
Anhlinh Contact List, Messages, Zalo, Email, Call Button Security & Risk Analysis
wordpress.org/plugins/anhlinh-call-buttonList icon button for hotline, messenger, zalo, email. A very simple yet very effective plugin that adds a Call Now button to your website for every de …
Is Anhlinh Contact List, Messages, Zalo, Email, Call Button Safe to Use in 2026?
Generally Safe
Score 85/100Anhlinh Contact List, Messages, Zalo, Email, Call Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The anhlinh-call-button plugin version 1.0.0 demonstrates a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code signals are positive, with no dangerous functions identified, all SQL queries utilizing prepared statements, and no file operations or external HTTP requests. This indicates a conscientious approach to secure coding practices.
However, a significant concern arises from the complete lack of nonce checks and capability checks. This omission means that any functionality the plugin might expose, even if currently minimal or nonexistent in the analyzed entry points, would be entirely unprotected from unauthorized execution. While the taint analysis found no issues, this is likely due to the lack of any discernible data flows or entry points to analyze. The plugin's vulnerability history being empty is a positive sign, suggesting no past exploits or discoveries, but it doesn't mitigate the inherent risk of the missing authorization checks.
In conclusion, while the current implementation appears clean and free of immediate exploitable flaws based on the limited scope of analysis, the absence of nonce and capability checks represents a critical security oversight. This leaves the plugin vulnerable to potential privilege escalation or unauthorized action if any functionality were to be added or discovered in the future. The plugin's strengths lie in its minimal attack surface and secure handling of database operations, but its weaknesses are substantial due to the lack of fundamental authorization mechanisms.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
- High percentage of unescaped output (19%)
Anhlinh Contact List, Messages, Zalo, Email, Call Button Security Vulnerabilities
Anhlinh Contact List, Messages, Zalo, Email, Call Button Code Analysis
Output Escaping
Anhlinh Contact List, Messages, Zalo, Email, Call Button Attack Surface
WordPress Hooks 6
Maintenance & Trust
Anhlinh Contact List, Messages, Zalo, Email, Call Button Maintenance & Trust
Maintenance Signals
Community Trust
Anhlinh Contact List, Messages, Zalo, Email, Call Button Alternatives
Anhlinh Contact List, Messages, Zalo, Email, Call Button Developer Profile
2 plugins · 140 total installs
How We Detect Anhlinh Contact List, Messages, Zalo, Email, Call Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/anhlinh-call-button/assets/css/call-button.css/wp-content/plugins/anhlinh-call-button/assets/js/call-button.js/wp-content/plugins/anhlinh-call-button/assets/js/call-button.jsanhlinh-call-button/assets/css/call-button.css?ver=anhlinh-call-button/assets/js/call-button.js?ver=HTML / DOM Fingerprints
al-hotlineal-cta-iconcta-leftal-cta-phoneal-cta-zaloal-ico-phoneal-ico-messengeral-ico-zalo+1 moredata-call-button-idal_cta_options[anhlinh_contact_button]