Smartarget – Chat Buttons & Engagement Apps Security & Risk Analysis

wordpress.org/plugins/smartarget-contact-us

WhatsApp Chat, Telegram, Messenger, TikTok, Line, Viber, Instagram, Click to call, Popup and 30 more apps to boost sales and user engagement

1K active installs v1.5.3 PHP 5.2.4+ WP 3.0.1+ Updated Feb 13, 2026
chatfaqpopupreviewswhatsapp
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEFeb 3, 2025
Safety Verdict

Is Smartarget – Chat Buttons & Engagement Apps Safe to Use in 2026?

Mostly Safe

Score 79/100

Smartarget – Chat Buttons & Engagement Apps is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Feb 3, 2025Updated 1mo ago
Risk Assessment

The 'smartarget-contact-us' v1.5.3 plugin exhibits a concerning security posture despite some positive indicators. While the static analysis shows a clean slate regarding dangerous functions, SQL injection, file operations, and external HTTP requests, the lack of any identified attack surface entry points (AJAX, REST API, shortcodes, cron events) is unusual and potentially hides vulnerabilities. Furthermore, the significantly low percentage of properly escaped output (46%) is a major red flag, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks on any discovered entry points, though the number is zero, further contributes to potential insecurities if any were to be introduced or overlooked in the analysis.

The vulnerability history is a critical concern. The plugin has a known medium severity CVE that remains unpatched. The historical pattern of Cross-Site Scripting (XSS) vulnerabilities suggests a recurring issue with how user-provided data is handled. This, combined with the poor output escaping observed in the static analysis, strongly suggests that the plugin has a systemic weakness in sanitizing and escaping user input, making it susceptible to XSS attacks. While the plugin avoids some common pitfalls, the unpatched XSS vulnerability and the low output escaping percentage are significant weaknesses that outweigh the strengths.

Key Concerns

  • Unpatched medium severity CVE
  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
1

Smartarget – Chat Buttons & Engagement Apps Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22650medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Smartarget – Get 40% more sales, improve user engagement with 25+ free apps. <= 1.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting

Feb 3, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Smartarget – Chat Buttons & Engagement Apps Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

46% escaped13 total outputs
Attack Surface

Smartarget – Chat Buttons & Engagement Apps Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_noticesadmin\class-smartarget-admin.php:142
actionadmin_initadmin\class-smartarget-admin.php:157
actionplugins_loadedincludes\class-smartarget.php:142
actionadmin_enqueue_scriptsincludes\class-smartarget.php:157
actionadmin_enqueue_scriptsincludes\class-smartarget.php:158
actionadmin_menuincludes\class-smartarget.php:160
actionadmin_initincludes\class-smartarget.php:165
actionwp_enqueue_scriptsincludes\class-smartarget.php:179
actionwp_enqueue_scriptsincludes\class-smartarget.php:180
Maintenance & Trust

Smartarget – Chat Buttons & Engagement Apps Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 13, 2026
PHP min version5.2.4
Downloads28K

Community Trust

Rating92/100
Number of ratings10
Active installs1K
Developer Profile

Smartarget – Chat Buttons & Engagement Apps Developer Profile

Erez Hadas-Sonnenschein

21 plugins · 2K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smartarget – Chat Buttons & Engagement Apps

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smartarget-contact-us/admin/css/smartarget-admin.css
Script Paths
https://smartarget.online/wp-dashboard/package.jshttps://smartarget.online/loader.js
Version Parameters
smartarget-contact-us/admin/css/smartarget-admin.css?ver=smartarget-admin.css?ver=icons.css?ver=styles.css?ver=package.js?ver=loader.js?ver=

HTML / DOM Fingerprints

CSS Classes
smartarget-reviewsmartarget-plugin-ignore-notice
HTML Comments
<!-- The current version of the {your-plugin-name} is {your-plugin-name} -->
Data Attributes
data-dismissible="smartarget-review"data-dismissible="smartarget-review"
FAQ

Frequently Asked Questions about Smartarget – Chat Buttons & Engagement Apps