
WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Security & Risk Analysis
wordpress.org/plugins/support-chatOffer unlimited chat apps and support channels to your WordPress website.
Is WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Safe to Use in 2026?
Generally Safe
Score 99/100WP Click to Chat – Email, Live Chat, Call & Book Now Buttons has a strong security track record. Known vulnerabilities have been patched promptly.
The "support-chat" plugin v2.3.6 demonstrates generally good security practices, with all identified entry points having authorization checks, no dangerous functions used, and all SQL queries employing prepared statements. The plugin also shows a strong adherence to output escaping, with 87% of outputs properly sanitized, and all four AJAX handlers include nonce checks. Taint analysis did not reveal any critical or high-severity vulnerabilities related to unsanitized data flow.
Despite these strengths, the plugin has a history of two medium-severity vulnerabilities, both related to Cross-Site Scripting (XSS). The fact that the last vulnerability was dated March 27, 2025, and is currently unpatched is a significant concern, indicating a potential for recurring XSS issues or a lack of recent security maintenance. While the static analysis shows no immediate critical flaws, the historical trend of XSS vulnerabilities, coupled with the unpatched medium-severity issue, suggests a need for vigilance and further investigation into the root causes of these past issues.
In conclusion, while the current version of "support-chat" exhibits a solid foundation in secure coding practices, the historical context of medium-severity XSS vulnerabilities and the existence of an unpatched issue necessitate a cautious approach. The plugin's strengths lie in its robust handling of SQL and input validation at the entry points. However, the recurring nature of XSS and the unpatched vulnerability are significant weaknesses that could be exploited if not addressed.
Key Concerns
- Unpatched medium severity CVEs
- History of XSS vulnerabilities
- Minor output escaping concern (13% unescaped)
WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Click to Chat – WP Support All-in-One Floating Widget <= 2.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Click to Chat – WP Support All-in-One Floating Widget <= 2.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpsaio_snapchat Shortcode
WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Code Analysis
Output Escaping
Data Flow Analysis
WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Attack Surface
AJAX Handlers 4
WordPress Hooks 8
Maintenance & Trust
WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Maintenance & Trust
Maintenance Signals
Community Trust
WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Alternatives
Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons
sticky-chat-widget
Social chat buttons with WhatsApp, Messenger, WeChat, Telegram, Instagram, TikTok, Zalo & more — plus SMS, Call button, Contact form, and 20+ icons.
Floating Contact Button
madnesschat-button
Add a lightweight floating WhatsApp chat button (click to chat) with styles, triggers, responsive options, and optional GDPR consent.
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist
bit-assist
Floating sticky chat button for WhatsApp Chat, Facebook Messenger, Telegram, Instagram, SMS, Call, Discord chat, TikTok, Line & 30+ channels
Boei – Chat Widget & AI Chatbot with 50+ Channels
boei-help
Capture every lead. Reply instantly. Close more deals. AI chatbot, 50+ contact channels, single inbox, and lead tracking—all in one WordPress plugin.
Click to Call or Chat Buttons
click-to-call-or-chat-buttons
This plugin adds Phone Call and WhatsApp button on your webpage.
WP Click to Chat – Email, Live Chat, Call & Book Now Buttons Developer Profile
13 plugins · 496K total installs
How We Detect WP Click to Chat – Email, Live Chat, Call & Book Now Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/support-chat/assets/admin/css/wp-saio.css/wp-content/plugins/support-chat/assets/home/css/wp-saio.css/wp-content/plugins/support-chat/assets/admin/css/ui-range.css/wp-content/plugins/support-chat/assets/admin/js/Sortable.min.js/wp-content/plugins/support-chat/app/build/index.js/wp-content/plugins/support-chat/app/build/index.jssupport-chat/assets/admin/css/wp-saio.css?ver=support-chat/assets/home/css/wp-saio.css?ver=support-chat/assets/admin/css/ui-range.css?ver=support-chat/assets/admin/js/Sortable.min.js?ver=support-chat/app/build/index.js?ver=HTML / DOM Fingerprints
wp-saio-app-itemwp_saio_html_inputswp_saio_object