
Chat Button & Custom ChatGPT-Powered Bot by GetButton.io Security & Risk Analysis
wordpress.org/plugins/whatshelp-chat-buttonFloating button for chatting with your visitors via WhatsApp, Messenger, Contact form, and more.
Is Chat Button & Custom ChatGPT-Powered Bot by GetButton.io Safe to Use in 2026?
Generally Safe
Score 100/100Chat Button & Custom ChatGPT-Powered Bot by GetButton.io has a strong security track record. Known vulnerabilities have been patched promptly.
The "whatshelp-chat-button" plugin v1.9.2 demonstrates a mixed security posture. On the positive side, the static analysis reveals a commendably small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code shows good practices in SQL query handling, exclusively using prepared statements, and no file operations or external HTTP requests were detected, all contributing to a reduced risk of common vulnerabilities.
However, there are significant areas of concern. The low percentage of properly escaped output (10%) is a major red flag, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. This is further corroborated by the vulnerability history, which shows a past medium-severity XSS vulnerability, suggesting a recurring weakness in input sanitization. The complete absence of nonce and capability checks, while tied to the zero-attack-surface finding, means that any future expansion of features without proper authorization checks could immediately expose the plugin to serious risks.
In conclusion, while the plugin has a minimal attack surface and handles database queries securely, the poor output escaping and past XSS vulnerability highlight a critical weakness in handling user-provided data. The lack of any authorization checks also presents a latent risk. The plugin's security is heavily reliant on its limited functionality; any feature expansion would require immediate attention to input validation and output escaping.
Key Concerns
- Low percentage of properly escaped output
- Past medium severity XSS vulnerability
- No nonce checks
- No capability checks
Chat Button & Custom ChatGPT-Powered Bot by GetButton.io Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Chat Button <= 1.8.9.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings
Chat Button & Custom ChatGPT-Powered Bot by GetButton.io Code Analysis
Output Escaping
Chat Button & Custom ChatGPT-Powered Bot by GetButton.io Attack Surface
WordPress Hooks 2
Maintenance & Trust
Chat Button & Custom ChatGPT-Powered Bot by GetButton.io Maintenance & Trust
Maintenance Signals
Community Trust
Chat Button & Custom ChatGPT-Powered Bot by GetButton.io Alternatives
Animated Floating Chat Button
animated-floating-chat-button
Adds an animated floating chat button to the WordPress site, making communication easier.
Easy WP Chat Integration
easy-wp-chat-integration
Custom Phone Call and WhatsApp Chat Button for website.
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
chaty
WhatsApp chat, Facebook Messenger, Telegram, TikTok, Instagram, Email, Line, WeChat Phone call, SMS, 20+ live chat icons & WhatsApp chat pop up 💬
Buttonizer – Live Chat, AI Chatbot, & Chat Widgets
button-contact-vr
Powerful platform with Live Chat, AI Chatbots, and Real-Time Visitor Monitoring! Also, create Call, Email, SMS, & Contact buttons to increase conv …
Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons
chatway-live-chat
AI chatbot & live chat for customer support, FAQ, chat buttons including WhatsApp with Chatway live chat. iOS & Android apps available 💬
Chat Button & Custom ChatGPT-Powered Bot by GetButton.io Developer Profile
1 plugin · 20K total installs
How We Detect Chat Button & Custom ChatGPT-Powered Bot by GetButton.io
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whatshelp-chat-button/img/wh-icon.icoHTML / DOM Fingerprints
<!-- GetButton.io widget --><!-- /GetButton.io widget -->data-no-optimize="1"WhWidgetSendButton<script data-no-optimize="1" defer src="https://static.getbutton.io/widget/bundle.js?id=<img src="https://getbutton.io/wp-content/uploads/2019/09/cropped-getbutton_logo-32x32.png" style="max-width: 250px;"><img src="plugin_dir_url(__FILE__) . 'img/getbutton_logo.png'" style="max-width: 250px;">