[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0R6_Ux5mNwAl5ZXsU4sFkHA7YYkYOLeN5cfHNaepxTU":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27,"vulnerabilities":28,"developer":29,"crawl_stats":26,"alternatives":35,"analysis":128,"fingerprints":224},"800-com-call-tracking","800.com Call Tracking","1.0.2","800.com","https:\u002F\u002Fprofiles.wordpress.org\u002F800noc\u002F","\u003Cp>\u003Cstrong>800.com Call Tracking\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Easily add dynamic number swapping to your WordPress site with the 800.com Call Tracking plugin. This lightweight plugin seamlessly integrates with your 800.com account to display unique phone numbers based on visitor sources, enhancing call tracking and marketing attribution for businesses.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003Cbr \u002F>\n– \u003Cstrong>Dynamic Number Swapping\u003C\u002Fstrong>: Automatically display trackable phone numbers on your website, powered by 800.com’s call tracking technology.\u003Cbr \u002F>\n– \u003Cstrong>Simple Setup\u003C\u002Fstrong>: Configure your 800.com API credentials in the WordPress admin panel and start tracking in minutes.\u003Cbr \u002F>\n– \u003Cstrong>Non-Intrusive Integration\u003C\u002Fstrong>: Injects a small, optimized JavaScript snippet into the \u003Ccode>\u003Chead>\u003C\u002Fcode> tag of your site for reliable performance.\u003Cbr \u002F>\n– \u003Cstrong>Secure and Compliant\u003C\u002Fstrong>: Safely handles API credentials and ensures no sensitive data is exposed, adhering to WordPress security standards.\u003Cbr \u002F>\n– \u003Cstrong>Marketing Insights\u003C\u002Fstrong>: Pair with 800.com’s analytics to track call sources, optimize campaigns, and boost ROI.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>How It Works:\u003C\u002Fstrong>\u003Cbr \u002F>\n1. Sign up for an \u003Ca href=\"https:\u002F\u002Fwww.800.com\u002F\" rel=\"nofollow ugc\">800.com account\u003C\u002Fa> to access dynamic number insertion features.\u003Cbr \u002F>\n2. Enter your 800.com API key in the plugin’s settings.\u003Cbr \u002F>\n3. The plugin injects the 800.com JavaScript into your site’s \u003Ccode>\u003Chead>\u003C\u002Fcode>, enabling dynamic phone number swapping based on visitor data (e.g., referral source, campaign, or location).\u003Cbr \u002F>\n4. Monitor call performance directly in your 800.com dashboard.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why Choose This Plugin?\u003C\u002Fstrong>\u003Cbr \u002F>\n– Perfect for businesses, marketers, and agencies using 800.com to track phone leads.\u003Cbr \u002F>\n– No coding required—works out of the box with any WordPress theme.\u003Cbr \u002F>\n– Lightweight and performance-optimized, ensuring fast page loads.\u003Cbr \u002F>\n– Built with security in mind, protecting your 800.com credentials and user data.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Requirements:\u003C\u002Fstrong>\u003Cbr \u002F>\n– An active 800.com account with API access.\u003Cbr \u002F>\n– WordPress 5.0 or higher.\u003Cbr \u002F>\n– Basic familiarity with 800.com’s call tracking setup.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Note\u003C\u002Fstrong>: This plugin relies on 800.com’s services and does not store or process call data locally. All tracking and analytics are managed via your 800.com account.\u003C\u002Fp>\n\u003Cp>Get started today and supercharge your call tracking with dynamic number insertion!\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin connects to 800.com’s external services to provide call tracking functionality. The following information details what data is transmitted and how it is used:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>API Endpoints Used:\u003C\u002Fstrong>\u003Cbr \u002F>\n– \u003Ccode>https:\u002F\u002Fapi.800.com\u002Fcompanies\u002Fslim\u003C\u002Fcode> – Retrieves a list of companies associated with your 800.com account for configuration purposes.\u003Cbr \u002F>\n– \u003Ccode>https:\u002F\u002Fapi.800.com\u002Fcompanies\u002F{id}\u002FtrackingNumbers\u002Fscript\u003C\u002Fcode> – Fetches the JavaScript snippet required for dynamic number insertion on your website.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data Transmission:\u003C\u002Fstrong>\u003Cbr \u002F>\nDuring plugin configuration, your 800.com API key is used to authenticate requests to the above endpoints. Once configured, the injected script communicates with 800.com servers on each page view to determine which phone numbers to display.