Bazz CallBack widget Security & Risk Analysis

wordpress.org/plugins/bazz-callback-widget

This plugin makes a simple widget for callback on your website.

4K active installs v3.23 PHP + WP 3.0.1+ Updated Mar 19, 2023
bazzcallcall-backcall-requestcallback
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bazz CallBack widget Safe to Use in 2026?

Generally Safe

Score 85/100

Bazz CallBack widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "bazz-callback-widget" plugin, version 3.23, exhibits a generally strong security posture with a clean vulnerability history. Static analysis reveals no known CVEs and a commendable lack of dangerous functions, raw SQL queries, or file operations. The presence of a nonce check is also a positive indicator. However, a significant concern arises from the complete absence of capability checks for its two identified AJAX entry points. While the analysis indicates these handlers are not directly exposed without authentication checks (0 unprotected entry points), the lack of explicit capability checks means that any authenticated user, regardless of their role or permissions, could potentially trigger these AJAX actions. This presents a risk of unauthorized actions being performed if the AJAX handlers themselves contain logic that should be restricted to privileged users.

Furthermore, the output escaping is not fully implemented, with 34% of outputs lacking proper escaping. This could lead to cross-site scripting (XSS) vulnerabilities if the data processed by these outputs is not sufficiently sanitized before rendering. The lack of identified taint flows is a positive sign, but this could also be due to the limited scope of the analysis or the absence of complex data processing within the plugin that would trigger such flows.

In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the missing capability checks on AJAX handlers and the incomplete output escaping are notable weaknesses. The absence of past vulnerabilities is a positive indicator of developer diligence, but these identified code signals warrant attention to prevent future security issues. Addressing these specific concerns would significantly bolster the plugin's overall security.

Key Concerns

  • AJAX handlers without capability checks
  • Unescaped output detected
Vulnerabilities
None known

Bazz CallBack widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bazz CallBack widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
23 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

66% escaped35 total outputs
Attack Surface

Bazz CallBack widget Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_bazz_widget_actionbazz-callback-widget.php:142
noprivwp_ajax_bazz_widget_actionbazz-callback-widget.php:143
WordPress Hooks 8
actioninitbazz-callback-widget.php:78
actionplugins_loadedbazz-callback-widget.php:96
actioninitbazz-callback-widget.php:99
actionwp_footerbazz-callback-widget.php:108
filterwp_mail_from_namebazz-callback-widget.php:179
actionwp_footerbazz-callback-widget.php:185
actionadmin_menubazz-callback-widget.php:293
actionadmin_initbazz-callback-widget.php:296
Maintenance & Trust

Bazz CallBack widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedMar 19, 2023
PHP min version
Downloads107K

Community Trust

Rating86/100
Number of ratings33
Active installs4K
Developer Profile

Bazz CallBack widget Developer Profile

glomberg

1 plugin · 4K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bazz CallBack widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bazz-callback-widget/css/bazz-widget.css/wp-content/plugins/bazz-callback-widget/css/bazz-widget-admin.css/wp-content/plugins/bazz-callback-widget/js/jquery.maskedinput.min.js/wp-content/plugins/bazz-callback-widget/js/jquery.draggable.min.js/wp-content/plugins/bazz-callback-widget/js/bazz-widget.js/wp-content/plugins/bazz-callback-widget/js/jquery.ui-slider.js/wp-content/plugins/bazz-callback-widget/js/jquery.ui.slider-rtl.min.js
Script Paths
/wp-content/plugins/bazz-callback-widget/js/jquery.maskedinput.min.js/wp-content/plugins/bazz-callback-widget/js/jquery.draggable.min.js/wp-content/plugins/bazz-callback-widget/js/bazz-widget.js/wp-content/plugins/bazz-callback-widget/js/jquery.ui-slider.js/wp-content/plugins/bazz-callback-widget/js/jquery.ui.slider-rtl.min.js
Version Parameters
bazz-callback-widget/css/bazz-widget.css?ver=bazz-callback-widget/css/bazz-widget-admin.css?ver=bazz-callback-widget/js/jquery.maskedinput.min.js?ver=bazz-callback-widget/js/jquery.draggable.min.js?ver=bazz-callback-widget/js/bazz-widget.js?ver=bazz-callback-widget/js/jquery.ui-slider.js?ver=bazz-callback-widget/js/jquery.ui.slider-rtl.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
bazz-widgetbazz-widget-closebazz-widget-form-submitbazz-widget-buttonbazz-widget-name-closebazz-widget-inner-circlebazz-widget-inner-borderbazz-widget-form-top+1 more
Data Attributes
data-bazz-options
JS Globals
bazz_ajaxbazz_options
FAQ

Frequently Asked Questions about Bazz CallBack widget