800.com Call Tracking Security & Risk Analysis
wordpress.org/plugins/800-com-call-trackingSeamlessly add 800.com dynamic number insertion to your WordPress site for enhanced call tracking and marketing attribution.
Is 800.com Call Tracking Safe to Use in 2026?
Generally Safe
Score 100/100800.com Call Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "800-com-call-tracking" v1.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, proper utilization of prepared statements for all SQL queries, and 100% proper output escaping are significant strengths. Furthermore, the presence of nonce and capability checks on its identified entry points, along with a clean vulnerability history, suggests a well-developed and maintained plugin. The limited attack surface, consisting of a single AJAX handler, further contributes to its positive security assessment.
However, the taint analysis reveals two flows with unsanitized paths, even though they are not categorized as critical or high severity. While the absence of explicit vulnerabilities in the history is reassuring, these unsanitized paths represent potential avenues for attackers if not handled with extreme care by the code interacting with them. The presence of external HTTP requests also introduces a minor risk, as the security of these external services is beyond the plugin's direct control.
In conclusion, "800-com-call-tracking" v1.0.2 is a plugin with a good foundation for security. Its adherence to best practices like prepared statements and output escaping is commendable. The primary concern lies in the identified unsanitized paths, which, while not currently exploited or critical, warrant attention and thorough review to ensure no vulnerabilities can be introduced through these flows. The external HTTP requests are a minor but inherent risk.
Key Concerns
- Flows with unsanitized paths
- External HTTP requests (2)
800.com Call Tracking Security Vulnerabilities
800.com Call Tracking Code Analysis
Output Escaping
Data Flow Analysis
800.com Call Tracking Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
800.com Call Tracking Maintenance & Trust
Maintenance Signals
Community Trust
800.com Call Tracking Alternatives
INVOX Call Tracking
invox-call-tracking
The INVOX Call Tracking plugin lets WordPress users easily add Dynamic Number Insertion (DNI) to their site without technical or coding skills.
CallRoot
callroot
CallRoot wordpress plugin facilitates Dynamic Number Insertion (DNI), i.e., it automatically inserts the javascript code for swapping phone numbers in …
CallTrackingMetrics
call-tracking-metrics
CallTrackingMetrics integrates with your WordPress site to provide powerful call tracking and attribution.
Clixtell
clixtell-tracking-dynamic-phones
Clixtell Tracking & Dynamic Phones integrates Clixtell click fraud detection and dynamic phone number insertion into your WordPress site.
Callcap Webmatch
callcap-webmatch
Works with Webmatch by Callcap to associate pageviews with phone calls and dynamically change phone numbers on your Wordpress page using your Webmatch …
800.com Call Tracking Developer Profile
1 plugin · 0 total installs
How We Detect 800.com Call Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
800-com-call-tracking/eight-hundred-dni-injector.php?ver=1.0.2HTML / DOM Fingerprints
ehdi-error-messagename="ehdi_api_key"name="ehdi_selected_company_id"id="ehdi_company_select_field"