
WATI Chat and Notification Security & Risk Analysis
wordpress.org/plugins/wati-chat-and-notificationRecover your lost revenue by sending automatic cart abandonment messages on WhatsApp. Send transaction related updates on WhatsApp.
Is WATI Chat and Notification Safe to Use in 2026?
Generally Safe
Score 91/100WATI Chat and Notification has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "wati-chat-and-notification" plugin version 1.1.7 presents a mixed security posture. On the positive side, the plugin demonstrates good practices with a high percentage of SQL queries using prepared statements (91%) and properly escaped output (96%). It also correctly implements nonce and capability checks on a good portion of its entry points (3 each).
However, significant concerns arise from the presence of unprotected entry points, specifically 3 REST API routes that lack permission callbacks. This creates a substantial attack surface that could be exploited by unauthenticated users. Additionally, the discovery of the `unserialize` function, a known dangerous function, without further context on its usage, raises a potential flag for deserialization vulnerabilities. While no critical or high severity taint flows were identified, the absence of taint analysis results (0 flows analyzed) means this aspect might be incompletely assessed.
The plugin's vulnerability history shows one medium severity CVE, a Cross-Site Request Forgery (CSRF), which was last patched on March 11, 2025. While the absence of currently unpatched vulnerabilities is positive, the past existence of CSRF indicates a need for vigilance in securing forms and actions. Overall, the plugin has strengths in its implementation of secure coding practices for database and output handling, but the lack of authorization on REST API routes is a critical weakness that requires immediate attention.
Key Concerns
- REST API routes without permission callbacks
- Presence of dangerous unserialize function
- Past medium severity CVE (CSRF)
WATI Chat and Notification Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WATI Chat and Notification <= 1.1.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
WATI Chat and Notification Release Timeline
WATI Chat and Notification Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
WATI Chat and Notification Attack Surface
AJAX Handlers 4
REST API Routes 3
WordPress Hooks 14
Maintenance & Trust
WATI Chat and Notification Maintenance & Trust
Maintenance Signals
Community Trust
WATI Chat and Notification Alternatives
11za Chat and Notification
11za-chat-and-notification
Recover your lost revenue by sending automatic cart abandonment messages on WhatsApp. Send transaction related updates on WhatsApp.
CartSaver Chat Recovery
cartsaver-chat-recovery
Recover WooCommerce abandoned carts automatically via Official WhatsApp API or one-click manual links.
MegaSend for WooCommerce
megasend-for-woocommerce
Recover abandoned carts and boost sales with automated WhatsApp messages powered by MegaSend.
Quick Cart Recovery
quick-cart-recovery
Recover lost WooCommerce sales instantly via WhatsApp chat. A lightweight and powerful abandoned cart recovery tool.
ShopNotify – Personalized Cart Recovery for WooCommerce
shopnotify
Track abandoned carts for logged-in and guest users in WooCommerce, send automated WhatsApp reminders, and gain insights into cart recovery and abando …
WATI Chat and Notification Developer Profile
1 plugin · 700 total installs
How We Detect WATI Chat and Notification
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wati-chat-and-notification/assets/css/wati-chat.min.css/wp-content/plugins/wati-chat-and-notification/assets/js/wati-chat.min.jsWATI Chat and Notification/wp-content/plugins/wati-chat-and-notification/assets/js/wati-chat.min.jswati-chat-and-notification/assets/css/wati-chat.min.css?ver=wati-chat-and-notification/assets/js/wati-chat.min.js?ver=HTML / DOM Fingerprints
wati_chat_widgetdata-iddata-wati-tokenwati_initialize_chat/wp-json/api/v1/getWoocommerceInfo/wp-json/api/v1/getAccessToken/wp-json/api/v1/getOrderUrl