Callout Security & Risk Analysis

wordpress.org/plugins/callout-block

A styled box for featured content.

400 active installs v1.1.0 PHP 7.4+ WP 6.2+ Updated Apr 13, 2023
blockcalloutcallout-boxfeatured-boxstyled-box
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Callout Safe to Use in 2026?

Generally Safe

Score 85/100

Callout has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The static analysis of the 'callout-block' plugin v1.1.0 reveals an exceptionally small attack surface. The absence of AJAX handlers, REST API routes, shortcodes, and cron events, particularly without authentication checks, indicates a robust design principle for minimizing entry points. The code signals further reinforce this positive security posture with a complete absence of dangerous functions, SQL queries that are all prepared, and all output being properly escaped. There are no file operations, external HTTP requests, or instances of missing nonce or capability checks. Taint analysis also shows zero flows, indicating no apparent pathways for unsanitized data to impact critical functions.

The vulnerability history for this plugin is clean, with zero known CVEs, no currently unpatched vulnerabilities, and no historical patterns of common vulnerability types. This lack of recorded security incidents, combined with the strong static analysis results, suggests a well-maintained and secure codebase. While the absence of certain security checks (nonces, capabilities) might raise eyebrows in isolation, in the context of this plugin's extremely limited attack surface, it appears to be a deliberate and acceptable trade-off. The overall security posture is excellent, demonstrating a strong commitment to secure coding practices.

Vulnerabilities
None known

Callout Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Callout Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Callout Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitcallout-block.php:29
Maintenance & Trust

Callout Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 13, 2023
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs400
Developer Profile

Callout Developer Profile

Roel Magdaleno

5 plugins · 2K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Callout

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/callout-block/build/index.js/wp-content/plugins/callout-block/build/style-index.css/wp-content/plugins/callout-block/build/index.css
Script Paths
/wp-content/plugins/callout-block/build/index.js
Version Parameters
callout-block/build/index.js?ver=callout-block/build/style-index.css?ver=callout-block/build/index.css?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-callout-block-callout-block
FAQ

Frequently Asked Questions about Callout