WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Security & Risk Analysis

wordpress.org/plugins/support-chat

Offer unlimited chat apps and support channels to your WordPress website.

1K active installs v2.3.6 PHP + WP 3.0+ Updated Nov 4, 2025
chatchat-widgetcontactsticky-buttonwhatsapp
99
A · Safe
CVEs total2
Unpatched0
Last CVEMar 27, 2025
Safety Verdict

Is WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Safe to Use in 2026?

Generally Safe

Score 99/100

WP Click to Chat – Email, Live Chat, Call & Book Now Buttons has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Mar 27, 2025Updated 5mo ago
Risk Assessment

The "support-chat" plugin v2.3.6 demonstrates generally good security practices, with all identified entry points having authorization checks, no dangerous functions used, and all SQL queries employing prepared statements. The plugin also shows a strong adherence to output escaping, with 87% of outputs properly sanitized, and all four AJAX handlers include nonce checks. Taint analysis did not reveal any critical or high-severity vulnerabilities related to unsanitized data flow.

Despite these strengths, the plugin has a history of two medium-severity vulnerabilities, both related to Cross-Site Scripting (XSS). The fact that the last vulnerability was dated March 27, 2025, and is currently unpatched is a significant concern, indicating a potential for recurring XSS issues or a lack of recent security maintenance. While the static analysis shows no immediate critical flaws, the historical trend of XSS vulnerabilities, coupled with the unpatched medium-severity issue, suggests a need for vigilance and further investigation into the root causes of these past issues.

In conclusion, while the current version of "support-chat" exhibits a solid foundation in secure coding practices, the historical context of medium-severity XSS vulnerabilities and the existence of an unpatched issue necessitate a cautious approach. The plugin's strengths lie in its robust handling of SQL and input validation at the entry points. However, the recurring nature of XSS and the unpatched vulnerability are significant weaknesses that could be exploited if not addressed.

Key Concerns

  • Unpatched medium severity CVEs
  • History of XSS vulnerabilities
  • Minor output escaping concern (13% unescaped)
Vulnerabilities
2

WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-31092medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Click to Chat – WP Support All-in-One Floating Widget <= 2.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 27, 2025 Patched in 2.3.5 (205d)
CVE-2024-10055medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Click to Chat – WP Support All-in-One Floating Widget <= 2.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpsaio_snapchat Shortcode

Oct 17, 2024 Patched in 2.3.4 (1d)
Code Analysis
Analyzed Mar 16, 2026

WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
218 escaped
Nonce Checks
4
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

87% escaped250 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
set_design_settings (src\WpSaioAjax.class.php:74)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_wpsaio_choose_apps_settingssrc\WpSaioAjax.class.php:10
authwp_ajax_wpsaio_design_settingssrc\WpSaioAjax.class.php:11
authwp_ajax_wpsaio_display_settingssrc\WpSaioAjax.class.php:12
authwp_ajax_wpsaio_review_trackedsrc\WpSaioAjax.class.php:13
WordPress Hooks 8
actioninitsrc\WpSaioInit.class.php:14
actionadmin_enqueue_scriptssrc\WpSaioInit.class.php:19
actionwp_enqueue_scriptssrc\WpSaioInit.class.php:20
actionadmin_menusrc\WpSaioInit.class.php:25
actionadmin_headsrc\WpSaioInit.class.php:30
actionwp_footersrc\WpSaioInit.class.php:35
actionadmin_initsrc\WpSaioInit.class.php:52
actioninitsrc\WpSaioShortcodes.class.php:9
Maintenance & Trust

WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 4, 2025
PHP min version
Downloads18K

Community Trust

Rating100/100
Number of ratings7
Active installs1K
Developer Profile

WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Developer Profile

Ninja Team

13 plugins · 496K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
93 days
View full developer profile
Detection Fingerprints

How We Detect WP Click to Chat – Email, Live Chat, Call & Book Now Buttons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/support-chat/assets/admin/css/wp-saio.css/wp-content/plugins/support-chat/assets/home/css/wp-saio.css/wp-content/plugins/support-chat/assets/admin/css/ui-range.css/wp-content/plugins/support-chat/assets/admin/js/Sortable.min.js/wp-content/plugins/support-chat/app/build/index.js
Script Paths
/wp-content/plugins/support-chat/app/build/index.js
Version Parameters
support-chat/assets/admin/css/wp-saio.css?ver=support-chat/assets/home/css/wp-saio.css?ver=support-chat/assets/admin/css/ui-range.css?ver=support-chat/assets/admin/js/Sortable.min.js?ver=support-chat/app/build/index.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-saio-app-item
Data Attributes
wp_saio_html_inputs
JS Globals
wp_saio_object
FAQ

Frequently Asked Questions about WP Click to Chat – Email, Live Chat, Call & Book Now Buttons