Yappr Chat Widget Security & Risk Analysis

wordpress.org/plugins/yappr-chat-widget

Add the Yappr chat widget to your WordPress site.

0 active installs v1.0.1 PHP 7.4+ WP 6.0+ Updated Feb 12, 2026
automationchatbotcustomer-supportlive-chattags-ai-chat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Yappr Chat Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Yappr Chat Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "yappr-chat-widget" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices, with no identified dangerous functions, all SQL queries utilizing prepared statements, and all output properly escaped. Furthermore, the absence of file operations and external HTTP requests, along with zero taint analysis findings, indicates a well-contained and securely developed codebase. The plugin also shows good security consciousness with one capability check present, which is a positive sign for protecting sensitive operations.

However, the complete absence of entry points like AJAX handlers, REST API routes, and shortcodes, along with zero nonce checks and zero critical or high severity vulnerabilities in its history, while generally positive, raises a slight concern. This could indicate a plugin that is either extremely simple and has no need for such entry points or that its functionality is entirely client-side or dependent on other components. The lack of any recorded vulnerabilities in its history is a significant strength, suggesting consistent security-consciousness or limited exposure.

In conclusion, the "yappr-chat-widget" plugin appears to be very secure with no immediate critical threats identified in the static analysis. Its adherence to secure coding standards for SQL and output escaping is commendable. The primary area of note, rather than a direct risk, is the complete lack of traditional WordPress entry points and nonce checks, which, while not indicating a vulnerability, might warrant further investigation into its actual functionality and how it interacts with the WordPress environment to ensure no implicit risks are present due to this lack of explicit interaction.

Key Concerns

  • No nonce checks present
Vulnerabilities
None known

Yappr Chat Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Yappr Chat Widget Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Yappr Chat Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

Yappr Chat Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuyappr-chat-widget.php:42
actionadmin_inityappr-chat-widget.php:55
actionwp_enqueue_scriptsyappr-chat-widget.php:132
Maintenance & Trust

Yappr Chat Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 12, 2026
PHP min version7.4
Downloads136

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Yappr Chat Widget Developer Profile

YapprWidget

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yappr Chat Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yappr-chat-widget/widget.js
Script Paths
https://yappr.nl/widget.js

HTML / DOM Fingerprints

HTML Comments
<!-- Filter allows setting the real Yappr embed script URL later -->
JS Globals
window.YAPPR_WIDGET_ID
FAQ

Frequently Asked Questions about Yappr Chat Widget