
WP-AddonChat Security & Risk Analysis
wordpress.org/plugins/wp-addonchatWP-AddonChat provides an easy and quick way to integrate AddonInteractive's AddonChat software into your WordPress install.
Is WP-AddonChat Safe to Use in 2026?
Generally Safe
Score 85/100WP-AddonChat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-addonchat plugin v2.0.0 exhibits a mixed security posture. On one hand, it demonstrates good practices by utilizing prepared statements for all SQL queries and having no known historical vulnerabilities. It also has a very small attack surface, with only one entry point and no unprotected handlers. However, several concerning code signals and taint analysis results indicate potential weaknesses.
The use of the deprecated `create_function` is a significant security risk, as it can be exploited to execute arbitrary PHP code. Furthermore, 50% of output escaping is a considerable concern; improperly escaped output can lead to Cross-Site Scripting (XSS) vulnerabilities. The taint analysis reveals two high-severity flows with unsanitized paths, strongly suggesting potential for injection attacks, particularly if user-supplied data is involved in these flows without proper sanitization before use. The lack of capability checks for any entry points, while the attack surface is small, still represents a missed security control.
While the plugin has no recorded CVEs, this does not guarantee its security, especially given the identified code signals and taint analysis findings. The absence of vulnerabilities in its history might be due to limited security auditing or an older development cycle. The critical need to address the `create_function` usage and the high-severity taint flows, along with improving output escaping, should be the primary focus for improving this plugin's security.
Key Concerns
- Use of create_function
- High severity taint flows (2)
- 50% of outputs not properly escaped
- No capability checks
WP-AddonChat Security Vulnerabilities
WP-AddonChat Release Timeline
WP-AddonChat Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP-AddonChat Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
WP-AddonChat Maintenance & Trust
Maintenance Signals
Community Trust
WP-AddonChat Alternatives
Unicode Character Keyboard
unicode-character-keyboard
Admin widget on the Write Post or Write Page forms for inserting HTML encodings of Unicode characters into the edit window.
Easy
easy
Easy, but complex widget website builder.
2046's Loop widget
2046s-widget-loops
2046's loop widget boosts you website prototyping.
Elementor Custom Skin
ele-custom-skin
Create new skins for Elementor PRO 3.x page builder. Design your own skins for Post and Post Archive Widgets using Elementor Loop Templates.
Reveal IDs
reveal-ids-for-wp-admin-25
What this plugin does is to reveal most removed IDs on admin pages, as it was in versions prior to 2.5.
WP-AddonChat Developer Profile
14 plugins · 780 total installs
How We Detect WP-AddonChat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-addonchat/resources/admin.css/wp-content/plugins/wp-addonchat/resources/admin.js/wp-content/plugins/wp-addonchat/resources/admin.jswp-addonchat/resources/admin.js?ver=wp-addonchat/resources/admin.css?ver=HTML / DOM Fingerprints
[addonchat]