
Call Button Security & Risk Analysis
wordpress.org/plugins/call-buttonA modern, easy to use call button that shoots to increase conversions and drive sales!
Is Call Button Safe to Use in 2026?
Generally Safe
Score 85/100Call Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "call-button" v1.0 plugin exhibits a seemingly strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate no dangerous functions, all SQL queries use prepared statements, and there are no file operations or external HTTP requests, which are all positive security indicators. However, a significant concern arises from the output escaping, where only 40% of outputs are properly escaped. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, as unescaped output can allow malicious scripts to be injected and executed within the WordPress admin area or on the frontend, depending on where these outputs are rendered. The vulnerability history being clear of any known CVEs is a positive sign, suggesting the plugin has historically been well-maintained or has not been a target. In conclusion, while the plugin avoids many common pitfalls, the identified issue with output escaping presents a tangible risk that needs immediate attention. The limited attack surface and good practices in other areas are strengths, but the lack of comprehensive output sanitization is a notable weakness.
Key Concerns
- Insufficient output escaping
Call Button Security Vulnerabilities
Call Button Code Analysis
Output Escaping
Call Button Attack Surface
WordPress Hooks 11
Maintenance & Trust
Call Button Maintenance & Trust
Maintenance Signals
Community Trust
Call Button Alternatives
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
WP Call Button – Easy Click to Call Button for WordPress
wp-call-button
The best WordPress call now button plugin. We help you add a clickable phone link (quick call button), so people can easily call your business phone.
Really Simple Click To Call Bar
really-simple-click-to-call
A simple plugin that adds a click to call bar/call now button for mobile visitors.
All-in-one contact buttons – WPSHARE247
all-in-one-contact-buttons-wpshare247
Floating click to contact buttons All-In-One Tạo nút liên hệ gôm tất cả vào trong một nút duy nhất bao gồm: số hotline, zalo, facebook, messenger, ema …
Floating Click to Contact Buttons
floating-click-to-contact-buttons
Tạo các nút gọi, nút chat Zalo, nút Chat messenger, nút để lại thông tin để tư vấn, nút chỉ đường. Trình bày các nút đẹp mắt ở góc phải dưới màn hình, …
Call Button Developer Profile
3 plugins · 10K total installs
How We Detect Call Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/call-button/assets/css/pushlabs-callbutton-backend.css/wp-content/plugins/call-button/assets/js/pushlabs-callbutton-backend.js/wp-content/plugins/call-button/assets/css/pushlabs-callbutton.css/wp-content/plugins/call-button/inc/vendor/font-awesome/css/font-awesome.min.css/wp-content/plugins/call-button/assets/js/pushlabs-callbutton-backend.jspushlabs-callbutton-backend?ver=pushlabs-callbutton?ver=pushlabs-callbutton-fontawesome?ver=HTML / DOM Fingerprints
pushlabs-callbuttonpushlabs-callbutton-style--buttonpushlabs-callbutton-backgroundpushlabs-callbutton-icon-pospushlabs-callbutton-shadowpushlabs-callbutton-background-whitepushlabs-callbutton-style--bannerpushlabs_callbutton_imgUrlpushlabs_callbutton