
CallPage – Callback Widget Security & Risk Analysis
wordpress.org/plugins/callpageWidget for callback in 28 seconds! Gain 75% more leads from your website!
Is CallPage – Callback Widget Safe to Use in 2026?
Generally Safe
Score 100/100CallPage – Callback Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'callpage' v1.0.3 plugin presents a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities, including critical or high severity ones, and the lack of known CVEs are highly positive indicators. The code analysis also reveals no dangerous functions, no unescaped file operations, and no external HTTP requests, further contributing to a secure foundation. The plugin also uses prepared statements for all SQL queries, which is a crucial security best practice for preventing SQL injection vulnerabilities.
However, the analysis does highlight some areas for potential improvement. The low percentage of properly escaped output (29%) is a significant concern. Insufficient output escaping can lead to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into web pages viewed by other users. Additionally, the complete absence of nonce checks and capability checks across all entry points (AJAX handlers, REST API routes, shortcodes, cron events) indicates a potential lack of authorization controls. If any of these entry points were to be exposed or if the attack surface grew in the future, this would present a considerable risk. The plugin's current lack of an attack surface and no reported vulnerabilities might mask these underlying weaknesses, but they remain important considerations for future development and maintenance.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
CallPage – Callback Widget Security Vulnerabilities
CallPage – Callback Widget Code Analysis
Output Escaping
CallPage – Callback Widget Attack Surface
WordPress Hooks 8
Maintenance & Trust
CallPage – Callback Widget Maintenance & Trust
Maintenance Signals
Community Trust
CallPage – Callback Widget Alternatives
Bazz CallBack widget
bazz-callback-widget
This plugin makes a simple widget for callback on your website.
Novocall – Callback Widget
novocall-callback-widget
Novocall is a powerful callback widget that helps increase your web conversion by prompting interested visitors with a free callback in seconds, while …
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
API KEY for Google Maps
api-key-for-google-maps
Retroactively add Google Maps API KEY to any theme or plugin.
WP Call Button – Easy Click to Call Button for WordPress
wp-call-button
The best WordPress call now button plugin. We help you add a clickable phone link (quick call button), so people can easily call your business phone.
CallPage – Callback Widget Developer Profile
1 plugin · 1K total installs
How We Detect CallPage – Callback Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/callpage-widget/admin/css/callpage-widget-admin.css/wp-content/plugins/callpage-widget/admin/js/callpage-widget-admin.jscallpage-widget-admin.css?ver=callpage-widget-admin.js?ver=HTML / DOM Fingerprints
callpage-widget-settings<!-- Options saved. --><!-- CallPage settings -->data-page-iddata-widget-idcallpage