Сallback Samlab widget Security & Risk Analysis

wordpress.org/plugins/allback-samlab

Плагин предназначен для легкого создания виджета контактной формы для Вашео сайта. Этот виджет будет выполнять функцию "обратного звонка".

10 active installs v1.1.0 PHP + WP 3.0.1+ Updated Mar 1, 2019
call-backcallbackleadswidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Сallback Samlab widget Safe to Use in 2026?

Generally Safe

Score 85/100

Сallback Samlab widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "allback-samlab" v1.1.0 plugin exhibits a mixed security posture. While it demonstrates good practices by using prepared statements for all SQL queries and having no recorded vulnerabilities or dangerous functions, it suffers from a significant lack of security checks on its entry points. A large portion of its attack surface, specifically all 6 AJAX handlers, lacks any form of authentication or capability checks. This leaves them entirely open to unauthorized access and potential exploitation.

The static analysis reveals a substantial concern with the unprotected AJAX handlers. Although taint analysis did not reveal any immediate exploitable flows, the absence of nonces and capability checks on these handlers means that an attacker could potentially trigger them with malicious input, leading to unexpected behavior or the execution of unintended actions. The output escaping also appears to be a weak point, with only 17% of outputs being properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities if data processed by these handlers is not meticulously sanitized before display.

The plugin's clean vulnerability history is a positive sign, suggesting a generally careful development approach. However, this does not negate the immediate risks identified in the current code. The combination of a significant unprotected attack surface and insufficient output escaping presents a clear risk. The plugin needs to implement robust authentication and authorization checks on its AJAX handlers and improve its output sanitization to significantly strengthen its security.

Key Concerns

  • AJAX handlers without authentication/authorization
  • Low percentage of properly escaped output
  • Bundled outdated jQuery library
Vulnerabilities
None known

Сallback Samlab widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Сallback Samlab widget Release Timeline

v1.1.0Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Сallback Samlab widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
24
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

DataTablesjQuery1.12.4

SQL Query Safety

100% prepared3 total queries

Output Escaping

17% escaped29 total outputs
Attack Surface
6 unprotected

Сallback Samlab widget Attack Surface

Entry Points9
Unprotected6

AJAX Handlers 6

authwp_ajax_getformsamlabcallback-settings.php:60
noprivwp_ajax_getformsamlabcallback-settings.php:61
noprivwp_ajax_sampostmessagecallback-settings.php:63
authwp_ajax_sampostmessagecallback-settings.php:64
authwp_ajax_samlabdellrecordcallback-settings.php:199
authwp_ajax_samlabgettablecallback-settings.php:201

Shortcodes 3

[samlab_callback_form] callback-settings.php:492
[samlab_callback] callback-settings.php:519
[samlab_callback_button] callback-settings.php:547
WordPress Hooks 7
actionadmin_menuadmin/class-submenu.php:41
actionplugins_loadedcallback-settings.php:58
actionwp_footercallback-settings.php:165
actionadmin_initcallback-settings.php:197
actionadmin_print_footer_scriptscallback-settings.php:203
actionwp_dashboard_setupcallback-settings.php:208
actionadmin_print_footer_scriptscallback-settings.php:210
Maintenance & Trust

Сallback Samlab widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMar 1, 2019
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Сallback Samlab widget Developer Profile

wpdewlab

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Сallback Samlab widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
btn-green
JS Globals
samlab_callback_activatesamlab_callback_drop_tablessamlab_сallback_add_scriptсallbackFunkposscallme+4 more
REST Endpoints
/wp-json/callback-samlab/v1
Shortcode Output
[samlab_callback][samlab_callback_button][samlab_callback_form]
FAQ

Frequently Asked Questions about Сallback Samlab widget