
Smartarget – Chat Buttons & Engagement Apps Security & Risk Analysis
wordpress.org/plugins/smartarget-contact-usWhatsApp Chat, Telegram, Messenger, TikTok, Line, Viber, Instagram, Click to call, Popup and 30 more apps to boost sales and user engagement
Is Smartarget – Chat Buttons & Engagement Apps Safe to Use in 2026?
Mostly Safe
Score 79/100Smartarget – Chat Buttons & Engagement Apps is generally safe to use. 1 past CVE were resolved. Keep it updated.
The 'smartarget-contact-us' v1.5.3 plugin exhibits a concerning security posture despite some positive indicators. While the static analysis shows a clean slate regarding dangerous functions, SQL injection, file operations, and external HTTP requests, the lack of any identified attack surface entry points (AJAX, REST API, shortcodes, cron events) is unusual and potentially hides vulnerabilities. Furthermore, the significantly low percentage of properly escaped output (46%) is a major red flag, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks on any discovered entry points, though the number is zero, further contributes to potential insecurities if any were to be introduced or overlooked in the analysis.
The vulnerability history is a critical concern. The plugin has a known medium severity CVE that remains unpatched. The historical pattern of Cross-Site Scripting (XSS) vulnerabilities suggests a recurring issue with how user-provided data is handled. This, combined with the poor output escaping observed in the static analysis, strongly suggests that the plugin has a systemic weakness in sanitizing and escaping user input, making it susceptible to XSS attacks. While the plugin avoids some common pitfalls, the unpatched XSS vulnerability and the low output escaping percentage are significant weaknesses that outweigh the strengths.
Key Concerns
- Unpatched medium severity CVE
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
Smartarget – Chat Buttons & Engagement Apps Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Smartarget – Get 40% more sales, improve user engagement with 25+ free apps. <= 1.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Smartarget – Chat Buttons & Engagement Apps Code Analysis
Output Escaping
Smartarget – Chat Buttons & Engagement Apps Attack Surface
WordPress Hooks 9
Maintenance & Trust
Smartarget – Chat Buttons & Engagement Apps Maintenance & Trust
Maintenance Signals
Community Trust
Smartarget – Chat Buttons & Engagement Apps Alternatives
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
chaty
WhatsApp chat, Facebook Messenger, Telegram, TikTok, Instagram, Email, Line, WeChat Phone call, SMS, 20+ live chat icons & WhatsApp chat pop up 💬
Social Chat – Click To Chat App Button
wp-whatsapp-chat
WhatsApp Chat🔥 allows you to enhance customer engagement! Integrate "WhatsApp" or "WhatsApp Business" with a single click.
WP Chat App
wp-whatsapp
Integrate WhatsApp experience directly into your WordPress website.
Smartarget – Chat Buttons & Engagement Apps Developer Profile
21 plugins · 2K total installs
How We Detect Smartarget – Chat Buttons & Engagement Apps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smartarget-contact-us/admin/css/smartarget-admin.csshttps://smartarget.online/wp-dashboard/package.jshttps://smartarget.online/loader.jssmartarget-contact-us/admin/css/smartarget-admin.css?ver=smartarget-admin.css?ver=icons.css?ver=styles.css?ver=package.js?ver=loader.js?ver=HTML / DOM Fingerprints
smartarget-reviewsmartarget-plugin-ignore-notice<!--
The current version of the {your-plugin-name} is {your-plugin-name} -->
data-dismissible="smartarget-review"data-dismissible="smartarget-review"