
Broadcast – WordPress Call to Actions Security & Risk Analysis
wordpress.org/plugins/broadcast-call-to-actionsBroadcast is a call to action (CTA) management plugin that allows you to easy manage and display CTAs within your WordPress content.
Is Broadcast – WordPress Call to Actions Safe to Use in 2026?
Generally Safe
Score 85/100Broadcast – WordPress Call to Actions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "broadcast-call-to-actions" plugin v1.0 exhibits a generally positive security posture due to robust implementation of security best practices such as nonce and capability checks. The static analysis reveals no critical or high severity taint flows, and the absence of known vulnerabilities in its history further strengthens this assessment. All identified entry points, including AJAX handlers and shortcodes, appear to have appropriate authentication and permission checks, which is commendable.
However, a significant concern arises from the handling of SQL queries. The single detected SQL query is not being prepared, presenting a potential risk for SQL injection vulnerabilities if user-supplied data is ever incorporated into this query without proper sanitization. Additionally, the plugin's output escaping is only at 33%, indicating a substantial risk of cross-site scripting (XSS) vulnerabilities if any output is not properly sanitized. While the current attack surface is protected, the lack of preparedness in SQL and insufficient output escaping are notable weaknesses.
In conclusion, the plugin demonstrates a solid foundation with good authentication and authorization practices. The lack of past vulnerabilities is a positive indicator. Nevertheless, the unescaped output and the unprepared SQL query represent significant avenues for potential exploitation that require immediate attention to fully secure the plugin.
Key Concerns
- Raw SQL query without prepared statements
- Low percentage of properly escaped output
Broadcast – WordPress Call to Actions Security Vulnerabilities
Broadcast – WordPress Call to Actions Release Timeline
Broadcast – WordPress Call to Actions Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Broadcast – WordPress Call to Actions Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
Broadcast – WordPress Call to Actions Maintenance & Trust
Maintenance Signals
Community Trust
Broadcast – WordPress Call to Actions Alternatives
Mobile Contact Bar
mobile-contact-bar
Allow your visitors to contact you via mobile phones, or access your site's pages instantly.
WP CTA – Call Now Button, Sticky Button & Call to Action Builder
easy-sticky-sidebar
WordPress Call To Action builder that creates sticky buttons, call now buttons and CTAs to boost clicks, increase sales and generate leads.
TopBar Call To Action
topbar-call-to-action
Allow user to add upsales or any call to actions with TopBar Call To Action.
Call to Action Block by WPPOOL
call-to-action-block-wppool
Add a stunning call to action (CTA) block to your WordPress post or page using 10+ prebuilt call to action layouts for Gutenberg.
CTA Button Styler
cta-button-styler
Increase engagement with reusable CTA buttons, styled your way with hover effects and optional animations. Clean and efficient.
Broadcast – WordPress Call to Actions Developer Profile
3 plugins · 200K total installs
How We Detect Broadcast – WordPress Call to Actions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/broadcast-call-to-actions/core/classes/class.enqueue.php/wp-content/plugins/broadcast-call-to-actions/core/classes/class.shortcode.php/wp-content/plugins/broadcast-call-to-actions/functions/functions.php/wp-content/plugins/broadcast-call-to-actions/functions/post_types.php/wp-content/plugins/broadcast-call-to-actions/core/classes/class.enqueue.php/wp-content/plugins/broadcast-call-to-actions/core/classes/class.shortcode.php/wp-content/plugins/broadcast-call-to-actions/functions/functions.php/wp-content/plugins/broadcast-call-to-actions/functions/post_types.phpHTML / DOM Fingerprints
broadcast-meta-callout<!-- Broadcast - Link Options --><!-- Attach a custom link button label, URL and target to this call to action --><!-- Button Label --><!-- URL -->+2 morename="broadcast_label"id="broadcast_label"name="broadcast_url"id="broadcast_url"name="broadcast_target"id="broadcast_target"[broadcast][broadcast][broadcast][broadcast]