
Converzo Click-to-Call button Security & Risk Analysis
wordpress.org/plugins/click-to-call-button-by-converzo-nlWith this plugin you add a click-to-call button to your responsive website in no-time.
Is Converzo Click-to-Call button Safe to Use in 2026?
Generally Safe
Score 85/100Converzo Click-to-Call button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the 'click-to-call-button-by-converzo-nl' plugin v1.0 reveals a remarkably clean code base with no identified attack surface through AJAX, REST API, shortcodes, or cron events. The absence of dangerous functions, file operations, external HTTP requests, and reliance on prepared statements for SQL queries are all positive security indicators. However, the complete lack of output escaping is a significant concern, suggesting that any dynamic data rendered to the user interface is not being properly sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is incorporated into the output. The vulnerability history is also empty, indicating no known public exploits or past issues, which is a good sign of responsible development.
Despite the lack of discovered vulnerabilities and a small attack surface, the critical oversight in output escaping presents a clear and present risk. While the plugin might not have exploitable entry points due to its limited functionality as indicated, the potential for XSS remains if any part of its rendering process handles user-controlled data. The absence of nonce and capability checks is noted but is less concerning given the zero attack surface; however, it indicates a lack of robust authorization practices that could become an issue if new entry points are introduced in future versions. Overall, the plugin demonstrates good practices in some areas but suffers from a critical deficiency in output sanitization.
Key Concerns
- 0% output escaping
Converzo Click-to-Call button Security Vulnerabilities
Converzo Click-to-Call button Release Timeline
Converzo Click-to-Call button Code Analysis
Output Escaping
Converzo Click-to-Call button Attack Surface
WordPress Hooks 4
Maintenance & Trust
Converzo Click-to-Call button Maintenance & Trust
Maintenance Signals
Community Trust
Converzo Click-to-Call button Alternatives
No alternatives data available yet.
Converzo Click-to-Call button Developer Profile
2 plugins · 10 total installs
How We Detect Converzo Click-to-Call button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/click-to-call-button-by-converzo-nl/assets/css/wp-cta-css.css/wp-content/plugins/click-to-call-button-by-converzo-nl/assets/js/wp-cta-js.jsplugins/click-to-call-button-by-converzo-nl/assets/js/wp-cta-js.jsclick-to-call-button-by-converzo-nl/assets/css/wp-cta-css.css?ver=1.1.0HTML / DOM Fingerprints
wp-cta-buttonwp-cta-ph-circlename="wp_cta_options[phone_number]"name="wp_cta_options[button_position]"name="wp_cta_options[circle_color]"name="wp_cta_options[button_color]"name="wp_cta_options[call_wave_effect]"name="wp_cta_options[call_shake_effect]"+5 more