
CSH Callback Security & Risk Analysis
wordpress.org/plugins/csh-callbackAdd a callback request form to wordpress site
Is CSH Callback Safe to Use in 2026?
Generally Safe
Score 85/100CSH Callback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The csh-callback plugin v1.0.0 presents a significant security risk due to a large number of unprotected entry points. All five AJAX handlers lack authentication checks, meaning any authenticated user, regardless of their role or permissions, could potentially trigger these functions. This creates a broad attack surface for privilege escalation or unauthorized actions. Furthermore, the use of the `create_function` PHP function is a deprecated and potentially dangerous practice that can lead to code injection vulnerabilities if not handled with extreme care. While the plugin demonstrates good practice by using prepared statements for all its SQL queries and has no recorded vulnerabilities or CVEs, these positive aspects are overshadowed by the critical lack of security on its primary interaction points. The absence of taint analysis results might suggest no exploitable flows were found in the limited scope, but it also means the analysis might not be exhaustive. The plugin's current version has a concerningly low percentage of properly escaped output, increasing the risk of cross-site scripting (XSS) vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- Use of create_function (dangerous function)
- Low percentage of properly escaped output
- Zero nonce checks
- Zero capability checks
CSH Callback Security Vulnerabilities
CSH Callback Release Timeline
CSH Callback Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
CSH Callback Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
CSH Callback Maintenance & Trust
Maintenance Signals
Community Trust
CSH Callback Alternatives
CSH Login
csh-login
Modal login form with redirect and styling options.
CSH Multiscroll
csh-multiscroll
Add a multiscroll slide to wordpress site
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
OptionTree
option-tree
Theme Options UI Builder for WordPress. A simple way to create & save Theme Options and Meta Boxes for free or premium themes.
CSH Callback Developer Profile
4 plugins · 630 total installs
How We Detect CSH Callback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/csh-callback/assets/css/csh-callback-admin.css/wp-content/plugins/csh-callback/assets/css/fontawesome.min.css/wp-content/plugins/csh-callback/assets/js/csh-callback-admin.js/wp-content/plugins/csh-callback/assets/js/csh-callback-admin.jscsh-callback-admin.css?ver=fontawesome.min.css?ver=csh-callback-admin.js?ver=HTML / DOM Fingerprints
callback-wrapcallback-id/wp-json/cshcb/v1/callback