Connect-EZ Click-To-Call Security & Risk Analysis

wordpress.org/plugins/connect-ez-click-to-call

Make phone calls directly from your website!

30 active installs v1.1.0 PHP 5.2.4+ WP 3.1+ Updated Dec 3, 2025
bpotoll-free-callsvoipwebphonewebrtc
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Connect-EZ Click-To-Call Safe to Use in 2026?

Generally Safe

Score 100/100

Connect-EZ Click-To-Call has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The 'connect-ez-click-to-call' v1.1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and the fact that all SQL queries utilize prepared statements are positive indicators. Furthermore, the plugin demonstrates good output escaping practices, with only a small percentage of outputs not being properly sanitized. The presence of nonces and capability checks on the identified entry points is also a commendable security measure, significantly reducing the risk of unauthorized actions.

However, there are a few areas that warrant attention. The plugin performs one file operation and one external HTTP request, which, while not inherently vulnerable, represent potential attack vectors if not handled with extreme care and proper sanitization. The lack of taint analysis results is also a missed opportunity to uncover potential hidden vulnerabilities. While the total and unprotected entry points are low, and no critical or high-severity issues were flagged in the static analysis, the overall assessment leans towards good, but not perfect, security.

In conclusion, the plugin is relatively secure, primarily due to its adherence to common security best practices like prepared statements and output escaping, and a clean vulnerability history. The developer has implemented basic security controls. The main areas for improvement would be more thorough taint analysis and careful consideration of the security implications of file operations and external HTTP requests, especially in future updates.

Key Concerns

  • One file operation without specific security context
  • One external HTTP request without specific security context
  • No taint analysis performed
Vulnerabilities
None known

Connect-EZ Click-To-Call Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Connect-EZ Click-To-Call Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
35 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

97% escaped36 total outputs
Attack Surface

Connect-EZ Click-To-Call Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 2

authwp_ajax_get_sip_credentialssecure-form.php:81
noprivwp_ajax_get_sip_credentialssecure-form.php:82

Shortcodes 2

[connect-ez-call-center] connect-ez-wp.php:239
[connect-ez-wp-form] connect-ez-wp.php:240
WordPress Hooks 7
actionadmin_noticesconnect-ez-setup-wizard\step1.php:43
actionwp_enqueue_scriptsconnect-ez-wp.php:11
actionadmin_menuconnect-ez-wp.php:44
actioncurrent_screenconnect-ez-wp.php:61
actionadmin_initconnect-ez-wp.php:150
actionadmin_menuconnect-ez-wp.php:250
actionadmin_initconnect-ez-wp.php:290
Maintenance & Trust

Connect-EZ Click-To-Call Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version5.2.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Connect-EZ Click-To-Call Developer Profile

Connect-EZ

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Connect-EZ Click-To-Call

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/connect-ez-click-to-call/css/style.css/wp-content/plugins/connect-ez-click-to-call/js/SIPml-api.min.js/wp-content/plugins/connect-ez-click-to-call/js/sip_script.js/wp-content/plugins/connect-ez-click-to-call/css/connect-ez-wizard.css/wp-content/plugins/connect-ez-click-to-call/js/connect_ez.js
Script Paths
https://cdn.jsdelivr.net/npm/webrtc-adapter@9.0.1/out/adapter.min.js/wp-content/plugins/connect-ez-click-to-call/js/SIPml-api.min.js/wp-content/plugins/connect-ez-click-to-call/js/sip_script.js/wp-content/plugins/connect-ez-click-to-call/js/connect_ez.js
Version Parameters
connect-ez-click-to-call/css/style.css?ver=connect-ez-click-to-call/js/SIPml-api.min.js?ver=connect-ez-click-to-call/js/sip_script.js?ver=connect-ez-click-to-call/css/connect-ez-wizard.css?ver=connect-ez-click-to-call/js/connect_ez.js?ver=

HTML / DOM Fingerprints

CSS Classes
connect-ez-container
HTML Comments
<!-- Audios -->
Data Attributes
data-realmdata-display-typedata-display-namedata-websocket-proxy-urldata-ice-serversdata-username+6 more
JS Globals
realmdisplay_typedisplay_namewebsocket_proxy_urlice_serverssipAjax+4 more
Shortcode Output
<!-- Audios --> <audio id="audio_remote" autoplay="autoplay"></audio> <audio id="ringtone" loop="" src="<!--username-->
FAQ

Frequently Asked Questions about Connect-EZ Click-To-Call