
Replain Security & Risk Analysis
wordpress.org/plugins/replainBe in touch with your clients through Telegram, WhatsApp or Facebook Messenger. Fast, functional and free live-chat service for your website.
Is Replain Safe to Use in 2026?
Generally Safe
Score 85/100Replain has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the 'replain' plugin v1.9.1 exhibits a strong security posture with several good practices observed. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with unauthenticated access significantly limits the attack surface. Furthermore, the code demonstrates a commitment to security by using prepared statements for all SQL queries, implementing nonce checks, and employing capability checks for its operations. The lack of any recorded vulnerabilities, critical or otherwise, in its history is a positive indicator of consistent security development.
However, a potential concern arises from the low percentage of properly escaped output (9%). With 11 total outputs analyzed, this means at least one output is likely not being adequately sanitized, which could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unsanitized outputs. While the taint analysis shows no unsanitized paths, the output escaping percentage is a specific area to monitor. The plugin also does not bundle any external libraries, which removes the risk of vulnerable bundled components.
In conclusion, the 'replain' plugin v1.9.1 is generally well-secured, with a very limited attack surface and robust handling of sensitive operations like database queries. The primary area of attention is the output escaping, which, despite the absence of explicit XSS findings in the taint analysis, represents a deviation from best practices and a potential, albeit low, risk.
Key Concerns
- Low percentage of properly escaped output
Replain Security Vulnerabilities
Replain Code Analysis
Output Escaping
Data Flow Analysis
Replain Attack Surface
WordPress Hooks 6
Maintenance & Trust
Replain Maintenance & Trust
Maintenance Signals
Community Trust
Replain Alternatives
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
JivoChat Live Chat – WP live chat plugin for WordPress
jivochat
Omnichannel Live Chat and Help Desk plugin, optimized for WordPress. Free, fast, easy to install and to use. Turn your visitors into happy customers!
Floating Contact Button for MAX and Telegram
floating-contact-button-for-max-and-telegram
A lightweight floating contact button for WordPress with support for Telegram, WhatsApp, Facebook Messenger and MAX.
Contactus
contactus
Free website widget for chatting with your visitors via WhatsApp, Facebook Messenger, Viber and Telegram.
ProProfs Chat- Live Chat & Chatbot Plugin
proprofs-chat
ProProfs Chat is a SaaS-based live chat software that helps businesses of all sizes communicate with their website visitors and customers in real-time …
Replain Developer Profile
1 plugin · 800 total installs
How We Detect Replain
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/replain/assets/css/replain-wp-toolbar-link.csshttps://widget.replain.cc/dist/client.jsHTML / DOM Fingerprints
replain-bot-linkdata-replain-idwindow.replainSettings