
Сallback Samlab widget Security & Risk Analysis
wordpress.org/plugins/allback-samlabПлагин предназначен для легкого создания виджета контактной формы для Вашео сайта. Этот виджет будет выполнять функцию "обратного звонка".
Is Сallback Samlab widget Safe to Use in 2026?
Generally Safe
Score 85/100Сallback Samlab widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "allback-samlab" v1.1.0 plugin exhibits a mixed security posture. While it demonstrates good practices by using prepared statements for all SQL queries and having no recorded vulnerabilities or dangerous functions, it suffers from a significant lack of security checks on its entry points. A large portion of its attack surface, specifically all 6 AJAX handlers, lacks any form of authentication or capability checks. This leaves them entirely open to unauthorized access and potential exploitation.
The static analysis reveals a substantial concern with the unprotected AJAX handlers. Although taint analysis did not reveal any immediate exploitable flows, the absence of nonces and capability checks on these handlers means that an attacker could potentially trigger them with malicious input, leading to unexpected behavior or the execution of unintended actions. The output escaping also appears to be a weak point, with only 17% of outputs being properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities if data processed by these handlers is not meticulously sanitized before display.
The plugin's clean vulnerability history is a positive sign, suggesting a generally careful development approach. However, this does not negate the immediate risks identified in the current code. The combination of a significant unprotected attack surface and insufficient output escaping presents a clear risk. The plugin needs to implement robust authentication and authorization checks on its AJAX handlers and improve its output sanitization to significantly strengthen its security.
Key Concerns
- AJAX handlers without authentication/authorization
- Low percentage of properly escaped output
- Bundled outdated jQuery library
Сallback Samlab widget Security Vulnerabilities
Сallback Samlab widget Release Timeline
Сallback Samlab widget Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Сallback Samlab widget Attack Surface
AJAX Handlers 6
Shortcodes 3
WordPress Hooks 7
Maintenance & Trust
Сallback Samlab widget Maintenance & Trust
Maintenance Signals
Community Trust
Сallback Samlab widget Alternatives
ZVI CallBack widget
zvi-callback-widget
This plugin makes a simple widget for callback on your website.
Bazz CallBack widget
bazz-callback-widget
This plugin makes a simple widget for callback on your website.
Movylo Marketing Automation
movylo-widget
Build your Customer List by capturing leads from your website and social and then automatically convert the list into real sales.
LeadBack – Callback, Chatbot and Live Chat Widgets for WordPress sites
leadback
This plugin makes a simple widget for callback and live chat on your website. Official LeadBack plugin.
AeroLeads Contact Us Details
aeroleads-contact-us-details
AeroLeads Contact Us Details lets you add contact details in your sidebar as a widget. Simple yet effective.
Сallback Samlab widget Developer Profile
1 plugin · 10 total installs
How We Detect Сallback Samlab widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
btn-greensamlab_callback_activatesamlab_callback_drop_tablessamlab_сallback_add_scriptсallbackFunkposscallme+4 more/wp-json/callback-samlab/v1[samlab_callback][samlab_callback_button][samlab_callback_form]