CallTrackingMetrics Security & Risk Analysis
wordpress.org/plugins/call-tracking-metricsCallTrackingMetrics integrates with your WordPress site to provide powerful call tracking and attribution.
Is CallTrackingMetrics Safe to Use in 2026?
Generally Safe
Score 100/100CallTrackingMetrics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'call-tracking-metrics' plugin v2.1.8 exhibits a generally positive security posture, with a strong emphasis on prepared statements for SQL queries and a high percentage of properly escaped output. The absence of known CVEs and recorded vulnerability history suggests a proactive approach to security by the developers or a lack of historical exposure. However, the plugin is not without its risks. The presence of three AJAX handlers without authentication checks represents a significant attack surface that could potentially be exploited. The use of the dangerous `unserialize` function, while not directly tied to a taint flow in this analysis, always carries inherent risks of deserialization vulnerabilities if not handled with extreme caution and strict input validation. While the current taint analysis shows no critical or high severity issues, the single flow with unsanitized paths warrants attention as it could be a precursor to more severe vulnerabilities in future versions or under different attack vectors. In conclusion, the plugin demonstrates good core security practices but requires immediate attention to the unprotected AJAX endpoints and careful monitoring of the `unserialize` function's usage.
Key Concerns
- Unprotected AJAX handlers detected
- Use of dangerous unserialize function
- Flow with unsanitized paths found
CallTrackingMetrics Security Vulnerabilities
CallTrackingMetrics Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CallTrackingMetrics Attack Surface
AJAX Handlers 40
WordPress Hooks 27
Maintenance & Trust
CallTrackingMetrics Maintenance & Trust
Maintenance Signals
Community Trust
CallTrackingMetrics Alternatives
RedPic ADS Manager Lite
rp-ads-manager
JS/HTML ads block manager. Allows you to create and insert blocks of code anywhere on the blog.
AdNgin-Adsense Revenue Optimization
adngin-your-adsense-your-traffic-maximized-revenue-for-free
Your AdSense, Your Traffic, Maximized Revenue
AdScale AI Ads Meta/Google Ads
adscale-ai
Scale WooCommerce sales with AI advertising. AI that builds audiences, Creating winning ads, launches Google & Meta ads, and optimizes ROAS 24/7.
LH Multisite Ads
lh-multisite-ads
Allows you to insert ads after paragraphs of your post content, throughout your multisite network.
REXADZ Monetization
rexadz-monetization
REXADZ is a simple and user-friendly ad solution that makes you money by automatically displaying targeted ads to your website visitors.
CallTrackingMetrics Developer Profile
2 plugins · 3K total installs
How We Detect CallTrackingMetrics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/call-tracking-metrics/assets/js/ctm-script.js/wp-content/plugins/call-tracking-metrics/assets/css/ctm-styles.css/wp-content/plugins/call-tracking-metrics/assets/js/ctm-script.jscall-tracking-metrics/assets/js/ctm-script.js?ver=call-tracking-metrics/assets/css/ctm-styles.css?ver=HTML / DOM Fingerprints
ctm-field-mappingctm-log-tablectm-admin-options<!-- CTMS: Plugin active -->data-ctm-iddata-ctm-phone-fielddata-ctm-form-idwindow.ctm_ajax_objectctm_ajax_object.ajax_urlctm_ajax_object.noncectm_ajax_object.ctm_api_url/wp-json/call-tracking-metrics/v1/log/wp-json/call-tracking-metrics/v1/usage[ctm_tracking_script]