
Call Leads WordPress Plugin Security & Risk Analysis
wordpress.org/plugins/call-leadsThe easiest way to get more call leads, turn leads to customers.
Is Call Leads WordPress Plugin Safe to Use in 2026?
Generally Safe
Score 85/100Call Leads WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "call-leads" plugin version 1.0 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, file operations, and raw SQL queries is a strong positive. The high percentage of properly escaped outputs and the use of prepared statements for SQL queries indicate developers are following secure coding practices in these areas. The plugin also demonstrates an awareness of security by implementing nonce checks on two entry points.
However, a significant concern arises from the complete lack of capability checks across all identified entry points, including the three AJAX handlers. This means that any user, regardless of their role or permissions within WordPress, could potentially trigger these AJAX actions. While there are no known vulnerabilities or taint flows reported, this lack of authorization on critical entry points presents a substantial risk of privilege escalation or unauthorized actions if a vulnerability were discovered or introduced in the future. The plugin's clean vulnerability history is a positive indicator, but it doesn't negate the inherent risk of exposed functionality.
In conclusion, "call-leads" v1.0 has some commendable security practices in place, particularly regarding data handling and escaping. Nevertheless, the complete omission of capability checks on its AJAX handlers creates a critical security weakness that significantly elevates its risk profile. Addressing this oversight should be a top priority to ensure the plugin's secure operation.
Key Concerns
- No capability checks on AJAX handlers
Call Leads WordPress Plugin Security Vulnerabilities
Call Leads WordPress Plugin Code Analysis
Output Escaping
Call Leads WordPress Plugin Attack Surface
AJAX Handlers 3
WordPress Hooks 10
Maintenance & Trust
Call Leads WordPress Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Call Leads WordPress Plugin Alternatives
Bazz CallBack widget
bazz-callback-widget
This plugin makes a simple widget for callback on your website.
CallPage – Callback Widget
callpage
Widget for callback in 28 seconds! Gain 75% more leads from your website!
ZVI CallBack widget
zvi-callback-widget
This plugin makes a simple widget for callback on your website.
Quick Contact and Call back widget
wp-call-me-back
WP Call Back, gives you the ability to quickly add a call back widget to the sidebar of your website.
Free Call Me Back Widget
quiits-call-me-back-widget
Increase Your Website Conversion Up To 60% by enabling them to Request a Call back. Activate Call me back widget on your website in less than 30 secon …
Call Leads WordPress Plugin Developer Profile
1 plugin · 20 total installs
How We Detect Call Leads WordPress Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/call-leads/assets/css/jquery-ui.css/wp-content/plugins/call-leads/assets/css/admin_style.css/wp-content/plugins/call-leads/assets/css/admin_style_rtl.css/wp-content/plugins/call-leads/assets/js/wp-color-picker-alpha.min.js/wp-content/plugins/call-leads/assets/js/admin_script.js/wp-content/plugins/call-leads/assets/js/wp-color-picker-alpha.min.js/wp-content/plugins/call-leads/assets/js/admin_script.jscall-leads/assets/css/jquery-ui.css?ver=call-leads/assets/css/admin_style.css?ver=call-leads/assets/css/admin_style_rtl.css?ver=call-leads/assets/js/wp-color-picker-alpha.min.js?ver=call-leads/assets/js/admin_script.js?ver=HTML / DOM Fingerprints
calds_admin_csscalds_admin_rtl_cssCALDS_PLUGIN_URLCALDS_VERSION/wp-json/callleads/