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Information Sent to 800.com:\u003C\u002Fstrong>\u003Cbr \u002F>\n– Page location (URL)\u003Cbr \u002F>\n– Referrer information\u003Cbr \u002F>\n– 800.com session identifiers\u003Cbr \u002F>\n– Browser information\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Data Usage:\u003C\u002Fstrong>\u003Cbr \u002F>\nThe transmitted data is used exclusively to determine which of your configured phone numbers to serve to website visitors based on your 800.com account settings. This enables accurate call tracking and marketing attribution.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Transparency:\u003C\u002Fstrong>\u003Cbr \u002F>\n800.com maintains transparency by keeping requests and variables human-readable. Additionally, source maps are published for DNI scripts, allowing users to understand exactly how the scripts interact with their websites.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Service Links:\u003C\u002Fstrong>\u003Cbr \u002F>\n– 800.com Terms of Service: https:\u002F\u002Fwww.800.com\u002Fterms\u003Cbr \u002F>\n– 800.com Privacy Policy: https:\u002F\u002Fwww.800.com\u002Fprivacy\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong> This plugin requires an active 800.com account and relies on their external services for all call tracking functionality. No call data is processed or stored locally by this plugin.\u003C\u002Fp>\n","Seamlessly add 800.com dynamic number insertion to your WordPress site for enhanced call tracking and marketing attribution.",0,367,"","6.8.5","5.2","7.2",[18,19,20,21,22],"800-com","call-tracking","dynamic-number-insertion","marketing","phone-tracking","https:\u002F\u002Fwww.800.com\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002F800-com-call-tracking.1.0.2.zip",100,null,"2026-03-15T10:48:56.248Z",[],{"slug":30,"display_name":7,"profile_url":8,"plugin_count":31,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":32,"trust_score":33,"computed_at":34},"800noc",1,30,94,"2026-04-04T21:38:33.897Z",[36,53,71,94,112],{"slug":37,"name":38,"version":39,"author":40,"author_profile":41,"description":42,"short_description":43,"active_installs":44,"downloaded":45,"rating":25,"num_ratings":31,"last_updated":13,"tested_up_to":46,"requires_at_least":47,"requires_php":48,"tags":49,"homepage":51,"download_link":52,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":27},"invox-call-tracking","INVOX Call Tracking","1.1","invox","https:\u002F\u002Fprofiles.wordpress.org\u002Finvox\u002F","\u003Cp>INVOX is a powerful call tracking software designed to help businesses track and analyze phone call conversions from each marketing channel. With this easy-to-integrate plugin, you can gain valuable insights into your marketing campaigns, measure the effectiveness of your advertising efforts, and optimize your customer acquisition strategy.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Advanced Call Analytics:\u003C\u002Fstrong> Track call data such as duration, source, campaigns, ads, and PPC keywords to better understand customer behavior.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Dynamic Number Insertion:\u003C\u002Fstrong> Automatically display unique phone numbers on your website, based on the visitor’s source (e.g., paid ads, organic search, social media).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Real-time Reporting:\u003C\u002Fstrong> View live call data and detailed reports to evaluate your marketing efforts in real time.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Integration with CRM:\u003C\u002Fstrong> Easily sync call data with your CRM system to enhance lead management and follow-up strategies.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User-Friendly Setup:\u003C\u002Fstrong> Simple installation and configuration process, with no technical knowledge required.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>INVOX also offers a Call Transcript feature that automatically generates transcriptions of your phone conversations. This powerful tool provides a text-based record of each call, making it easier to analyze customer interactions, improve customer service, and optimize marketing strategies.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Why Choose INVOX Call Tracking?\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Measure ROI:\u003C\u002Fstrong> Understand the real ROI of your marketing channels by directly linking phone calls to specific campaigns, ads, or keywords.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Improve Campaigns:\u003C\u002Fstrong> Use data to fine-tune your ads and campaigns, ensuring you focus your budget on high-performing channels.