
Rashid Floating Chat Button Security & Risk Analysis
wordpress.org/plugins/rashid-floating-chat-buttonAdd a lightweight, customizable floating chat button to your WordPress site. Click-to-chat functionality for mobile and desktop.
Is Rashid Floating Chat Button Safe to Use in 2026?
Generally Safe
Score 100/100Rashid Floating Chat Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rashid-floating-chat-button" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for SQL queries, and proper output escaping for all identified outputs are positive indicators. The plugin also demonstrates good practices by avoiding file operations and external HTTP requests, and it does not bundle any libraries that could introduce known vulnerabilities. Furthermore, the plugin has no recorded vulnerability history, which suggests a history of secure development or prompt patching of any past issues.
However, a significant concern arises from the complete lack of nonce checks. While there are no AJAX handlers or REST API routes that would typically require nonces, the presence of a shortcode without a nonce check, coupled with a single capability check, leaves a potential, albeit small, attack surface. If the shortcode's functionality were to be exploited, an attacker might be able to trigger actions without proper user authorization. The current analysis doesn't reveal any critical or high-severity taint flows, which is reassuring, but the absence of nonce checks on any user-facing input, even within a shortcode, represents a potential weakness that could be exploited in specific scenarios.
Key Concerns
- No nonce checks on shortcode
Rashid Floating Chat Button Security Vulnerabilities
Rashid Floating Chat Button Release Timeline
Rashid Floating Chat Button Code Analysis
Output Escaping
Rashid Floating Chat Button Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Rashid Floating Chat Button Maintenance & Trust
Maintenance Signals
Community Trust
Rashid Floating Chat Button Alternatives
1R Chat Button
1r-chat-button
Lightweight floating contact button for WordPress with email, phone, WhatsApp, Facebook Messenger, Viber, Telegram, WeChat, Line, Signal, VK, KakaoTal …
MW Messenger Button
mw-messenger-button
Adds an animated WhatsApp button to your site with customizable options: phone number, color, text, position, alignment, CSS class/ID, visibility, and …
NXT Floating Chat Widget
nxt-floating-chat-widget
A lightweight, customizable WhatsApp floating button with position, size options, and optional click tracking.
Advanced Contact Button
advanced-contact-button
Add beautiful floating contact buttons (Call, Email, WhatsApp, WeChat) to your WordPress website with customizable settings.
AK Simple Chat
ak-simple-chat
Add a floating WhatsApp chat button with multiple agents, labels, colors, and WooCommerce support using a simple admin interface.
Rashid Floating Chat Button Developer Profile
1 plugin · 0 total installs
How We Detect Rashid Floating Chat Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rashid-floating-chat-button/assets/css/style.css/wp-content/plugins/rashid-floating-chat-button/assets/js/script.js/wp-content/plugins/rashid-floating-chat-button/assets/js/script.jsrashid-floating-chat-button/assets/css/style.css?ver=rashid-floating-chat-button/assets/js/script.js?ver=HTML / DOM Fingerprints
rfcb-whatsapp-buttonrfcb-position-rightrfcb-position-leftrfcb-button-linkitemscopeitemtype="https://schema.org/ContactPoint"rfcbSettings[rfcb_button