WazChat – Chat button widget Security & Risk Analysis

wordpress.org/plugins/wazchat-chat-button-widget

WazChat allows your visitors to contact you or your team through WhatsApp with a single click.

0 active installs v1.0.0 PHP 7.2+ WP 4.7+ Updated Aug 26, 2025
chatcontactmessengersupportwhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WazChat – Chat button widget Safe to Use in 2026?

Generally Safe

Score 100/100

WazChat – Chat button widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The 'wazchat-chat-button-widget' plugin v1.0.0 exhibits a generally good security posture regarding common WordPress vulnerabilities. The static analysis reveals no dangerous function usage, no raw SQL queries, and all output is properly escaped. Furthermore, there are no known historical vulnerabilities or CVEs associated with this plugin, suggesting a history of secure development or a lack of public exposure to sophisticated attacks. The plugin also demonstrates good practices in using prepared statements for any SQL queries and includes a nonce check.

However, a significant concern arises from the plugin's attack surface, specifically its REST API routes. Out of three REST API routes, two lack proper permission callbacks. This means that any user, regardless of their role or capabilities, could potentially interact with these unprotected routes, opening them up to unauthorized access and manipulation. While taint analysis shows no current issues, the unprotected REST API routes represent a tangible risk that could be exploited if malicious input is passed to them.

In conclusion, while the plugin avoids many typical web application vulnerabilities like SQL injection and XSS due to its coding practices and lack of historical issues, the presence of two unprotected REST API endpoints is a critical weakness. This exposes a portion of the plugin's functionality to potential misuse. Developers should prioritize implementing appropriate permission checks for these REST API routes to fully secure the plugin.

Key Concerns

  • REST API routes without permission callbacks
Vulnerabilities
None known

WazChat – Chat button widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WazChat – Chat button widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
33 escaped
Nonce Checks
1
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped33 total outputs
Attack Surface
2 unprotected

WazChat – Chat button widget Attack Surface

Entry Points3
Unprotected2

REST API Routes 3

GET/wp-json/wazchat/v1/widget/(?P<id>\d+)inc\class-wazchat856-api.php:47
GET/wp-json/wazchat/v1/widgetsinc\class-wazchat856-api.php:65
POST/wp-json/wazchat/v1/submit/(?P<id>\d+)inc\class-wazchat856-api.php:76
WordPress Hooks 24
actionadmin_enqueue_scriptsinc\class-wazchat856-admin.php:76
actionadmin_enqueue_scriptsinc\class-wazchat856-admin.php:77
actionadmin_menuinc\class-wazchat856-admin.php:78
filterwazchat_856_js_admin_datainc\class-wazchat856-admin.php:80
filterwazchat_856_js_public_datainc\class-wazchat856-admin.php:81
actionadmin_initinc\class-wazchat856-admin.php:83
filteradmin_body_classinc\class-wazchat856-admin.php:134
filterscreen_options_show_screeninc\class-wazchat856-admin.php:256
filtersubmenu_fileinc\class-wazchat856-admin.php:304
actionrest_api_initinc\class-wazchat856-api.php:38
actioninitinc\class-wazchat856-chatform.php:37
actionwazchat_856_after_register_chatform_post_typeinc\class-wazchat856-chatform.php:38
actionrest_prepare_wazchat_856_chatforminc\class-wazchat856-chatform.php:39
filterrest_pre_insert_wazchat_856_chatforminc\class-wazchat856-chatform.php:41
actionafter_premium_version_activationinc\class-wazchat856-core.php:69
actionwp_enqueue_scriptsinc\class-wazchat856-wazchat.php:37
actionwp_footerinc\class-wazchat856-wazchat.php:40
actioninitinc\class-wazchat856-wazchat.php:43
actioninitinc\class-wazchat856-widget.php:40
actionwazchat_856_after_register_waz_widget_post_typeinc\class-wazchat856-widget.php:41
actionrest_prepare_wazchat_856_widgetinc\class-wazchat856-widget.php:42
filterrest_pre_insert_wazchat_856_widgetinc\class-wazchat856-widget.php:43
filterwazchat_856_widget_editor_settingsinc\class-wazchat856-widget.php:44
filterrest_pre_insert_wazchat_856_widgetinc\class-wazchat856-widget.php:47
Maintenance & Trust

WazChat – Chat button widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 26, 2025
PHP min version7.2
Downloads225

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WazChat – Chat button widget Developer Profile

awsm.in

7 plugins · 100K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
115 days
View full developer profile
Detection Fingerprints

How We Detect WazChat – Chat button widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wazchat-chat-button-widget/build/admin/index.css/wp-content/plugins/wazchat-chat-button-widget/build/admin/index.js
Script Paths
/wp-content/plugins/wazchat-chat-button-widget/build/admin/index.js
Version Parameters
wazchat-856-admin/index.js?ver=wazchat-856-admin/index.css?ver=

HTML / DOM Fingerprints

JS Globals
wazchatAdminwazchatData
REST Endpoints
/wazchat/v1
FAQ

Frequently Asked Questions about WazChat – Chat button widget