
WazChat – Chat button widget Security & Risk Analysis
wordpress.org/plugins/wazchat-chat-button-widgetWazChat allows your visitors to contact you or your team through WhatsApp with a single click.
Is WazChat – Chat button widget Safe to Use in 2026?
Generally Safe
Score 100/100WazChat – Chat button widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wazchat-chat-button-widget' plugin v1.0.0 exhibits a generally good security posture regarding common WordPress vulnerabilities. The static analysis reveals no dangerous function usage, no raw SQL queries, and all output is properly escaped. Furthermore, there are no known historical vulnerabilities or CVEs associated with this plugin, suggesting a history of secure development or a lack of public exposure to sophisticated attacks. The plugin also demonstrates good practices in using prepared statements for any SQL queries and includes a nonce check.
However, a significant concern arises from the plugin's attack surface, specifically its REST API routes. Out of three REST API routes, two lack proper permission callbacks. This means that any user, regardless of their role or capabilities, could potentially interact with these unprotected routes, opening them up to unauthorized access and manipulation. While taint analysis shows no current issues, the unprotected REST API routes represent a tangible risk that could be exploited if malicious input is passed to them.
In conclusion, while the plugin avoids many typical web application vulnerabilities like SQL injection and XSS due to its coding practices and lack of historical issues, the presence of two unprotected REST API endpoints is a critical weakness. This exposes a portion of the plugin's functionality to potential misuse. Developers should prioritize implementing appropriate permission checks for these REST API routes to fully secure the plugin.
Key Concerns
- REST API routes without permission callbacks
WazChat – Chat button widget Security Vulnerabilities
WazChat – Chat button widget Code Analysis
Output Escaping
WazChat – Chat button widget Attack Surface
REST API Routes 3
WordPress Hooks 24
Maintenance & Trust
WazChat – Chat button widget Maintenance & Trust
Maintenance Signals
Community Trust
WazChat – Chat button widget Alternatives
Hibiscus Instant Chat
hibiscus-instant-chat
Hibiscus Instant Chat — Turn your website visitors into instant conversations with a simple and customizable chat widget.
Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons
sticky-chat-widget
Social chat buttons with WhatsApp, Messenger, WeChat, Telegram, Instagram, TikTok, Zalo & more — plus SMS, Call button, Contact form, and 20+ icons.
VW Floating Chat
vw-floating-chat
A draggable floating chat widget offering WhatsApp, email, and call shortcuts with adjustable icon sizing.
Chat Widget for FlowFunnel
chat-widget-for-flowfunnel
Add a floating WhatsApp chat widget to your WordPress site with customizable styles, inquiry options, and click analytics.
ClickDock – Instant Message, Call, Contact & More
clickdock-instant-message-call-contact-more
ClickDock is a customizable floating contact widget that lets your visitors reach you through WhatsApp, Messenger, Call, Email, Telegram, and more.
WazChat – Chat button widget Developer Profile
7 plugins · 100K total installs
How We Detect WazChat – Chat button widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wazchat-chat-button-widget/build/admin/index.css/wp-content/plugins/wazchat-chat-button-widget/build/admin/index.js/wp-content/plugins/wazchat-chat-button-widget/build/admin/index.jswazchat-856-admin/index.js?ver=wazchat-856-admin/index.css?ver=HTML / DOM Fingerprints
wazchatAdminwazchatData/wazchat/v1