Shois Chat Button Security & Risk Analysis

wordpress.org/plugins/shois-chat-button

WhatsApp Chat, Telegram, Messenger, Instagram, Discord, and 8+ chat apps to skyrocket your conversion rates. With Readymade templates, Animation, and …

0 active installs v1.0.0 PHP 7.4+ WP 5.8+ Updated Apr 1, 2026
chat-buttonlive-chatmessengertelegramwhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Shois Chat Button Safe to Use in 2026?

Generally Safe

Score 100/100

Shois Chat Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "shois-chat-button" plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, or external HTTP requests is highly positive. Furthermore, the consistent use of prepared statements for all SQL queries and proper output escaping for all outputs demonstrates good coding practices aimed at preventing common vulnerabilities like SQL injection and XSS.

The plugin also shows a proactive approach to security by implementing capability checks, indicating an effort to restrict functionality to authorized users. The lack of any known CVEs and a clean vulnerability history further reinforces its secure nature. The zero taint flow findings are also reassuring, suggesting no obvious paths for unsanitized data to lead to vulnerabilities.

However, the complete absence of entry points (AJAX handlers, REST API routes, shortcodes, cron events) raises a slight concern. While this contributes to a very small attack surface, it might also imply limited functionality or a design that doesn't leverage common WordPress extension mechanisms. Nevertheless, based on the data, this plugin appears to be very secure with no immediate exploitable vulnerabilities detected.

Key Concerns

  • No nonce checks implemented
Vulnerabilities
None known

Shois Chat Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Shois Chat Button Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Shois Chat Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
0
190 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

100% escaped190 total outputs
Attack Surface

Shois Chat Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuadmin/admin.php:34
actionadmin_enqueue_scriptsadmin/admin.php:43
actionadmin_initincludes/class-shcb-plugin.php:67
actionrest_api_initincludes/class-shcb-rest-api.php:28
actioninitincludes/class-shcb-template-cpt.php:44
actioninitincludes/class-shcb-template-cpt.php:45
actionwp_enqueue_scriptsincludes/class-shcb-widget-renderer.php:29
actionplugins_loadedshois-chat-button.php:67
Maintenance & Trust

Shois Chat Button Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 1, 2026
PHP min version7.4
Downloads67

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Shois Chat Button Developer Profile

Shois WP

4 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shois Chat Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shois-chat-button/admin/build/index.js/wp-content/plugins/shois-chat-button/admin/build/index.css
Version Parameters
shois-chat-button/admin/build/index.js?ver=shois-chat-button/admin/build/index.css?ver=

HTML / DOM Fingerprints

CSS Classes
shcb-admin-wrapper
Data Attributes
id="shcb-admin-root"
JS Globals
shcbAdmin
REST Endpoints
/wp-json/shois-chat/v1/
FAQ

Frequently Asked Questions about Shois Chat Button