VW Floating Chat Security & Risk Analysis

wordpress.org/plugins/vw-floating-chat

A draggable floating chat widget offering WhatsApp, email, and call shortcuts with adjustable icon sizing.

100 active installs v1.2.0 PHP 7.4+ WP 5.8+ Updated Dec 18, 2025
chatcontactfloatingsupportwhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is VW Floating Chat Safe to Use in 2026?

Generally Safe

Score 100/100

VW Floating Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "vw-floating-chat" v1.2.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of critical security signals such as dangerous functions, raw SQL queries, and taint flows with unsanitized paths is highly positive. Furthermore, the plugin demonstrates good practices by consistently using prepared statements for SQL queries and maintaining a high percentage of properly escaped output. The limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, further enhances its security profile, suggesting a well-contained plugin.

While the code analysis reveals no immediate vulnerabilities, the presence of 4 capability checks and 82% output escaping, though generally good, indicates areas where an attacker might potentially find edge cases for exploitation. The lack of nonce checks on any entry points, coupled with no explicit permission callbacks on REST API routes (though none were found), could present a risk if new entry points were introduced or existing ones were exposed without proper authentication in future updates. The plugin's vulnerability history is clean, with no known CVEs, which is a significant strength. However, this could also be interpreted as a lack of rigorous past security audits or a limited history of public disclosures. The overall assessment is that the plugin is currently secure, but ongoing vigilance and attention to future updates are recommended, particularly concerning any new entry points or changes in output escaping efficiency.

Key Concerns

  • Nonce checks missing on entry points
  • Output escaping not 100% proper
Vulnerabilities
None known

VW Floating Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

VW Floating Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
168 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped206 total outputs
Attack Surface

VW Floating Chat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuincludes\class-vwfc-admin.php:30
actionadmin_initincludes\class-vwfc-admin.php:31
actionadmin_enqueue_scriptsincludes\class-vwfc-admin.php:32
actionwp_enqueue_scriptsincludes\class-vwfc-frontend.php:27
actionwp_footerincludes\class-vwfc-frontend.php:28
actionplugins_loadedvw-floating-chat.php:78
Maintenance & Trust

VW Floating Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 18, 2025
PHP min version7.4
Downloads304

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

VW Floating Chat Developer Profile

vendweave

2 plugins · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect VW Floating Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vw-floating-chat/admin/css/vwfc-admin.css/wp-content/plugins/vw-floating-chat/admin/js/vwfc-admin.js/wp-content/plugins/vw-floating-chat/assets/css/frontend.css/wp-content/plugins/vw-floating-chat/assets/js/frontend.js
Script Paths
/wp-content/plugins/vw-floating-chat/admin/js/vwfc-admin.js/wp-content/plugins/vw-floating-chat/assets/js/frontend.js
Version Parameters
vw-floating-chat/admin/css/vwfc-admin.css?ver=vw-floating-chat/admin/js/vwfc-admin.js?ver=vw-floating-chat/assets/css/frontend.css?ver=vw-floating-chat/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
vwfc-chat-widgetvwfc-channel-itemvwfc-channel-iconvwfc-channel-labelvwfc-toggle-buttonvwfc-chat-contentvwfc-chat-headervwfc-chat-body+6 more
Data Attributes
data-vwfc-channel-slugdata-vwfc-channel-labeldata-vwfc-channel-type
JS Globals
VWFCAdmin
FAQ

Frequently Asked Questions about VW Floating Chat