
CallBack Widget for WordPress Security & Risk Analysis
wordpress.org/plugins/callback-widgetThe conversion of the site and landing pages up to 50%. Integrate CallBack widget by CallBackHunter in WordPress. And livechat, feedback form.
Is CallBack Widget for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100CallBack Widget for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "callback-widget" plugin version 20150911 exhibits a generally strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the plugin's attack surface. Furthermore, the analysis indicates no dangerous functions are used, all SQL queries are properly prepared, and there are no file operations or external HTTP requests. This suggests a cautious approach to implementing potentially risky functionalities.
However, a notable concern is the low percentage of properly escaped output (33%). While the number of outputs is small (3), it implies that a portion of the plugin's output is not being sanitized before being rendered. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is included in these unescaped outputs. The lack of identified CVEs and a clean vulnerability history is positive, suggesting the plugin has historically been secure or that potential vulnerabilities have been addressed. Despite the limited attack surface, the unescaped output remains a weakness that could be exploited.
Key Concerns
- Unescaped output identified
CallBack Widget for WordPress Security Vulnerabilities
CallBack Widget for WordPress Code Analysis
Output Escaping
CallBack Widget for WordPress Attack Surface
WordPress Hooks 2
Maintenance & Trust
CallBack Widget for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
CallBack Widget for WordPress Alternatives
Contact Form & SMTP Plugin for WordPress by PirateForms
pirate-forms
A simple and effective WordPress contact form & SMTP plugin. Compatible with best themes out there, is both a secure and responsive contact form p …
Contact Form Clean and Simple
clean-and-simple-contact-form-by-meg-nicholas
A clean and simple contact form with flexible CSS framework support.
More Mails for CF7
more-mails-for-cf7
Extends the ubiquitous Contact Form 7 plugin to allow three or more messages.
Contact Form 7 Countries
cf7-countries
Country drop-down menu for Contact Form 7.
Contact Form X
contact-form-x
Displays a user-friendly contact form that your visitors will love. Lightweight, fast, secure, and accessible (ADA/WCAG compliant).
CallBack Widget for WordPress Developer Profile
7 plugins · 700 total installs
How We Detect CallBack Widget for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.