
Click-to-Call for Twilio Security & Risk Analysis
wordpress.org/plugins/click-to-call-for-twilioThis Twilio plugin enables your website visitors to enter their mobile numbers and to be directed instantly to your Twilio endpoint numbers using voic …
Is Click-to-Call for Twilio Safe to Use in 2026?
Generally Safe
Score 85/100Click-to-Call for Twilio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "click-to-call-for-twilio" plugin v1.0.0 exhibits a generally good security posture based on the static analysis provided. It shows a strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and performing nonce checks on its entry points. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. The taint analysis also yielded no critical or high severity unsanitized flows, indicating a low risk of common injection vulnerabilities.
However, there are areas for improvement. The plugin lacks capability checks on its entry points. While the current attack surface is small and all are protected by nonces, the absence of capability checks means that *any logged-in user* could potentially interact with these AJAX actions, even if they aren't intended to. Furthermore, while 73% of output is properly escaped, the remaining 27% represents a potential risk for cross-site scripting (XSS) vulnerabilities if sensitive data is outputted without proper sanitization. The complete lack of recorded vulnerabilities in its history is a positive sign, suggesting the developers have historically prioritized security or the plugin has not been a target. Overall, this version is relatively secure, but the missing capability checks and potential for unescaped output are the primary areas of concern.
Key Concerns
- Missing capability checks on entry points
- Unescaped output present (27%)
Click-to-Call for Twilio Security Vulnerabilities
Click-to-Call for Twilio Release Timeline
Click-to-Call for Twilio Code Analysis
Output Escaping
Data Flow Analysis
Click-to-Call for Twilio Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Click-to-Call for Twilio Maintenance & Trust
Maintenance Signals
Community Trust
Click-to-Call for Twilio Alternatives
Easy Caller with Mocean
easy-caller-with-moceanapi
Easy Caller uses Mocean Voice API to connect calls with you and your customers both easily and efficiently.
Excitel – Click to call
excitel-click-to-call
Excitel helps your customers make calls from your site over Internet (free) using WebRTC, RTMP and SIP protocols.
Toky Click To Call
toky-click-to-call
Add a call button to your website to let your visitors and customers call you with a single click without leaving their browsers
WP Call Me
wp-call-me
Take calls from your website with an easy to install click to call button.
Called.in Click To Call Plugin
wp-click-to-call-calledin
Called Click to call plugin allows you to easily issue a clickToCall service between two phone numbers.
Click-to-Call for Twilio Developer Profile
1 plugin · 40 total installs
How We Detect Click-to-Call for Twilio
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/click-to-call-for-twilio/css/admin.css/wp-content/plugins/click-to-call-for-twilio/js/admin.js/wp-content/plugins/click-to-call-for-twilio/css/frontend.css/wp-content/plugins/click-to-call-for-twilio/css/intlTelInput.css/wp-content/plugins/click-to-call-for-twilio/js/intlTelInput.min.js/wp-content/plugins/click-to-call-for-twilio/js/utils.js/wp-content/plugins/click-to-call-for-twilio/js/twt-script.js/wp-content/plugins/click-to-call-for-twilio/js/admin.js/wp-content/plugins/click-to-call-for-twilio/js/intlTelInput.min.js/wp-content/plugins/click-to-call-for-twilio/js/utils.js/wp-content/plugins/click-to-call-for-twilio/js/twt-script.jsHTML / DOM Fingerprints
twt_settingstwt-tab-bartwt-tab-activetwt-tab-paneldata-tabajax_urlcountries