
OrbitCarrot CTA Widget Manager Security & Risk Analysis
wordpress.org/plugins/cta-widget-managerThe easiest way to create Call to Actions as widgets on your Wordpress site. Customize your own CTA style or use pre-designed ones.
Is OrbitCarrot CTA Widget Manager Safe to Use in 2026?
Generally Safe
Score 85/100OrbitCarrot CTA Widget Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cta-widget-manager" plugin v1.1 exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs, critical taint flows, and dangerous functions is a strong positive indicator. The plugin also correctly utilizes prepared statements for its SQL queries and avoids external HTTP requests and file operations, which are common sources of vulnerabilities.
However, a significant concern arises from the low percentage of properly escaped output (14%). This suggests that user-supplied data or data processed by the plugin might be directly outputted into the HTML without sufficient sanitization, potentially leading to Cross-Site Scripting (XSS) vulnerabilities if user input is not properly handled elsewhere. The lack of any capability checks or nonce checks on the identified entry points, while the attack surface is reported as zero, is also noteworthy. If any entry points were to be introduced in future versions or if the reported zero is an oversight, the absence of these fundamental security checks would be a critical flaw.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices in SQL handling and external interactions, the unescaped output is a notable weakness that requires attention. The absence of nonce and capability checks, even with a zero attack surface currently, points to a potential area of risk if the plugin's functionality evolves. Addressing the output escaping issue should be the primary focus for improving the plugin's security.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks on entry points
- Missing capability checks on entry points
OrbitCarrot CTA Widget Manager Security Vulnerabilities
OrbitCarrot CTA Widget Manager Code Analysis
Output Escaping
OrbitCarrot CTA Widget Manager Attack Surface
WordPress Hooks 2
Maintenance & Trust
OrbitCarrot CTA Widget Manager Maintenance & Trust
Maintenance Signals
Community Trust
OrbitCarrot CTA Widget Manager Alternatives
Mobile Contact Bar
mobile-contact-bar
Allow your visitors to contact you via mobile phones, or access your site's pages instantly.
Call to Action Block by WPPOOL
call-to-action-block-wppool
Add a stunning call to action (CTA) block to your WordPress post or page using 10+ prebuilt call to action layouts for Gutenberg.
CTA Button Styler
cta-button-styler
Increase engagement with reusable CTA buttons, styled your way with hover effects and optional animations. Clean and efficient.
Button Widget
button-widget
A simple customizable button widget for your sidebars.
Call to Action Widget
call-to-action-widget
A simple text widget with Title, Image URL, A text/html area, Link Text and Link URL. This simple widget is often used for a call to action widget.
OrbitCarrot CTA Widget Manager Developer Profile
1 plugin · 10 total installs
How We Detect OrbitCarrot CTA Widget Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cta-widget-manager/css/styles.csscta-widget-manager/css/styles.css?ver=HTML / DOM Fingerprints
ctatitlectatext/* Are you sure you want to be in here? Do you have magic developer powers? If not move along... */WIDGET CTA CODEid="cta"id="red"id="blue"id="green"id="purple"id="royalred"+1 more