Anhlinh Contact List, Messages, Zalo, Email, Call Button Security & Risk Analysis

wordpress.org/plugins/anhlinh-call-button

List icon button for hotline, messenger, zalo, email. A very simple yet very effective plugin that adds a Call Now button to your website for every de …

100 active installs v1.0.0 PHP + WP 3.3+ Updated Aug 14, 2021
anh-linh-contact-listhotline-button-weblist-contact-on-webphonering
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Anhlinh Contact List, Messages, Zalo, Email, Call Button Safe to Use in 2026?

Generally Safe

Score 85/100

Anhlinh Contact List, Messages, Zalo, Email, Call Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The anhlinh-call-button plugin version 1.0.0 demonstrates a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code signals are positive, with no dangerous functions identified, all SQL queries utilizing prepared statements, and no file operations or external HTTP requests. This indicates a conscientious approach to secure coding practices.

However, a significant concern arises from the complete lack of nonce checks and capability checks. This omission means that any functionality the plugin might expose, even if currently minimal or nonexistent in the analyzed entry points, would be entirely unprotected from unauthorized execution. While the taint analysis found no issues, this is likely due to the lack of any discernible data flows or entry points to analyze. The plugin's vulnerability history being empty is a positive sign, suggesting no past exploits or discoveries, but it doesn't mitigate the inherent risk of the missing authorization checks.

In conclusion, while the current implementation appears clean and free of immediate exploitable flaws based on the limited scope of analysis, the absence of nonce and capability checks represents a critical security oversight. This leaves the plugin vulnerable to potential privilege escalation or unauthorized action if any functionality were to be added or discovered in the future. The plugin's strengths lie in its minimal attack surface and secure handling of database operations, but its weaknesses are substantial due to the lack of fundamental authorization mechanisms.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
  • High percentage of unescaped output (19%)
Vulnerabilities
None known

Anhlinh Contact List, Messages, Zalo, Email, Call Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Anhlinh Contact List, Messages, Zalo, Email, Call Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

81% escaped16 total outputs
Attack Surface

Anhlinh Contact List, Messages, Zalo, Email, Call Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuadmin.php:11
actionadmin_initadmin.php:12
actionwp_headpublic.php:16
actionwp_footerpublic.php:19
actionwp_headpublic.php:26
actionwp_footerpublic.php:40
Maintenance & Trust

Anhlinh Contact List, Messages, Zalo, Email, Call Button Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedAug 14, 2021
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Anhlinh Contact List, Messages, Zalo, Email, Call Button Developer Profile

thanhansoft

2 plugins · 140 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Anhlinh Contact List, Messages, Zalo, Email, Call Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/anhlinh-call-button/assets/css/call-button.css/wp-content/plugins/anhlinh-call-button/assets/js/call-button.js
Script Paths
/wp-content/plugins/anhlinh-call-button/assets/js/call-button.js
Version Parameters
anhlinh-call-button/assets/css/call-button.css?ver=anhlinh-call-button/assets/js/call-button.js?ver=

HTML / DOM Fingerprints

CSS Classes
al-hotlineal-cta-iconcta-leftal-cta-phoneal-cta-zaloal-ico-phoneal-ico-messengeral-ico-zalo+1 more
Data Attributes
data-call-button-id
JS Globals
al_cta_options
Shortcode Output
[anhlinh_contact_button]
FAQ

Frequently Asked Questions about Anhlinh Contact List, Messages, Zalo, Email, Call Button