WPZOOM Connect: Social Icons Widget, Share Buttons & Click to Chat

Social icons, share buttons & a floating Click to Chat button for WhatsApp, Telegram, Messenger & Viber. Gutenberg block, widget & Elementor.

v4.6.0WPZOOMUpdated Added 100k+ installs98% rating
35
Score
28
Errors
31
Warnings
+0
Change

Category Scores

Security14
Repo86
Performance100
Maintainability79

Issues to Review

Prioritized issue groups from the latest Plugin Check scan

59 findings

Security

31

5 issue groups

Maintainability

21

7 issue groups

I18n

5

2 issue groups

Supply Chain

2

1 issue group

WARNINGSecurityInput is not sanitizedDetected usage of a non-sanitized input variable: $_POST['ctc_button_size']10
Category
Security
Occurrences
10
Severity
warning

Sample message

Detected usage of a non-sanitized input variable: $_POST['ctc_button_size']

WARNINGSecurityRequest data is not unslashed$_GET['page'] not unslashed before sanitization. Use wp_unslash() or similar9
Category
Security
Occurrences
9
Severity
warning

Sample message

$_GET['page'] not unslashed before sanitization. Use wp_unslash() or similar

ERRORSecurityOutput is not escapedAll output should be run through an escaping function (see the Security sections in the WordPress Developer Handbooks), found '$choice['icon']'.8
Category
Security
Occurrences
8
Severity
error

Sample message

All output should be run through an escaping function (see the Security sections in the WordPress Developer Handbooks), found '$choice['icon']'.

ERRORMaintainabilityOffloaded ContentOffloading images, js, css, and other scripts to your servers or any remote service is disallowed.7
Category
Maintainability
Occurrences
7
Severity
error

Sample message

Offloading images, js, css, and other scripts to your servers or any remote service is disallowed.

ERRORI18nText Domain MismatchMismatched text domain. Expected 'social-icons-widget-by-wpzoom' but got 'wpzoom-forms'.4
Category
I18n
Occurrences
4
Severity
error

Sample message

Mismatched text domain. Expected 'social-icons-widget-by-wpzoom' but got 'wpzoom-forms'.

ERRORMaintainabilityMissing direct file access protectionPHP file should prevent direct access. Add a check like: if ( ! defined( 'ABSPATH' ) ) exit;4
Category
Maintainability
Occurrences
4
Severity
error

Sample message

PHP file should prevent direct access. Add a check like: if ( ! defined( 'ABSPATH' ) ) exit;

WARNINGMaintainabilityNon-prefixed global variableGlobal variables defined by a theme/plugin should start with the theme/plugin prefix. Found: "$current_theme".3
Category
Maintainability
Occurrences
3
Severity
warning

Sample message

Global variables defined by a theme/plugin should start with the theme/plugin prefix. Found: "$current_theme".

WARNINGMaintainabilitytrademarked termThe plugin name includes a restricted term. Your chosen plugin name - "Social Icons, Share Buttons & Click to Chat by WPZOOM" - contains the restricted term "wp" which cannot be used at all in your plugin name.3
Category
Maintainability
Occurrences
3
Severity
warning

Sample message

The plugin name includes a restricted term. Your chosen plugin name - "Social Icons, Share Buttons & Click to Chat by WPZOOM" - contains the restricted term "wp" which cannot be used at all in your plugin name.

WARNINGSecurityNonce verification recommendedProcessing form data without nonce verification.2
Category
Security
Occurrences
2
Severity
warning

Sample message

Processing form data without nonce verification.

WARNINGSecurityInput is not validatedDetected usage of a possibly undefined superglobal array index: $_SERVER['QUERY_STRING']. Check that the array index exists before using it.2
Category
Security
Occurrences
2
Severity
warning

Sample message

Detected usage of a possibly undefined superglobal array index: $_SERVER['QUERY_STRING']. Check that the array index exists before using it.

Show 5 more
ERRORMaintainabilityNo Explicit Version2
Category
Maintainability
Occurrences
2
Severity
error

Sample message

Version parameter is not explicitly set or has been set to an equivalent of "false" for wp_enqueue_script; This means that the WordPress core version will be used which is not recommended for plugin or theme development.

ERRORSupply ChainHidden files included2
Category
Supply Chain
Occurrences
2
Severity
error

Sample message

Hidden files are not permitted.

WARNINGI18nDiscouraged text-domain loading1
Category
I18n
Occurrences
1
Severity
warning

Sample message

load_plugin_textdomain() has been discouraged since WordPress version 4.6. When your plugin is hosted on WordPress.org, you no longer need to manually include this function call for translations under your plugin slug. WordPress will automatically load the translations for you as needed.

ERRORMaintainabilityparse url parse url1
Category
Maintainability
Occurrences
1
Severity
error

Sample message

parse_url() is discouraged because of inconsistency in the output across PHP versions; use wp_parse_url() instead.

WARNINGMaintainabilitymismatched plugin name1
Category
Maintainability
Occurrences
1
Severity
warning

Sample message

Plugin name "WPZOOM Connect: Social Icons Widget, Share Buttons & Click to Chat" is different from the name declared in plugin header "Social Icons, Share Buttons & Click to Chat by WPZOOM".

Score History

First score snapshot

v4.6.0

35

Latest

Findings
59
Errors
28
Warnings
31
Check
2.0.0

Related Plugins

Catch Web Tools

10k+ active installs

100
Social Icons Sticky

1k+ active installs

100
Social Share for WooCommerce

3k+ active installs

100
Click to Chat – HoliThemes

700k+ active installs

99
Social Media Feather

10k+ active installs

99
ShareThis Share Buttons

10k+ active installs

98