Call Now Button Ultimate Security & Risk Analysis

wordpress.org/plugins/call-now-button-ultimate

Instantly add a customizable Call Now Button to your website. Our call now button automatically changes into an Email Us button based on your work sch …

200 active installs v1.1 PHP + WP 2.7+ Updated Jan 9, 2018
call-nowcall-us-buttoncontact-us-buttonemail-nowemail-us-button
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Call Now Button Ultimate Safe to Use in 2026?

Generally Safe

Score 85/100

Call Now Button Ultimate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin 'call-now-button-ultimate' v1.1 demonstrates a strong foundational security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with potential entry points significantly reduces the plugin's attack surface. Furthermore, the code analysis shows no dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests, which are all positive indicators of secure coding practices. The lack of critical and high-severity taint analysis results is also a reassuring sign.

However, a notable concern arises from the low percentage of properly escaped output (22%). This indicates a significant risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data or plugin-generated content may not be sufficiently sanitized before being displayed to users. The complete absence of nonce checks and capability checks, coupled with a 0% proper output escaping rate, suggests a general lack of robust authorization and input validation mechanisms for any potential, albeit currently undiscovered, interaction points. The vulnerability history showing zero past CVEs is positive, but this could also be attributed to the limited attack surface or the plugin not being extensively scrutinized. The overall picture is a plugin with a small attack surface but with a critical weakness in output sanitization and authorization checks that needs immediate attention.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Call Now Button Ultimate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Call Now Button Ultimate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

22% escaped18 total outputs
Attack Surface

Call Now Button Ultimate Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menugethuman-call-now-button-ultimate.php:43
actionadmin_enqueue_scriptsgethuman-call-now-button-ultimate.php:44
actionadmin_initgethuman-call-now-button-ultimate.php:45
actionwp_footergethuman-call-now-button-ultimate.php:49
Maintenance & Trust

Call Now Button Ultimate Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 9, 2018
PHP min version
Downloads9K

Community Trust

Rating94/100
Number of ratings7
Active installs200
Developer Profile

Call Now Button Ultimate Developer Profile

gethuman

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Call Now Button Ultimate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/call-now-button-ultimate/gethuman-call-now-button-ultimate.js
Script Paths
https://gethuman.com/call-now-button-ultimate-wp-plugin.js
Version Parameters
call-now-button-ultimate/gethuman-call-now-button-ultimate.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="gh-cnbu-plugin"
JS Globals
gh_cnbu_call_now_button_ultimate_options
FAQ

Frequently Asked Questions about Call Now Button Ultimate