöglicht es Webseitenbesuchern, Sie direkt über WhatsApp zu kontaktieren.

1K active installs v3.6.1 PHP + WP 4.0+ Updated May 28, 2025
chatcontactsharesocial-mediawhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Webchat Safe to Use in 2026?

Generally Safe

Score 100/100

Simple Webchat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "quick-whatsapp" plugin v3.6.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL query handling, exclusively using prepared statements, and implements a substantial number of nonce checks. It also has no known CVEs and no recorded vulnerabilities, suggesting a generally stable security history. However, there are significant concerns arising from the static analysis. The most notable issue is the low percentage of properly escaped output (31%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals a concerning number of flows with unsanitized paths (17 out of 18), even though no critical or high severity issues were flagged in the taint analysis itself. This could indicate potential for vulnerabilities if user-supplied data is not properly handled, despite the current lack of severe findings. The absence of capability checks on entry points is also a potential weakness, as it relies solely on nonce checks for authorization.

Key Concerns

  • Low output escaping percentage
  • High percentage of unsanitized paths in taint analysis
  • No capability checks on entry points
Vulnerabilities
None known

Simple Webchat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Webchat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
96
44 escaped
Nonce Checks
27
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

31% escaped140 total outputs
Data Flows
17 unsanitized

Data Flow Analysis

18 flows17 with unsanitized paths
saveForm_quickwhatsappbutton_style (form.php:606)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Simple Webchat Attack Surface

Entry Points5
Unprotected0

Shortcodes 5

[quickwhatsapp_group] simple-webchat-whatsapp-shortcode-gruppe.php:43
[quickwhatsapp_group2] simple-webchat-whatsapp-shortcode-gruppe.php:89
[quickwhatsapp_group3] simple-webchat-whatsapp-shortcode-gruppe.php:134
[quickwhatsapp_chat] whatsapp-shortcode-chat.php:106
[quickwhatsapp_share] whatsapp-shortcode-sharing.php:97
WordPress Hooks 8
actionadmin_menuconf.php:18
actioninitsimple-webchat.php:26
actionadmin_noticessimple-webchat.php:46
actionadmin_noticessimple-webchat.php:68
actionwoocommerce_after_add_to_cart_buttonwhatsapp-button-after-addtocart.php:7
actionwp_enqueue_scriptswhatsapp-floating-button.php:8
actionwp_footerwhatsapp-floating-button.php:17
filterthe_contentwhatsapp-standard.php:3
Maintenance & Trust

Simple Webchat Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 28, 2025
PHP min version
Downloads73K

Community Trust

Rating100/100
Number of ratings4
Active installs1K
Developer Profile

Simple Webchat Developer Profile

Eric-Oliver Mächler

11 plugins · 5K total installs

96
trust score
Avg Security Score
94/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Simple Webchat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quick-whatsapp/css/quick-whatsapp-floating-button.php

HTML / DOM Fingerprints

CSS Classes
simplewebchat_float
Shortcode Output
<a href='https://chat.whatsapp.com/' target='_blank'>
FAQ

Frequently Asked Questions about Simple Webchat