
sendMeMsg Security & Risk Analysis
wordpress.org/plugins/sendmemsgThis plugin provide a widget button that allow users to send direct message to you whatsapp account , you can change the number who you users send to …
Is sendMeMsg Safe to Use in 2026?
Generally Safe
Score 85/100sendMeMsg has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "sendmemsg" v1.0.0 plugin exhibits a very strong security posture. The static analysis reveals an extremely limited attack surface with zero entry points identified, meaning there are no directly exposed AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is commendable. The code also demonstrates good practices in its SQL queries, with 100% utilizing prepared statements, and a high percentage (86%) of its outputs are properly escaped, which is a significant mitigation against cross-site scripting (XSS) vulnerabilities. The taint analysis finding zero flows with unsanitized paths further reinforces this positive assessment.
However, a notable concern is the complete absence of nonce checks and capability checks. While the current attack surface is zero, any future additions or modifications that introduce new entry points without these fundamental security mechanisms would immediately introduce significant vulnerabilities, particularly for AJAX and REST API interactions. The vulnerability history being entirely clear is a strong positive indicator of diligent development and maintenance, suggesting a commitment to security. In conclusion, "sendmemsg" v1.0.0 is currently very secure due to its limited attack surface and good coding practices. The primary weakness lies in the lack of built-in security checks like nonces and capability checks, which, if left unaddressed, could become a critical security flaw if the plugin's functionality expands.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
- Low percentage of output escaping (86%)
sendMeMsg Security Vulnerabilities
sendMeMsg Code Analysis
Output Escaping
sendMeMsg Attack Surface
WordPress Hooks 2
Maintenance & Trust
sendMeMsg Maintenance & Trust
Maintenance Signals
Community Trust
sendMeMsg Alternatives
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
chaty
WhatsApp chat, Facebook Messenger, Telegram, TikTok, Instagram, Email, Line, WeChat Phone call, SMS, 20+ live chat icons & WhatsApp chat pop up 💬
All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements
mystickyelements
Get leads with a floating contact form tab, chat & social buttons like Facebook Messenger, WhatsApp, Viber, Telegram, Twitter, Instagram & more 🎉
Chat Button & Custom ChatGPT-Powered Bot by GetButton.io
whatshelp-chat-button
Floating button for chatting with your visitors via WhatsApp, Messenger, Contact form, and more.
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist
bit-assist
Floating sticky chat button for WhatsApp Chat, Facebook Messenger, Telegram, Instagram, SMS, Call, Discord chat, TikTok, Line & 30+ channels
sendMeMsg Developer Profile
8 plugins · 10 total installs
How We Detect sendMeMsg
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sendmemsg/includes/sendmemsg-scripts.php