CSH Callback Security & Risk Analysis

wordpress.org/plugins/csh-callback

Add a callback request form to wordpress site

10 active installs v1.0.0 PHP + WP 3.0.1+ Updated Mar 27, 2018
admin-interfacecallbackoptionsrequesttheme-options
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CSH Callback Safe to Use in 2026?

Generally Safe

Score 85/100

CSH Callback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The csh-callback plugin v1.0.0 presents a significant security risk due to a large number of unprotected entry points. All five AJAX handlers lack authentication checks, meaning any authenticated user, regardless of their role or permissions, could potentially trigger these functions. This creates a broad attack surface for privilege escalation or unauthorized actions. Furthermore, the use of the `create_function` PHP function is a deprecated and potentially dangerous practice that can lead to code injection vulnerabilities if not handled with extreme care. While the plugin demonstrates good practice by using prepared statements for all its SQL queries and has no recorded vulnerabilities or CVEs, these positive aspects are overshadowed by the critical lack of security on its primary interaction points. The absence of taint analysis results might suggest no exploitable flows were found in the limited scope, but it also means the analysis might not be exhaustive. The plugin's current version has a concerningly low percentage of properly escaped output, increasing the risk of cross-site scripting (XSS) vulnerabilities.

Key Concerns

  • Unprotected AJAX handlers
  • Use of create_function (dangerous function)
  • Low percentage of properly escaped output
  • Zero nonce checks
  • Zero capability checks
Vulnerabilities
None known

CSH Callback Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

CSH Callback Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

CSH Callback Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
5 prepared
Unescaped Output
62
34 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'return register_widget("Cshcb_Widget_Callback");'));includes/widget-callback.php:5

SQL Query Safety

100% prepared5 total queries

Output Escaping

35% escaped96 total outputs
Attack Surface
5 unprotected

CSH Callback Attack Surface

Entry Points6
Unprotected5

AJAX Handlers 5

authwp_ajax_delete_callbackadmin/class-csh-callback-admin.php:47
authwp_ajax_change_to_calledadmin/class-csh-callback-admin.php:48
authwp_ajax_change_to_notcalladmin/class-csh-callback-admin.php:49
authwp_ajax_cshcb_submitpublic/class-csh-callback-public.php:43
noprivwp_ajax_cshcb_submitpublic/class-csh-callback-public.php:44

Shortcodes 1

[csh_callback] public/class-csh-callback-public.php:50
WordPress Hooks 10
actionadmin_enqueue_scriptsadmin/class-csh-callback-admin.php:39
actionadmin_enqueue_scriptsadmin/class-csh-callback-admin.php:40
filteradmin_initadmin/class-csh-callback-admin.php:42
actionadmin_menuadmin/class-csh-callback-admin.php:45
actionplugins_loadedcsh-callback.php:60
actiondelete_postincludes/class-csh-callback-table-db.php:15
actionwidgets_initincludes/widget-callback.php:5
actionwp_enqueue_scriptspublic/class-csh-callback-public.php:46
actionwp_enqueue_scriptspublic/class-csh-callback-public.php:47
actionwp_footerpublic/class-csh-callback-public.php:55
Maintenance & Trust

CSH Callback Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMar 27, 2018
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

CSH Callback Developer Profile

cmssuperheroes

4 plugins · 630 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CSH Callback

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/csh-callback/assets/css/csh-callback-admin.css/wp-content/plugins/csh-callback/assets/css/fontawesome.min.css/wp-content/plugins/csh-callback/assets/js/csh-callback-admin.js
Script Paths
/wp-content/plugins/csh-callback/assets/js/csh-callback-admin.js
Version Parameters
csh-callback-admin.css?ver=fontawesome.min.css?ver=csh-callback-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
callback-wrap
Data Attributes
callback-id
REST Endpoints
/wp-json/cshcb/v1/callback
FAQ

Frequently Asked Questions about CSH Callback