
Asterisk Web Callback Security & Risk Analysis
wordpress.org/plugins/asterisk-web-callbackA widget that make call back to visitor via Asterisk
Is Asterisk Web Callback Safe to Use in 2026?
Generally Safe
Score 85/100Asterisk Web Callback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "asterisk-web-callback" plugin version 0.1 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL queries, exclusively utilizing prepared statements, and reports zero known CVEs, indicating a history of good security hygiene. There are no file operations or external HTTP requests, which further reduces the potential attack surface. However, the static analysis reveals a significant concern with output escaping, where only 45% of outputs are properly escaped. This leaves a substantial portion of the plugin's output vulnerable to cross-site scripting (XSS) attacks, especially considering the total number of outputs analyzed.
The taint analysis shows two flows with unsanitized paths, though thankfully, these did not escalate to critical or high severity. Nonetheless, the presence of unsanitized paths, even if currently benign, represents a potential future risk if the plugin is updated or if the context of these paths changes. The lack of any observed nonces or capability checks on potential entry points (though the attack surface is currently reported as zero) is also a point of caution, as it implies a potential reliance on other security mechanisms or a very limited initial scope.
Overall, while the plugin benefits from a clean vulnerability history and secure database practices, the high percentage of unescaped output is a notable weakness. The presence of unsanitized paths, even without immediate high-severity impact, warrants attention. The conclusion is that the plugin has a solid foundation but requires immediate attention to its output sanitization to mitigate XSS risks.
Key Concerns
- Insufficient output escaping
- Unsanitized paths in taint analysis
Asterisk Web Callback Security Vulnerabilities
Asterisk Web Callback Release Timeline
Asterisk Web Callback Code Analysis
Output Escaping
Data Flow Analysis
Asterisk Web Callback Attack Surface
WordPress Hooks 2
Maintenance & Trust
Asterisk Web Callback Maintenance & Trust
Maintenance Signals
Community Trust
Asterisk Web Callback Alternatives
Excitel – Click to call
excitel-click-to-call
Excitel helps your customers make calls from your site over Internet (free) using WebRTC, RTMP and SIP protocols.
Firmao CallBack
firmao-callback
(OFFICIAL Firmao plugin) Manage call requests from visitors on your website via Firmao CallBack.
Fonetic Web Callback
fonetic-web-callback
Fonetic is a web call feature for your website that allows your visitors to be called back for free. Get a real leverage for your online conversions !
API KEY for Google Maps
api-key-for-google-maps
Retroactively add Google Maps API KEY to any theme or plugin.
Bazz CallBack widget
bazz-callback-widget
This plugin makes a simple widget for callback on your website.
Asterisk Web Callback Developer Profile
1 plugin · 10 total installs
How We Detect Asterisk Web Callback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/asterisk-web-callback/css/z_asteriskcallback.cssasterisk-web-callback/css/z_asteriskcallback.css?ver=HTML / DOM Fingerprints
z_asteriskcallbackasteriskcallback-widget-popup_toggleasteriskcallback-widget-buttonasteriskcallback-widget-circle_phoneasteriskcallback-widget-circle_fillasteriskcallback-widget-img_circleasteriskcallback-widget-img_circle_blockasteriskcallback-widget-block+7 more<!-- Callback button --><!-- Callback button --> <!-- Callback begin --> <!-- Callback - end --> id="asteriskcallback-widget-popup_toggle"id="asteriskcallback-widget-button"id="call"id="asteriskcallback-widget-button"name="txtphonenumber"id="asteriskcallback-widget-button"hidecallchangestate