ZS Social Chat by ZS Software Studio Security & Risk Analysis

wordpress.org/plugins/zs-social-chat

ZS Social Chat will help you to add WhatsApp Chat Button in your website so that your users can connect with you through WhatsApp & WhatsApp Busin …

0 active installs v1.0.1 PHP 7.3+ WP 5.2+ Updated Mar 30, 2023
chat-buttonclick-to-chatsocial-chatwhatsappzs-social-chat
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ZS Social Chat by ZS Software Studio Safe to Use in 2026?

Generally Safe

Score 85/100

ZS Social Chat by ZS Software Studio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The zs-social-chat plugin v1.0.1 exhibits a generally good security posture based on the provided static analysis. There are no detected dangerous functions, file operations, external HTTP requests, or SQL queries that do not use prepared statements. The high percentage of properly escaped output is also a positive indicator. The absence of any recorded vulnerabilities or CVEs further strengthens this impression of a secure plugin. However, the complete lack of nonce checks and capability checks across all identified entry points is a significant concern. While the current attack surface appears minimal and all entry points are reported as protected (which is unusual if there are no auth checks), this indicates a potential reliance on external mechanisms for security rather than inherent checks within the plugin itself. This could leave the plugin vulnerable if those external protections are misconfigured or bypassed. The lack of taint analysis data is also a minor concern, as it means potential data flow vulnerabilities may not have been thoroughly examined.

In conclusion, the plugin demonstrates strong foundational security practices by avoiding common pitfalls like raw SQL and unsafe output. The vulnerability history is excellent. The primary weakness lies in the complete absence of built-in authentication and authorization checks for its entry points. This, combined with the lack of taint analysis, means that while no *known* vulnerabilities exist, there's a potential for undiscovered issues, especially if the plugin's scope or attack surface were to expand in future versions. It's recommended to implement proper nonce and capability checks to solidify its security.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • No taint analysis data provided
Vulnerabilities
None known

ZS Social Chat by ZS Software Studio Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ZS Social Chat by ZS Software Studio Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped26 total outputs
Attack Surface

ZS Social Chat by ZS Software Studio Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionactivated_pluginzs-social-chat.php:33
actionadmin_menuzswwc-plugin-admin.php:11
actionadmin_enqueue_scriptszswwc-plugin-admin.php:23
actionwp_enqueue_scriptszswwc-plugin-home.php:13
actionwp_footerzswwc-plugin-home.php:55
Maintenance & Trust

ZS Social Chat by ZS Software Studio Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMar 30, 2023
PHP min version7.3
Downloads687

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ZS Social Chat by ZS Software Studio Developer Profile

Zarif Sadman

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ZS Social Chat by ZS Software Studio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zs-social-chat/css/zswwc-admin-styles.css/wp-content/plugins/zs-social-chat/img/logo.svg/wp-content/plugins/zs-social-chat/img/logo.png/wp-content/plugins/zs-social-chat/css/zswwc-styles.css/wp-content/plugins/zs-social-chat/img/whatsapp.png/wp-content/plugins/zs-social-chat/img/buymeacoffee.svg
Version Parameters
zswwc-admin-styles.css?ver=zswwc-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
zswwc__mainzswwc__logozswwc__formzswwc__inputzswwc__copyrightzswwc__donate-buttonzswwc__chat-box-zswwc__chat-box-right+2 more
HTML Comments
ZS Social Chat Button by ZS Software StudioZS Social Chat Button Script by ZS Software StudioDonation Button
Data Attributes
id="zswwc__chat-button"class="zswwc__chat-box-id="zswwc-whatsapp-number"name="zswwc-whatsapp-number"id="zswwc-text-message"name="zswwc-text-message"+2 more
JS Globals
window.open('https://api.whatsapp.com/send/?phone=const chatButton = document.querySelector('#zswwc__chat-button');
FAQ

Frequently Asked Questions about ZS Social Chat by ZS Software Studio