Click to call button Security & Risk Analysis

wordpress.org/plugins/click-to-call-button

Shows a Click to Call / Call Now Button to your visitors and turns your website into a phone with call recording, voicemail and SMS.

100 active installs v0.0.1 PHP + WP 3.5+ Updated Aug 17, 2015
answering-machinecall-now-buttonclick-to-callclick-to-call-buttonvoicemail
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Click to call button Safe to Use in 2026?

Generally Safe

Score 85/100

Click to call button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'click-to-call-button' plugin v0.0.1 presents a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query security, utilizing prepared statements exclusively, and has no recorded vulnerability history, suggesting a lack of known exploitable flaws. The absence of file operations and bundled libraries further minimizes potential attack vectors. However, significant concerns arise from the code analysis. The taint analysis reveals four flows with unsanitized paths, indicating a potential for data manipulation or injection, even though no critical or high severity issues were flagged by this specific analysis. More concerningly, 49% of output is not properly escaped, creating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the complete absence of nonce checks and capability checks on any potential entry points, even though the attack surface appears limited in terms of documented handlers, is a serious oversight that leaves the plugin vulnerable to unauthorized actions or data exposure if new entry points are discovered or introduced.

Key Concerns

  • Significant percentage of unescaped output
  • Unsanitized paths in taint flows
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Click to call button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Click to call button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
46
45 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

49% escaped91 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
ctcb_service_status (includes\ctcb_callback_handlers.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Click to call button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuadmin\ctcb_admin.php:465
actionadmin_initadmin\ctcb_admin.php:470
actionadmin_enqueue_scriptsadmin\ctcb_admin.php:476
actionparse_requestincludes\ctcb_callback_handlers.php:294
filterquery_varsincludes\ctcb_callback_handlers.php:295
actionwpincludes\ctcb_callback_handlers.php:296
actionwp_headincludes\ctcb_public_facing.php:71
actionwp_footerincludes\ctcb_public_facing.php:280
Maintenance & Trust

Click to call button Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedAug 17, 2015
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Click to call button Developer Profile

Andy Moore

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Click to call button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/click-to-call-button/images/paypal_donate_button.gif/wp-content/plugins/click-to-call-button/css/style.css/wp-content/plugins/click-to-call-button/js/script.js
Script Paths
/wp-content/plugins/click-to-call-button/js/script.js
Version Parameters
click-to-call-button/css/style.css?ver=click-to-call-button/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
ctcb-button
Data Attributes
data-default-color
FAQ

Frequently Asked Questions about Click to call button