
Call From Web – Click to Call & Live Support Button for WordPress Security & Risk Analysis
wordpress.org/plugins/call-from-web🚀 Transform Your Website into a Direct Communication Channel! Get FREE Calls from Visitors Worldwide. Boost Conversions & Customer Satisfaction. 💪
Is Call From Web – Click to Call & Live Support Button for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Call From Web – Click to Call & Live Support Button for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'call-from-web' plugin v4.0.3 exhibits a generally good security posture concerning direct attack vectors and traditional vulnerabilities. The static analysis reveals no AJAX handlers, REST API routes, shortcodes, or cron events, resulting in zero entry points. Furthermore, there are no identified dangerous functions or SQL queries that are not using prepared statements. The plugin also has no recorded CVEs, indicating a history of secure development or diligent patching.
However, the analysis highlights significant concerns regarding output escaping and taint analysis. With 100% of its outputs not properly escaped and two flows identified with unsanitized paths, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on any potential, albeit currently undiscovered, entry points further compounds this risk. The presence of an external HTTP request also warrants attention, as it could be a vector for further compromise if not handled securely.
In conclusion, while the plugin avoids common attack surfaces and has a clean vulnerability history, the unescaped outputs and unsanitized taint flows represent critical weaknesses. These issues could be exploited to inject malicious scripts or manipulate plugin behavior, potentially leading to data theft or site defacement. The lack of explicit authentication checks for any potential future entry points is also a concern for future extensibility.
Key Concerns
- Output escaping is not implemented
- Taint flows with unsanitized paths
- No nonce checks
- No capability checks
Call From Web – Click to Call & Live Support Button for WordPress Security Vulnerabilities
Call From Web – Click to Call & Live Support Button for WordPress Code Analysis
Output Escaping
Data Flow Analysis
Call From Web – Click to Call & Live Support Button for WordPress Attack Surface
WordPress Hooks 11
Maintenance & Trust
Call From Web – Click to Call & Live Support Button for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Call From Web – Click to Call & Live Support Button for WordPress Alternatives
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
Call Me Button for Call Center Online
call-center-online
A simple-to-use plugin that works with the Call Center Online platform. Adds a button to collect contacts on your website.
Really Simple Click To Call Bar
really-simple-click-to-call
A simple plugin that adds a click to call bar/call now button for mobile visitors.
Floating Click to Contact Buttons
floating-click-to-contact-buttons
Tạo các nút gọi, nút chat Zalo, nút Chat messenger, nút để lại thông tin để tư vấn, nút chỉ đường. Trình bày các nút đẹp mắt ở góc phải dưới màn hình, …
Mobile Call Buttons
mobile-call-buttons
Lightweight plugin that displays two fixed call buttons on mobile devices to boost conversions.
Call From Web – Click to Call & Live Support Button for WordPress Developer Profile
1 plugin · 10 total installs
How We Detect Call From Web – Click to Call & Live Support Button for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/call-from-web/css/call-from-web-admin.css/wp-content/plugins/call-from-web/js/call-from-web-admin.js/wp-content/plugins/call-from-web/js/call-from-web.js/wp-content/plugins/call-from-web/css/call-from-web.cssjs/call-from-web-admin.jsjs/call-from-web.jscall-from-web-admin.css?ver=call-from-web-admin.js?ver=call-from-web.js?ver=call-from-web.css?ver=HTML / DOM Fingerprints
cfw-buttondata-cfw-button-iddata-cfw-widget-iddata-cfw-company-iddata-cfw-caller-iddata-cfw-widget-urlcall_from_web_data