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Enhance Customer Experience:\u003C\u002Fstrong> With a clear view of customer interactions, you can improve your communication and overall service quality.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Whether you’re running online ads, email campaigns, or organic SEO efforts, INVOX Call Tracking provides the tools you need to make data-driven decisions and boost your marketing performance.\u003C\u002Fp>\n\u003Cp>For more information about INVOX, visit our \u003Ca href=\"https:\u002F\u002Finvox.eu\" rel=\"nofollow ugc\">plugin homepage\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Configuration\u003C\u002Fh3>\n\u003Cp>To configure the plugin, go to ‘Settings’ > ‘INVOX Call Tracking’ in the WordPress admin panel. Enter your custom CID and Version (v) values and save the settings.\u003C\u002Fp>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Cp>Once configured, the INVOX Call Tracking JavaScript tag will be automatically added to your website.\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For support or questions, please contact us at \u003Ca href=\"mailto:contact@invox.eu\" rel=\"nofollow ugc\">contact@invox.eu\u003C\u002Fa>.\u003C\u002Fp>\n","The INVOX Call Tracking plugin lets WordPress users easily add Dynamic Number Insertion (DNI) to their site without technical or coding skills.",40,1027,"6.7.5","4.9","7.0",[19,20,50],"marketing-analytics","https:\u002F\u002Finvox.eu","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Finvox-call-tracking.1.1.zip",{"slug":54,"name":55,"version":39,"author":54,"author_profile":56,"description":57,"short_description":58,"active_installs":59,"downloaded":60,"rating":11,"num_ratings":11,"last_updated":61,"tested_up_to":62,"requires_at_least":47,"requires_php":63,"tags":64,"homepage":67,"download_link":68,"security_score":69,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":70},"callroot","CallRoot","https:\u002F\u002Fprofiles.wordpress.org\u002Fcallroot\u002F","\u003Cp>CallRoot is a call tracking software for marketing teams and agencies. Track & record incoming phone calls, dynamically insert phone numbers & map referrer source with every incoming call. This wordpress plugin automatically inserts the javascript code for swapping phone numbers in your wordpress website. Using our plugin, you no longer have to manually insert the JavaScript for dynamic number insertion on every page. To know more about CallRoot, go to \u003Ca href=\"https:\u002F\u002Fcallroot.com\" rel=\"nofollow ugc\">https:\u002F\u002Fcallroot.com\u003C\u002Fa>\u003C\u002Fp>\n","CallRoot wordpress plugin facilitates Dynamic Number Insertion (DNI), i.e., it automatically inserts the javascript code for swapping phone numbers in &hellip;",10,6135,"2018-03-26T07:31:00.000Z","4.9.29","5.5.9",[19,65,66,20,21],"campaign-tracking","dni","https:\u002F\u002Fcallroot.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcallroot.1.2.zip",85,"2026-03-15T15:16:48.613Z",{"slug":72,"name":73,"version":74,"author":75,"author_profile":76,"description":77,"short_description":78,"active_installs":79,"downloaded":80,"rating":81,"num_ratings":82,"last_updated":83,"tested_up_to":84,"requires_at_least":85,"requires_php":86,"tags":87,"homepage":92,"download_link":93,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":70},"call-tracking-metrics","CallTrackingMetrics","2.1.8","taf2","https:\u002F\u002Fprofiles.wordpress.org\u002Ftaf2\u002F","\u003Cp>CallTrackingMetrics integrates with your WordPress site to provide powerful call tracking and attribution.\u003C\u002Fp>\n","CallTrackingMetrics integrates with your WordPress site to provide powerful call tracking and attribution.",3000,125043,74,3,"2026-02-16T14:22:00.000Z","6.9.4","6.5","8.2",[88,19,89,90,91],"advertising","conversation-analytics","google-ads","marketing-attribution","https:\u002F\u002Fcalltrackingmetrics.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcall-tracking-metrics.2.1.8.zip",{"slug":95,"name":96,"version":97,"author":98,"author_profile":99,"description":100,"short_description":101,"active_installs":102,"downloaded":103,"rating":11,"num_ratings":11,"last_updated":104,"tested_up_to":84,"requires_at_least":105,"requires_php":16,"tags":106,"homepage":110,"download_link":111,"security_score":25,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":70},"clixtell-tracking-dynamic-phones","Clixtell","2.4","clixtell","https:\u002F\u002Fprofiles.wordpress.org\u002Fclixtell\u002F","\u003Cp>\u003Cstrong>Clixtell Tracking & Dynamic Phones\u003C\u002Fstrong> helps businesses protect their advertising budget and improve conversion tracking by integrating Clixtell’s advanced click fraud detection and dynamic call tracking technology into WordPress.