
WP Chat App Security & Risk Analysis
wordpress.org/plugins/wp-whatsappIntegrate WhatsApp experience directly into your WordPress website.
Is WP Chat App Safe to Use in 2026?
Generally Safe
Score 97/100WP Chat App has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-whatsapp plugin v3.7.3 exhibits a mixed security posture. On the positive side, the code analysis reveals a commendable adherence to secure coding practices, with no dangerous functions, all SQL queries using prepared statements, and a significant percentage of output being properly escaped. The presence of numerous nonce and capability checks across its AJAX handlers further suggests an effort to protect against common WordPress vulnerabilities. However, a substantial vulnerability history, with 6 known medium-severity CVEs, raises significant concerns. The prevalence of past vulnerabilities related to Missing Authorization, Cross-site Scripting, and Improper Input Validation indicates recurring weaknesses in how the plugin handles user input and controls access. While the current version shows no unpatched vulnerabilities, the historical pattern suggests a need for continued vigilance and potentially more rigorous code review in these specific areas. The overall attack surface is moderate, with 14 AJAX handlers, and thankfully, none are found to be unprotected in this analysis.
Key Concerns
- Six known medium-severity CVEs
- 73% output escaping (27% unescaped)
WP Chat App Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
WP Chat App <= 3.6.8 - Missing Authorization to Authenticated (Subscriber+) Filebird Plugin Installation
WP Chat App <= 3.6.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Chat App <= 3.6.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Chat App <= 3.6.2 - Authenticated(Contributor+) Stored Cross-Site Scripting via Block Image Attribute
WP Chat App <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes
WP Chat App <= 3.4.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Chat App Code Analysis
Output Escaping
WP Chat App Attack Surface
AJAX Handlers 14
Shortcodes 1
WordPress Hooks 39
Maintenance & Trust
WP Chat App Maintenance & Trust
Maintenance Signals
Community Trust
WP Chat App Alternatives
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Social Chat – Click To Chat App Button
wp-whatsapp-chat
WhatsApp Chat🔥 allows you to enhance customer engagement! Integrate "WhatsApp" or "WhatsApp Business" with a single click.
Contact Form to Chat Apps | Click to Chat to Order – FormyChat
social-contact-form
Connect contact forms and WooCommerce to WhatsApp by live click to chat. Send form data to WhatsApp Business for instant customer engagement
ChatHelp – Click to Chat Button, Chat to Order, Floating Chat & Form
chat-help
Add WhatsApp click to chat with floating chat button, chat to order for WooCommerce, and chat forms to convert visitors into customers.
Watso – Basic Help Chat Button
watso-basic-chat
Lightweight and blazing-fast WhatsApp chat button for WordPress with full customization, UTM tracking, multi-agent support, and scheduling.
WP Chat App Developer Profile
13 plugins · 496K total installs
How We Detect WP Chat App
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-whatsapp/assets/css/whatsapp.css/wp-content/plugins/wp-whatsapp/assets/js/whatsapp.js/wp-content/plugins/wp-whatsapp/blocks/dist/blocks.style.build.css/wp-content/plugins/wp-whatsapp/blocks/dist/blocks.build.js/wp-content/plugins/wp-whatsapp/blocks/dist/blocks.editor.build.css/wp-content/plugins/wp-whatsapp/blocks/dist/blocks.build.jswp-whatsapp/assets/css/whatsapp.css?ver=wp-whatsapp/assets/js/whatsapp.js?ver=wp-whatsapp/blocks/dist/blocks.style.build.css?ver=wp-whatsapp/blocks/dist/blocks.build.js?ver=wp-whatsapp/blocks/dist/blocks.editor.build.css?ver=HTML / DOM Fingerprints
wa__buttonwa__r_buttonwa__sq_buttonwa__button_text_onlywa__btn_iconwa__cs_imgwa__cs_img_wrapwa__btn_txt+3 more<!-- BEGIN: WP WA Button --><!-- END: WP WA Button --><!-- Shortcode Output -->data-phonedata-colordata-text-colordata-background-colordata-positiondata-size+13 morenjtwa[njwa_button[wp_whatsapp