Click to Call or Chat Buttons Security & Risk Analysis

wordpress.org/plugins/click-to-call-or-chat-buttons

This plugin adds Phone Call and WhatsApp button on your webpage.

1K active installs v1.6.0 PHP 7.0+ WP 5.2+ Updated Feb 6, 2025
call-now-buttoncall-us-buttonclick-to-call-chatcontact-bottom-buttonphone-whatsapp-button
92
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 15, 2023
Safety Verdict

Is Click to Call or Chat Buttons Safe to Use in 2026?

Generally Safe

Score 92/100

Click to Call or Chat Buttons has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Feb 15, 2023Updated 1yr ago
Risk Assessment

The "click-to-call-or-chat-buttons" plugin, version 1.6.0, exhibits a generally positive security posture based on the static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is a significant strength. Furthermore, the plugin appears to have no identified attack surface through AJAX, REST API, shortcodes, or cron events, indicating a well-contained design. However, the static analysis does reveal a concern regarding output escaping, with only 5% of outputs being properly escaped. This suggests a potential for cross-site scripting (XSS) vulnerabilities, especially if any user-supplied data is rendered without adequate sanitization.

Key Concerns

  • Low percentage of properly escaped output
  • No capability checks detected
  • No nonce checks detected
Vulnerabilities
1 published

Click to Call or Chat Buttons Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-25710medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Click to Call or Chat Buttons <= 1.4.0 - Authenticated(Admin+) Stored Cross-Site Scripting

Feb 15, 2023 Patched in 1.5.0 (342d)
Version History

Click to Call or Chat Buttons Release Timeline

v1.7.0
v1.6.0Current
v1.5.0
v1.4.01 CVE
v1.3.01 CVE
v1.2.01 CVE
v1.1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Click to Call or Chat Buttons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
35
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

5% escaped37 total outputs
Attack Surface

Click to Call or Chat Buttons Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwp_enqueue_scriptsctcocb.php:37
actionadmin_menuctcocb.php:38
actionadmin_initctcocb.php:39
filterplugin_row_metactcocb.php:40
actionadmin_enqueue_scriptsctcocb.php:43
actionwp_headctcocb.php:469
actionwp_footerctcocb.php:470
Maintenance & Trust

Click to Call or Chat Buttons Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 6, 2025
PHP min version7.0
Downloads14K

Community Trust

Rating74/100
Number of ratings3
Active installs1K
Developer Profile

Click to Call or Chat Buttons Developer Profile

digitalblue

1 plugin · 1K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
342 days
View full developer profile
Detection Fingerprints

How We Detect Click to Call or Chat Buttons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/click-to-call-or-chat-buttons/css/ctcocb-style.css/wp-content/plugins/click-to-call-or-chat-buttons/js/ctcocb-script.js/wp-content/plugins/click-to-call-or-chat-buttons/js/ctcocb-admin.js
Script Paths
/wp-content/plugins/click-to-call-or-chat-buttons/js/ctcocb-script.js/wp-content/plugins/click-to-call-or-chat-buttons/js/ctcocb-admin.js
Version Parameters
click-to-call-or-chat-buttons/css/ctcocb-style.css?ver=click-to-call-or-chat-buttons/js/ctcocb-script.js?ver=click-to-call-or-chat-buttons/js/ctcocb-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
ctcocb-color-fieldctcocb-container
HTML Comments
<!-- Require Phone icon color to be set -->
Data Attributes
name="ctcocb[activePlugin]"name="ctcocb[numberPhone]"name="ctcocb[textPhone]"name="ctcocb[numberWapp]"name="ctcocb[textWapp]"name="ctcocb[text]"+14 more
JS Globals
ctcocb_options
FAQ

Frequently Asked Questions about Click to Call or Chat Buttons