CallRail Phone Call Tracking Security & Risk Analysis
wordpress.org/plugins/callrail-phone-call-trackingDynamically swap CallRail tracking phone numbers based on the visitor's referring source.
Is CallRail Phone Call Tracking Safe to Use in 2026?
Generally Safe
Score 99/100CallRail Phone Call Tracking has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin exhibits some good security practices, particularly in its avoidance of dangerous functions, the use of prepared statements for all SQL queries, and a generally high rate of output escaping. However, there are significant concerns regarding its attack surface. The presence of a REST API route without a permission callback represents a clear entry point that is not adequately protected, potentially allowing unauthorized access or manipulation of plugin functionality. While the taint analysis did not reveal any critical or high-severity unsanitized flows in this specific version, the past vulnerability history, including two medium-severity Cross-Site Scripting (XSS) vulnerabilities, suggests a recurring pattern of input sanitization weaknesses. The fact that these past vulnerabilities are now patched is positive, but the historical data warrants vigilance. Overall, the plugin has strengths in its internal code handling but requires attention to its external interfaces to mitigate risks.
Key Concerns
- REST API route without permission callback
- Historical XSS vulnerabilities
CallRail Phone Call Tracking Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
CallRail Phone Call Tracking <= 0.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
CallRail Phone Call Tracking <= 0.4.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting
CallRail Phone Call Tracking Code Analysis
Output Escaping
Data Flow Analysis
CallRail Phone Call Tracking Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
CallRail Phone Call Tracking Maintenance & Trust
Maintenance Signals
Community Trust
CallRail Phone Call Tracking Alternatives
Nimbata Call Tracking
nimbata-call-tracking
Dynamically swap your site's phone number with a nimbata tracking numbers. Track which sources generate phone leads to your business.
Freespee Call Tracking
freespee-call-tracking
See which visitors ended up calling you, no coding required. Automated delivery of phone call data to your Google Analytics account.
Tracking Script Manager
tracking-script-manager
Easy tag management. Manage the tracking tags, codes and scripts you use in your WordPress site; easily add, update, reorder, delete, as required.
Technoscore Google Tracking
technoscore-google-tracking
Technoscore Google Tracking is best Google Analytics plugin for WordPress. See how visitors find and use your website, so you can keep them coming ba …
SEO SIMPLE PACK
seo-simple-pack
This is a very simple SEO plugin. You can easily set and customize meta tags and OGP tags for each page.
CallRail Phone Call Tracking Developer Profile
1 plugin · 10K total installs
How We Detect CallRail Phone Call Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/callrail-phone-call-tracking/swap.js//cdn.callrail.com/companies/[escaped_api_key]/wp-0-5-3/swap.jscallrail-phone-call-tracking/style.css?ver=HTML / DOM Fingerprints
<!-- CallRail WordPress Integration -->id="cr-form-class="regular-text code"window.crwpVer/calltrk/v1/store<div id="cr-form-</div>