
Bazz CallBack widget Security & Risk Analysis
wordpress.org/plugins/bazz-callback-widgetThis plugin makes a simple widget for callback on your website.
Is Bazz CallBack widget Safe to Use in 2026?
Generally Safe
Score 85/100Bazz CallBack widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bazz-callback-widget" plugin, version 3.23, exhibits a generally strong security posture with a clean vulnerability history. Static analysis reveals no known CVEs and a commendable lack of dangerous functions, raw SQL queries, or file operations. The presence of a nonce check is also a positive indicator. However, a significant concern arises from the complete absence of capability checks for its two identified AJAX entry points. While the analysis indicates these handlers are not directly exposed without authentication checks (0 unprotected entry points), the lack of explicit capability checks means that any authenticated user, regardless of their role or permissions, could potentially trigger these AJAX actions. This presents a risk of unauthorized actions being performed if the AJAX handlers themselves contain logic that should be restricted to privileged users.
Furthermore, the output escaping is not fully implemented, with 34% of outputs lacking proper escaping. This could lead to cross-site scripting (XSS) vulnerabilities if the data processed by these outputs is not sufficiently sanitized before rendering. The lack of identified taint flows is a positive sign, but this could also be due to the limited scope of the analysis or the absence of complex data processing within the plugin that would trigger such flows.
In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the missing capability checks on AJAX handlers and the incomplete output escaping are notable weaknesses. The absence of past vulnerabilities is a positive indicator of developer diligence, but these identified code signals warrant attention to prevent future security issues. Addressing these specific concerns would significantly bolster the plugin's overall security.
Key Concerns
- AJAX handlers without capability checks
- Unescaped output detected
Bazz CallBack widget Security Vulnerabilities
Bazz CallBack widget Code Analysis
Output Escaping
Bazz CallBack widget Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
Bazz CallBack widget Maintenance & Trust
Maintenance Signals
Community Trust
Bazz CallBack widget Alternatives
CallPage – Callback Widget
callpage
Widget for callback in 28 seconds! Gain 75% more leads from your website!
ZVI CallBack widget
zvi-callback-widget
This plugin makes a simple widget for callback on your website.
Call Leads WordPress Plugin
call-leads
The easiest way to get more call leads, turn leads to customers.
API KEY for Google Maps
api-key-for-google-maps
Retroactively add Google Maps API KEY to any theme or plugin.
WP Router
wp-router
Provides a simple API for mapping requests to callback functions.
Bazz CallBack widget Developer Profile
1 plugin · 4K total installs
How We Detect Bazz CallBack widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bazz-callback-widget/css/bazz-widget.css/wp-content/plugins/bazz-callback-widget/css/bazz-widget-admin.css/wp-content/plugins/bazz-callback-widget/js/jquery.maskedinput.min.js/wp-content/plugins/bazz-callback-widget/js/jquery.draggable.min.js/wp-content/plugins/bazz-callback-widget/js/bazz-widget.js/wp-content/plugins/bazz-callback-widget/js/jquery.ui-slider.js/wp-content/plugins/bazz-callback-widget/js/jquery.ui.slider-rtl.min.js/wp-content/plugins/bazz-callback-widget/js/jquery.maskedinput.min.js/wp-content/plugins/bazz-callback-widget/js/jquery.draggable.min.js/wp-content/plugins/bazz-callback-widget/js/bazz-widget.js/wp-content/plugins/bazz-callback-widget/js/jquery.ui-slider.js/wp-content/plugins/bazz-callback-widget/js/jquery.ui.slider-rtl.min.jsbazz-callback-widget/css/bazz-widget.css?ver=bazz-callback-widget/css/bazz-widget-admin.css?ver=bazz-callback-widget/js/jquery.maskedinput.min.js?ver=bazz-callback-widget/js/jquery.draggable.min.js?ver=bazz-callback-widget/js/bazz-widget.js?ver=bazz-callback-widget/js/jquery.ui-slider.js?ver=bazz-callback-widget/js/jquery.ui.slider-rtl.min.js?ver=HTML / DOM Fingerprints
bazz-widgetbazz-widget-closebazz-widget-form-submitbazz-widget-buttonbazz-widget-name-closebazz-widget-inner-circlebazz-widget-inner-borderbazz-widget-form-top+1 moredata-bazz-optionsbazz_ajaxbazz_options