\u003C\u002Fp>\n\u003Cp>With this plugin you can:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Detect and block fraudulent clicks\u003C\u002Fli>\n\u003Cli>Track phone calls accurately from paid traffic\u003C\u002Fli>\n\u003Cli>Enable Dynamic Phone Insertion (DNI)\u003C\u002Fli>\n\u003Cli>Integrate seamlessly with your existing Clixtell account\u003C\u002Fli>\n\u003Cli>Avoid complex code changes or manual script insertion\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>An active \u003Cstrong>Clixtell account\u003C\u002Fstrong> is required to use this plugin.\u003C\u002Fp>\n\u003Cp>Learn more at \u003Ca href=\"https:\u002F\u002Fwww.clixtell.com\" rel=\"nofollow ugc\">https:\u002F\u002Fwww.clixtell.com\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Easy WordPress integration\u003C\u002Fli>\n\u003Cli>Dynamic Phone Insertion (optional toggle)\u003C\u002Fli>\n\u003Cli>Automatic script loading\u003C\u002Fli>\n\u003Cli>Clean and secure WordPress Settings API usage\u003C\u002Fli>\n\u003Cli>Lightweight and performance-friendly\u003C\u002Fli>\n\u003Cli>No theme modification required\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Configuration\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>Settings \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Clixtell\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Check \u003Cstrong>Activate Dynamic Call Tracking\u003C\u002Fstrong> to enable Dynamic Phone Insertion\u003C\u002Fli>\n\u003Cli>Save changes\u003C\u002Fli>\n\u003Cli>Ensure your Clixtell account is properly configured\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Tracking scripts are automatically injected on the frontend once enabled.\u003C\u002Fp>\n\u003Ch3>Privacy Policy\u003C\u002Fh3>\n\u003Cp>Clixtell Tracking & Dynamic Phones does not store or process personal data locally.\u003Cbr \u002F>\nAll tracking, analytics, and data processing are handled by Clixtell services.\u003Cbr \u002F>\nPlease review Clixtell’s Privacy Policy at:\u003Cbr \u002F>\nhttps:\u002F\u002Fwww.clixtell.com\u002Fprivacy-policy\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For documentation and support:\u003Cbr \u002F>\n* https:\u002F\u002Fsupport.clixtell.com\u003Cbr \u002F>\n* https:\u002F\u002Fwww.clixtell.com\u003C\u002Fp>\n","Clixtell Tracking & Dynamic Phones integrates Clixtell click fraud detection and dynamic phone number insertion into your WordPress site.",1000,8147,"2026-02-07T05:14:00.000Z","5.5",[19,107,108,50,109],"click-fraud","dynamic-phone","tracking","https:\u002F\u002Fwww.clixtell.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fclixtell-tracking-dynamic-phones.zip",{"slug":113,"name":114,"version":115,"author":116,"author_profile":117,"description":118,"short_description":119,"active_installs":59,"downloaded":120,"rating":81,"num_ratings":82,"last_updated":121,"tested_up_to":122,"requires_at_least":123,"requires_php":13,"tags":124,"homepage":126,"download_link":127,"security_score":69,"vuln_count":11,"unpatched_count":11,"last_vuln_date":26,"fetched_at":70},"callcap-webmatch","Callcap Webmatch","1.6.5","sethduncan","https:\u002F\u002Fprofiles.wordpress.org\u002Fsethduncan\u002F","\u003Cp>“Webmatch” is a call-tracking feature provided by Callcap that associates phone calls with specific pageviews to bridge the gap between advertising campaigns and incoming phone calls.\u003C\u002Fp>\n\u003Cp>Webmatch allows a company to bridge the gap between basic web analytics and direct sales via phone calls. If a call leads to a sale, Webmatch can help you see where the initial visit came from, what ad campaign it may have run under, and what page the user was on when they called you.\u003C\u002Fp>\n\u003Cp>At it’s most basic, Webmatch will simply associate recent calls to recent pageviews, but with Dynamic Rotator enabled, Webmatch can show unique phone numbers to visitors to more accurately track their statistics.