QuickFloat Chat Security & Risk Analysis

wordpress.org/plugins/quickfloat-chat

A simple and lightweight floating chat widget with custom icons, animations, and analytics.

0 active installs v2.2.2 PHP 7.2+ WP 6.0+ Updated Dec 9, 2025
buttonchatclick-to-chatcontactwhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is QuickFloat Chat Safe to Use in 2026?

Generally Safe

Score 100/100

QuickFloat Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The quickfloat-chat plugin version 2.2.2 demonstrates a strong security posture based on the static analysis. The plugin has a limited attack surface, with only two AJAX handlers, and crucially, none of these are exposed without authentication checks. Furthermore, all identified code signals indicate good security practices: no dangerous functions were found, SQL queries are 100% prepared, and all output is properly escaped. The presence of a nonce check and the absence of file operations or external HTTP requests further bolster its security. The vulnerability history shows no recorded CVEs, suggesting a consistent track record of security. While the lack of capability checks on AJAX handlers is a minor concern, given the overall lack of critical vulnerabilities and the presence of nonce checks, the risk remains low. The plugin's strengths lie in its disciplined coding practices regarding sensitive operations and its clean vulnerability history.

Key Concerns

  • AJAX handlers without capability checks
Vulnerabilities
None known

QuickFloat Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

QuickFloat Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
32 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped32 total outputs
Attack Surface

QuickFloat Chat Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_quickfloat_free_trackquickfloat-chat.php:30
noprivwp_ajax_quickfloat_free_trackquickfloat-chat.php:31
WordPress Hooks 4
actionadmin_menuquickfloat-chat.php:22
actionadmin_initquickfloat-chat.php:23
actionwp_enqueue_scriptsquickfloat-chat.php:25
actionwp_footerquickfloat-chat.php:26
Maintenance & Trust

QuickFloat Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 9, 2025
PHP min version7.2
Downloads114

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

QuickFloat Chat Developer Profile

Delwar Hossain

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect QuickFloat Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/quickfloat-chat/assets/js/frontend.js
Script Paths
/wp-content/plugins/quickfloat-chat/assets/js/frontend.js
Version Parameters
quickfloat-chat/assets/js/frontend.js?ver=2.2.2

HTML / DOM Fingerprints

CSS Classes
quickfloat-btnquickfloat-iconquickfloat-custom-imgquickfloat-tooltipquickfloat-anim-zoomquickfloat-anim-fadequickfloat-anim-slide
Data Attributes
data-settingdata-settings
JS Globals
quickfloat_obj
REST Endpoints
/wp-json/quickfloat/v1/settings
FAQ

Frequently Asked Questions about QuickFloat Chat