
AgilityFeat's Click To Call Security & Risk Analysis
wordpress.org/plugins/agilityfeats-click-to-callThis plugin adds the functionality of video chat between users of your blog by using Tokbox (Experimental).
Is AgilityFeat's Click To Call Safe to Use in 2026?
Generally Safe
Score 85/100AgilityFeat's Click To Call has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "agilityfeats-click-to-call" plugin version 0.5.0 exhibits several significant security concerns. The most prominent issue is the presence of three AJAX handlers that lack any authentication or capability checks. This exposes a substantial attack surface, allowing any unauthenticated user to potentially trigger these handlers. Additionally, the plugin performs two SQL queries without using prepared statements, which could lead to SQL injection vulnerabilities if user input is not properly sanitized before being passed to these queries. The output escaping is also a concern, with 58% of outputs properly escaped, leaving the remaining 42% potentially vulnerable to cross-site scripting (XSS) attacks. The absence of any recorded vulnerabilities in its history might suggest a lack of prior discovery or exploitation, but this does not negate the immediate risks identified in the static analysis. While the plugin doesn't use dangerous functions, perform file operations, external HTTP requests, or bundle libraries, the identified unauthenticated entry points and insecure SQL practices are critical weaknesses that demand immediate attention.
Key Concerns
- Unprotected AJAX handlers
- SQL queries without prepared statements
- Insufficient output escaping
AgilityFeat's Click To Call Security Vulnerabilities
AgilityFeat's Click To Call Release Timeline
AgilityFeat's Click To Call Code Analysis
SQL Query Safety
Output Escaping
AgilityFeat's Click To Call Attack Surface
AJAX Handlers 3
WordPress Hooks 10
Maintenance & Trust
AgilityFeat's Click To Call Maintenance & Trust
Maintenance Signals
Community Trust
AgilityFeat's Click To Call Alternatives
HTML5 Chat
html5-chat
HTML5 Chat is a WordPress plugin that lets you easily embed a real-time audio & video chat into your website using HTML5 technology.
LiveSmart Video Chat Live Video Chat
new-dev-livesmart-video-chat
LiveSmart Video Chat Live Video chat plugin for WordPress that allows visitors to establish live video chat in the browser without download.
Paid Videochat Turnkey Site – HTML5 PPV Live Webcams
ppv-live-webcams
Launch a PPV live webcam platform with real-time interaction and robust monetization for performers.
WP-WebRTC2
wp-webrtc2
Free video chat for registered site users.
ConnectSphere
connectsphere
ConnectSphere transforms your online courses with video, audio, chat, and screen-sharing sessions via WebRTC. With proper configured Janus server.
AgilityFeat's Click To Call Developer Profile
1 plugin · 10 total installs
How We Detect AgilityFeat's Click To Call
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/agilityfeats-click-to-call/public/js/heartbeat_actions.js/wp-content/plugins/agilityfeats-click-to-call/public/js/opentok.min.js/wp-content/plugins/agilityfeats-click-to-call/public/js/opentok_handler.js/wp-content/plugins/agilityfeats-click-to-call/public/css/contacts.css/wp-content/plugins/agilityfeats-click-to-call/public/js/heartbeat_actions.js/wp-content/plugins/agilityfeats-click-to-call/public/js/opentok.min.js/wp-content/plugins/agilityfeats-click-to-call/public/js/opentok_handler.js/wp-content/plugins/agilityfeats-click-to-call/public/js/heartbeat_actions.js?ver=/wp-content/plugins/agilityfeats-click-to-call/public/js/opentok.min.js?ver=/wp-content/plugins/agilityfeats-click-to-call/public/js/opentok_handler.js?ver=/wp-content/plugins/agilityfeats-click-to-call/public/css/contacts.css?ver=HTML / DOM Fingerprints
video_elonclickphp/wp-ajax.php