
Call Now Button Ultimate Security & Risk Analysis
wordpress.org/plugins/call-now-button-ultimateInstantly add a customizable Call Now Button to your website. Our call now button automatically changes into an Email Us button based on your work sch …
Is Call Now Button Ultimate Safe to Use in 2026?
Generally Safe
Score 85/100Call Now Button Ultimate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'call-now-button-ultimate' v1.1 demonstrates a strong foundational security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events with potential entry points significantly reduces the plugin's attack surface. Furthermore, the code analysis shows no dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests, which are all positive indicators of secure coding practices. The lack of critical and high-severity taint analysis results is also a reassuring sign.
However, a notable concern arises from the low percentage of properly escaped output (22%). This indicates a significant risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data or plugin-generated content may not be sufficiently sanitized before being displayed to users. The complete absence of nonce checks and capability checks, coupled with a 0% proper output escaping rate, suggests a general lack of robust authorization and input validation mechanisms for any potential, albeit currently undiscovered, interaction points. The vulnerability history showing zero past CVEs is positive, but this could also be attributed to the limited attack surface or the plugin not being extensively scrutinized. The overall picture is a plugin with a small attack surface but with a critical weakness in output sanitization and authorization checks that needs immediate attention.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks implemented
- No capability checks implemented
Call Now Button Ultimate Security Vulnerabilities
Call Now Button Ultimate Code Analysis
Output Escaping
Call Now Button Ultimate Attack Surface
WordPress Hooks 4
Maintenance & Trust
Call Now Button Ultimate Maintenance & Trust
Maintenance Signals
Community Trust
Call Now Button Ultimate Alternatives
Call Now and Chat Buttons
call-now-and-chat-buttons
Add instant "Call Now" and "Chat" buttons to your website, allowing visitors to seamlessly contact you with a single click.
Click to Call or Chat Buttons
click-to-call-or-chat-buttons
This plugin adds Phone Call and WhatsApp button on your webpage.
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements
mystickyelements
Get leads with a floating contact form tab, chat & social buttons like Facebook Messenger, WhatsApp, Viber, Telegram, Twitter, Instagram & more 🎉
WP Call Button – Easy Click to Call Button for WordPress
wp-call-button
The best WordPress call now button plugin. We help you add a clickable phone link (quick call button), so people can easily call your business phone.
Call Now Button Ultimate Developer Profile
1 plugin · 200 total installs
How We Detect Call Now Button Ultimate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/call-now-button-ultimate/gethuman-call-now-button-ultimate.jshttps://gethuman.com/call-now-button-ultimate-wp-plugin.jscall-now-button-ultimate/gethuman-call-now-button-ultimate.js?ver=HTML / DOM Fingerprints
id="gh-cnbu-plugin"gh_cnbu_call_now_button_ultimate_options