800.com Call Tracking Security & Risk Analysis

wordpress.org/plugins/800-com-call-tracking

Seamlessly add 800.com dynamic number insertion to your WordPress site for enhanced call tracking and marketing attribution.

0 active installs v1.0.2 PHP 7.2+ WP 5.2+ Updated Unknown
800-comcall-trackingdynamic-number-insertionmarketingphone-tracking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is 800.com Call Tracking Safe to Use in 2026?

Generally Safe

Score 100/100

800.com Call Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "800-com-call-tracking" v1.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, proper utilization of prepared statements for all SQL queries, and 100% proper output escaping are significant strengths. Furthermore, the presence of nonce and capability checks on its identified entry points, along with a clean vulnerability history, suggests a well-developed and maintained plugin. The limited attack surface, consisting of a single AJAX handler, further contributes to its positive security assessment.

However, the taint analysis reveals two flows with unsanitized paths, even though they are not categorized as critical or high severity. While the absence of explicit vulnerabilities in the history is reassuring, these unsanitized paths represent potential avenues for attackers if not handled with extreme care by the code interacting with them. The presence of external HTTP requests also introduces a minor risk, as the security of these external services is beyond the plugin's direct control.

In conclusion, "800-com-call-tracking" v1.0.2 is a plugin with a good foundation for security. Its adherence to best practices like prepared statements and output escaping is commendable. The primary concern lies in the identified unsanitized paths, which, while not currently exploited or critical, warrant attention and thorough review to ensure no vulnerabilities can be introduced through these flows. The external HTTP requests are a minor but inherent risk.

Key Concerns

  • Flows with unsanitized paths
  • External HTTP requests (2)
Vulnerabilities
None known

800.com Call Tracking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

800.com Call Tracking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
50 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped50 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ehdi_ajax_refresh_script_handler (eight-hundred-dni-injector.php:653)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

800.com Call Tracking Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_ehdi_refresh_scripteight-hundred-dni-injector.php:694
WordPress Hooks 7
actionadmin_menueight-hundred-dni-injector.php:36
actionadmin_initeight-hundred-dni-injector.php:132
actionshutdowneight-hundred-dni-injector.php:318
actionadmin_noticeseight-hundred-dni-injector.php:339
actionwp_enqueue_scriptseight-hundred-dni-injector.php:470
actionwp_footereight-hundred-dni-injector.php:497
actionadmin_enqueue_scriptseight-hundred-dni-injector.php:648
Maintenance & Trust

800.com Call Tracking Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.2
Downloads367

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

800.com Call Tracking Developer Profile

800.com

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect 800.com Call Tracking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
800-com-call-tracking/eight-hundred-dni-injector.php?ver=1.0.2

HTML / DOM Fingerprints

CSS Classes
ehdi-error-message
Data Attributes
name="ehdi_api_key"name="ehdi_selected_company_id"id="ehdi_company_select_field"
FAQ

Frequently Asked Questions about 800.com Call Tracking