Call From Web – Click to Call & Live Support Button for WordPress Security & Risk Analysis

wordpress.org/plugins/call-from-web

🚀 Transform Your Website into a Direct Communication Channel! Get FREE Calls from Visitors Worldwide. Boost Conversions & Customer Satisfaction. 💪

10 active installs v4.0.3 PHP + WP 3.0.1+ Updated May 7, 2025
call-buttoncall-now-buttonclick-to-callcontact-buttonconvert
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Call From Web – Click to Call & Live Support Button for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

Call From Web – Click to Call & Live Support Button for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The 'call-from-web' plugin v4.0.3 exhibits a generally good security posture concerning direct attack vectors and traditional vulnerabilities. The static analysis reveals no AJAX handlers, REST API routes, shortcodes, or cron events, resulting in zero entry points. Furthermore, there are no identified dangerous functions or SQL queries that are not using prepared statements. The plugin also has no recorded CVEs, indicating a history of secure development or diligent patching.

However, the analysis highlights significant concerns regarding output escaping and taint analysis. With 100% of its outputs not properly escaped and two flows identified with unsanitized paths, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on any potential, albeit currently undiscovered, entry points further compounds this risk. The presence of an external HTTP request also warrants attention, as it could be a vector for further compromise if not handled securely.

In conclusion, while the plugin avoids common attack surfaces and has a clean vulnerability history, the unescaped outputs and unsanitized taint flows represent critical weaknesses. These issues could be exploited to inject malicious scripts or manipulate plugin behavior, potentially leading to data theft or site defacement. The lack of explicit authentication checks for any potential future entry points is also a concern for future extensibility.

Key Concerns

  • Output escaping is not implemented
  • Taint flows with unsanitized paths
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Call From Web – Click to Call & Live Support Button for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Call From Web – Click to Call & Live Support Button for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
store_pairing_token_and_redirect (admin\class-call-from-web-admin.php:180)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Call From Web – Click to Call & Live Support Button for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedincludes\class-call-from-web.php:145
actionadmin_enqueue_scriptsincludes\class-call-from-web.php:161
actionadmin_enqueue_scriptsincludes\class-call-from-web.php:162
actionadmin_noticesincludes\class-call-from-web.php:164
actionadmin_initincludes\class-call-from-web.php:166
actionwp_loadedincludes\class-call-from-web.php:168
actionwp_loadedincludes\class-call-from-web.php:169
actionwp_loadedincludes\class-call-from-web.php:170
actionwp_enqueue_scriptsincludes\class-call-from-web.php:185
actionwp_enqueue_scriptsincludes\class-call-from-web.php:186
actionwp_footerincludes\class-call-from-web.php:188
Maintenance & Trust

Call From Web – Click to Call & Live Support Button for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 7, 2025
PHP min version
Downloads8K

Community Trust

Rating74/100
Number of ratings3
Active installs10
Developer Profile

Call From Web – Click to Call & Live Support Button for WordPress Developer Profile

call_from_web

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Call From Web – Click to Call & Live Support Button for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/call-from-web/css/call-from-web-admin.css/wp-content/plugins/call-from-web/js/call-from-web-admin.js/wp-content/plugins/call-from-web/js/call-from-web.js/wp-content/plugins/call-from-web/css/call-from-web.css
Script Paths
js/call-from-web-admin.jsjs/call-from-web.js
Version Parameters
call-from-web-admin.css?ver=call-from-web-admin.js?ver=call-from-web.js?ver=call-from-web.css?ver=

HTML / DOM Fingerprints

CSS Classes
cfw-button
Data Attributes
data-cfw-button-iddata-cfw-widget-iddata-cfw-company-iddata-cfw-caller-iddata-cfw-widget-url
JS Globals
call_from_web_data
FAQ

Frequently Asked Questions about Call From Web – Click to Call & Live Support Button for WordPress