CallPage – Callback Widget Security & Risk Analysis

wordpress.org/plugins/callpage

Widget for callback in 28 seconds! Gain 75% more leads from your website!

1K active installs v1.0.3 PHP + WP 3.0.1+ Updated Feb 3, 2026
call-buttoncall-requestcallbackcallpagecalls
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CallPage – Callback Widget Safe to Use in 2026?

Generally Safe

Score 100/100

CallPage – Callback Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'callpage' v1.0.3 plugin presents a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities, including critical or high severity ones, and the lack of known CVEs are highly positive indicators. The code analysis also reveals no dangerous functions, no unescaped file operations, and no external HTTP requests, further contributing to a secure foundation. The plugin also uses prepared statements for all SQL queries, which is a crucial security best practice for preventing SQL injection vulnerabilities.

However, the analysis does highlight some areas for potential improvement. The low percentage of properly escaped output (29%) is a significant concern. Insufficient output escaping can lead to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into web pages viewed by other users. Additionally, the complete absence of nonce checks and capability checks across all entry points (AJAX handlers, REST API routes, shortcodes, cron events) indicates a potential lack of authorization controls. If any of these entry points were to be exposed or if the attack surface grew in the future, this would present a considerable risk. The plugin's current lack of an attack surface and no reported vulnerabilities might mask these underlying weaknesses, but they remain important considerations for future development and maintenance.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

CallPage – Callback Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CallPage – Callback Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped14 total outputs
Attack Surface

CallPage – Callback Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedincludes\class-callpage-widget.php:139
actionadmin_enqueue_scriptsincludes\class-callpage-widget.php:154
actionadmin_enqueue_scriptsincludes\class-callpage-widget.php:155
actionadmin_initincludes\class-callpage-widget.php:158
actionadmin_menuincludes\class-callpage-widget.php:161
actioninitincludes\class-callpage-widget.php:184
actionwp_footerpublic\class-callpage-widget-public.php:131
actionwp_footerpublic\class-callpage-widget-public.php:135
Maintenance & Trust

CallPage – Callback Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 3, 2026
PHP min version
Downloads47K

Community Trust

Rating94/100
Number of ratings27
Active installs1K
Developer Profile

CallPage – Callback Widget Developer Profile

CallPage

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CallPage – Callback Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/callpage-widget/admin/css/callpage-widget-admin.css/wp-content/plugins/callpage-widget/admin/js/callpage-widget-admin.js
Version Parameters
callpage-widget-admin.css?ver=callpage-widget-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
callpage-widget-settings
HTML Comments
<!-- Options saved. --><!-- CallPage settings -->
Data Attributes
data-page-iddata-widget-id
JS Globals
callpage
FAQ

Frequently Asked Questions about CallPage – Callback Widget