
VABE / Button – Floating Chat Widget Security & Risk Analysis
wordpress.org/plugins/vabe-buttonFREE widget! Chat with your customers via WhatsApp, Facebook Messenger, Telegram, Viber and other apps.
Is VABE / Button – Floating Chat Widget Safe to Use in 2026?
Generally Safe
Score 85/100VABE / Button – Floating Chat Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "vabe-button" v1.0 plugin exhibits a strong security posture in several key areas based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the complete avoidance of dangerous functions, file operations, and external HTTP requests is commendable. The fact that all SQL queries utilize prepared statements is a critical best practice that prevents SQL injection vulnerabilities.
However, the analysis also reveals notable areas of concern. A substantial portion of output (69%) is not properly escaped, presenting a significant risk for Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks across all identified entry points (though none were found) suggests a potential weakness if new entry points are introduced without proper security measures. The fact that there are no recorded vulnerabilities in its history is positive, but the lack of historical data makes it difficult to draw strong conclusions about long-term maintainability and proactive security practices.
In conclusion, while the plugin has demonstrated good practices in preventing common vulnerabilities like SQL injection and limiting its attack surface, the high rate of unescaped output is a critical flaw that needs immediate attention. The absence of comprehensive security checks like nonces and capability checks also represents a latent risk that could be exploited if the plugin's functionality expands. Addressing the unescaped output is paramount to improving its security.
Key Concerns
- Unescaped output detected (31% properly escaped)
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
VABE / Button – Floating Chat Widget Security Vulnerabilities
VABE / Button – Floating Chat Widget Release Timeline
VABE / Button – Floating Chat Widget Code Analysis
Output Escaping
VABE / Button – Floating Chat Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
VABE / Button – Floating Chat Widget Maintenance & Trust
Maintenance Signals
Community Trust
VABE / Button – Floating Chat Widget Alternatives
Joinchat
creame-whatsapp-me
WhatsApp, Messenger, Telegram, Phone call… capture users through their favorite Apps and turn into clients
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
chaty
WhatsApp chat, Facebook Messenger, Telegram, TikTok, Instagram, Email, Line, WeChat Phone call, SMS, 20+ live chat icons & WhatsApp chat pop up 💬
Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat – Bit Assist
bit-assist
Floating sticky chat button for WhatsApp Chat, Facebook Messenger, Telegram, Instagram, SMS, Call, Discord chat, TikTok, Line & 30+ channels
Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons
sticky-chat-widget
Social chat buttons with WhatsApp, Messenger, WeChat, Telegram, Instagram, TikTok, Zalo & more — plus SMS, Call button, Contact form, and 20+ icons.
SiteLeads
siteleads
Capture more leads automatically with a multi-channel contact widget and a free AI assistant that works 24/7.
VABE / Button – Floating Chat Widget Developer Profile
1 plugin · 40 total installs
How We Detect VABE / Button – Floating Chat Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<textarea cols="80" rows="15" name="vabe-code">