
Connect-EZ Click-To-Call Security & Risk Analysis
wordpress.org/plugins/connect-ez-click-to-callMake phone calls directly from your website!
Is Connect-EZ Click-To-Call Safe to Use in 2026?
Generally Safe
Score 100/100Connect-EZ Click-To-Call has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'connect-ez-click-to-call' v1.1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and the fact that all SQL queries utilize prepared statements are positive indicators. Furthermore, the plugin demonstrates good output escaping practices, with only a small percentage of outputs not being properly sanitized. The presence of nonces and capability checks on the identified entry points is also a commendable security measure, significantly reducing the risk of unauthorized actions.
However, there are a few areas that warrant attention. The plugin performs one file operation and one external HTTP request, which, while not inherently vulnerable, represent potential attack vectors if not handled with extreme care and proper sanitization. The lack of taint analysis results is also a missed opportunity to uncover potential hidden vulnerabilities. While the total and unprotected entry points are low, and no critical or high-severity issues were flagged in the static analysis, the overall assessment leans towards good, but not perfect, security.
In conclusion, the plugin is relatively secure, primarily due to its adherence to common security best practices like prepared statements and output escaping, and a clean vulnerability history. The developer has implemented basic security controls. The main areas for improvement would be more thorough taint analysis and careful consideration of the security implications of file operations and external HTTP requests, especially in future updates.
Key Concerns
- One file operation without specific security context
- One external HTTP request without specific security context
- No taint analysis performed
Connect-EZ Click-To-Call Security Vulnerabilities
Connect-EZ Click-To-Call Code Analysis
Output Escaping
Connect-EZ Click-To-Call Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 7
Maintenance & Trust
Connect-EZ Click-To-Call Maintenance & Trust
Maintenance Signals
Community Trust
Connect-EZ Click-To-Call Alternatives
TeleFinity WebRTC to SIP Gateway
telefinity-webrtc-sip-gateway
Turns your website into a phone and let your abroad customers connect to your PBX /Call Center directly at zero-cost and without a telecom operator.
Structured Content (JSON-LD) #wpsc
structured-content
Add flexible content boxes with JSON-LD microdata output according to schema.org e.g. FAQPage, ProfilePage, Event, Course, LocalBusiness, JobPosting a …
bpost shipping
bpost-shipping
This plugin allows customers to choose their preferred Belgian bpost delivery method when ordering in your Woocommerce webshop.
WebPOS – Point of Sale for WooCommerce
webpos-point-of-sale-for-woocommerce
Powerful POS with user-friendly front-end interface for physical stores. Sync orders, inventory, and details seamlessly with your online store
LiveSmart Video Chat Live Video Chat
new-dev-livesmart-video-chat
LiveSmart Video Chat Live Video chat plugin for WordPress that allows visitors to establish live video chat in the browser without download.
Connect-EZ Click-To-Call Developer Profile
1 plugin · 30 total installs
How We Detect Connect-EZ Click-To-Call
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/connect-ez-click-to-call/css/style.css/wp-content/plugins/connect-ez-click-to-call/js/SIPml-api.min.js/wp-content/plugins/connect-ez-click-to-call/js/sip_script.js/wp-content/plugins/connect-ez-click-to-call/css/connect-ez-wizard.css/wp-content/plugins/connect-ez-click-to-call/js/connect_ez.jshttps://cdn.jsdelivr.net/npm/webrtc-adapter@9.0.1/out/adapter.min.js/wp-content/plugins/connect-ez-click-to-call/js/SIPml-api.min.js/wp-content/plugins/connect-ez-click-to-call/js/sip_script.js/wp-content/plugins/connect-ez-click-to-call/js/connect_ez.jsconnect-ez-click-to-call/css/style.css?ver=connect-ez-click-to-call/js/SIPml-api.min.js?ver=connect-ez-click-to-call/js/sip_script.js?ver=connect-ez-click-to-call/css/connect-ez-wizard.css?ver=connect-ez-click-to-call/js/connect_ez.js?ver=HTML / DOM Fingerprints
connect-ez-container<!-- Audios -->data-realmdata-display-typedata-display-namedata-websocket-proxy-urldata-ice-serversdata-username+6 morerealmdisplay_typedisplay_namewebsocket_proxy_urlice_serverssipAjax+4 more<!-- Audios -->
<audio id="audio_remote" autoplay="autoplay"></audio>
<audio id="ringtone" loop="" src="<!--username-->