Converzo Click-to-Call button Security & Risk Analysis

wordpress.org/plugins/click-to-call-button-by-converzo-nl

With this plugin you add a click-to-call button to your responsive website in no-time.

0 active installs v1.0 PHP + WP 3.0+ Updated Aug 2, 2019
add-a-click-to-call-button-to-responsive-website
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Converzo Click-to-Call button Safe to Use in 2026?

Generally Safe

Score 85/100

Converzo Click-to-Call button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of the 'click-to-call-button-by-converzo-nl' plugin v1.0 reveals a remarkably clean code base with no identified attack surface through AJAX, REST API, shortcodes, or cron events. The absence of dangerous functions, file operations, external HTTP requests, and reliance on prepared statements for SQL queries are all positive security indicators. However, the complete lack of output escaping is a significant concern, suggesting that any dynamic data rendered to the user interface is not being properly sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is incorporated into the output. The vulnerability history is also empty, indicating no known public exploits or past issues, which is a good sign of responsible development.

Despite the lack of discovered vulnerabilities and a small attack surface, the critical oversight in output escaping presents a clear and present risk. While the plugin might not have exploitable entry points due to its limited functionality as indicated, the potential for XSS remains if any part of its rendering process handles user-controlled data. The absence of nonce and capability checks is noted but is less concerning given the zero attack surface; however, it indicates a lack of robust authorization practices that could become an issue if new entry points are introduced in future versions. Overall, the plugin demonstrates good practices in some areas but suffers from a critical deficiency in output sanitization.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

Converzo Click-to-Call button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Converzo Click-to-Call button Release Timeline

v1.1
v1.0Current
Code Analysis
Analyzed Apr 16, 2026

Converzo Click-to-Call button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

Converzo Click-to-Call button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuconverzo-click-to-call.php:26
actionadmin_enqueue_scriptsconverzo-click-to-call.php:27
actionadmin_initconverzo-click-to-call.php:30
actionwp_footerconverzo-click-to-call.php:33
Maintenance & Trust

Converzo Click-to-Call button Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedAug 2, 2019
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Alternatives

Converzo Click-to-Call button Alternatives

No alternatives data available yet.

Developer Profile

Converzo Click-to-Call button Developer Profile

converzo

2 plugins · 10 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Converzo Click-to-Call button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/click-to-call-button-by-converzo-nl/assets/css/wp-cta-css.css/wp-content/plugins/click-to-call-button-by-converzo-nl/assets/js/wp-cta-js.js
Script Paths
plugins/click-to-call-button-by-converzo-nl/assets/js/wp-cta-js.js
Version Parameters
click-to-call-button-by-converzo-nl/assets/css/wp-cta-css.css?ver=1.1.0

HTML / DOM Fingerprints

CSS Classes
wp-cta-buttonwp-cta-ph-circle
Data Attributes
name="wp_cta_options[phone_number]"name="wp_cta_options[button_position]"name="wp_cta_options[circle_color]"name="wp_cta_options[button_color]"name="wp_cta_options[call_wave_effect]"name="wp_cta_options[call_shake_effect]"+5 more
FAQ

Frequently Asked Questions about Converzo Click-to-Call button