\u003C\u002Fp>\n","Works with Webmatch by Callcap to associate pageviews with phone calls and dynamically change phone numbers on your Wordpress page using your Webmatch &hellip;",1780,"2017-08-01T20:18:00.000Z","4.9.6.2","4.0",[19,125,22],"phone-numbers","http:\u002F\u002Fwww.callcap.com\u002Fhelp\u002Fwebmatch-wordpress\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcallcap-webmatch.zip",{"attackSurface":129,"codeSignals":172,"taintFlows":181,"riskAssessment":215,"analyzedAt":223},{"hooks":130,"ajaxHandlers":162,"restRoutes":169,"shortcodes":170,"cronEvents":171,"entryPointCount":31,"unprotectedCount":11},[131,137,141,145,149,153,158],{"type":132,"name":133,"callback":134,"file":135,"line":136},"action","admin_menu","ehdi_add_admin_menu","eight-hundred-dni-injector.php",36,{"type":132,"name":138,"callback":139,"file":135,"line":140},"admin_init","ehdi_settings_init",132,{"type":132,"name":142,"callback":143,"file":135,"line":144},"shutdown","ehdi_fetch_script_on_shutdown",318,{"type":132,"name":146,"callback":147,"file":135,"line":148},"admin_notices","ehdi_display_admin_notices",339,{"type":132,"name":150,"callback":151,"file":135,"line":152},"wp_enqueue_scripts","ehdi_enqueue_dni_script",470,{"type":132,"name":154,"callback":155,"priority":156,"file":135,"line":157},"wp_footer","ehdi_output_dni_script_direct",999,497,{"type":132,"name":159,"callback":160,"file":135,"line":161},"admin_enqueue_scripts","ehdi_enqueue_admin_scripts",648,[163],{"action":164,"nopriv":165,"callback":166,"hasNonce":167,"hasCapCheck":167,"file":135,"line":168},"ehdi_refresh_script",false,"ehdi_ajax_refresh_script_handler",true,694,[],[],[],{"dangerousFunctions":173,"sqlUsage":174,"outputEscaping":176,"fileOperations":11,"externalRequests":179,"nonceChecks":31,"capabilityChecks":179,"bundledLibraries":180},[],{"prepared":11,"raw":11,"locations":175},[],{"escaped":177,"rawEcho":11,"locations":178},50,[],2,[],[182,205],{"entryPoint":183,"graph":184,"unsanitizedCount":31,"severity":204},"ehdi_ajax_refresh_script_handler (eight-hundred-dni-injector.php:653)",{"nodes":185,"edges":201},[186,191,195],{"id":187,"type":188,"label":189,"file":135,"line":190},"n0","source","$_POST",679,{"id":192,"type":193,"label":194,"file":135,"line":190},"n1","transform","→ ehdi_fetch_dni_script()",{"id":196,"type":197,"label":198,"file":135,"line":199,"wp_function":200},"n2","sink","wp_remote_get() [SSRF]",278,"wp_remote_get",[202,203],{"from":187,"to":192,"sanitized":165},{"from":192,"to":196,"sanitized":165},"medium",{"entryPoint":206,"graph":207,"unsanitizedCount":31,"severity":204},"\u003Ceight-hundred-dni-injector> (eight-hundred-dni-injector.php:0)",{"nodes":208,"edges":212},[209,210,211],{"id":187,"type":188,"label":189,"file":135,"line":190},{"id":192,"type":193,"label":194,"file":135,"line":190},{"id":196,"type":197,"label":198,"file":135,"line":199,"wp_function":200},[213,214],{"from":187,"to":192,"sanitized":165},{"from":192,"to":196,"sanitized":165},{"summary":216,"deductions":217},"The plugin \"800-com-call-tracking\" v1.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, proper utilization of prepared statements for all SQL queries, and 100% proper output escaping are significant strengths. Furthermore, the presence of nonce and capability checks on its identified entry points, along with a clean vulnerability history, suggests a well-developed and maintained plugin. The limited attack surface, consisting of a single AJAX handler, further contributes to its positive security assessment.\n\nHowever, the taint analysis reveals two flows with unsanitized paths, even though they are not categorized as critical or high severity. While the absence of explicit vulnerabilities in the history is reassuring, these unsanitized paths represent potential avenues for attackers if not handled with extreme care by the code interacting with them. The presence of external HTTP requests also introduces a minor risk, as the security of these external services is beyond the plugin's direct control.\n\nIn conclusion, \"800-com-call-tracking\" v1.0.2 is a plugin with a good foundation for security. Its adherence to best practices like prepared statements and output escaping is commendable. The primary concern lies in the identified unsanitized paths, which, while not currently exploited or critical, warrant attention and thorough review to ensure no vulnerabilities can be introduced through these flows. The external HTTP requests are a minor but inherent risk.",[218,221],{"reason":219,"points":220},"Flows with unsanitized paths",8,{"reason":222,"points":179},"External HTTP requests (2)","2026-03-17T06:01:15.785Z",{"wat":225,"direct":231},{"assetPaths":226,"generatorPatterns":227,"scriptPaths":228,"versionParams":229},[],[],[],[230],"800-com-call-tracking\u002Feight-hundred-dni-injector.php?ver=1.0.2",{"cssClasses":232,"htmlComments":234,"htmlAttributes":235,"restEndpoints":239,"jsGlobals":240,"shortcodeOutput":241},[233],"ehdi-error-message",[],[236,237,238],"name=\"ehdi_api_key\"","name=\"ehdi_selected_company_id\"","id=\"ehdi_company_select_field\"",[],[],[]]