
CTCL Phone Pay Security & Risk Analysis
wordpress.org/plugins/ctcl-phone-payCTC Lite add-on to charge customer with phone call
Is CTCL Phone Pay Safe to Use in 2026?
Generally Safe
Score 100/100CTCL Phone Pay has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ctcl-phone-pay" v1.1.0 plugin exhibits a concerning security posture due to significant weaknesses in its access control mechanisms. The static analysis reveals an attack surface primarily composed of two AJAX handlers, both of which lack any authentication checks. This means that any unauthenticated user can trigger these actions, presenting a direct pathway for exploitation.
While the plugin doesn't have a history of publicly disclosed vulnerabilities (CVEs), this is likely a false sense of security given the readily apparent flaws in its code. The absence of capability checks, nonce checks, and the use of SQL queries without prepared statements further exacerbate the risks. Although no critical taint flows were identified, the unescaped output on 17% of outputs indicates a potential for Cross-Site Scripting (XSS) vulnerabilities. The lack of prepared statements for the single SQL query also points towards a SQL injection risk.
In conclusion, despite the clean vulnerability history, the "ctcl-phone-pay" plugin has critical security deficiencies, particularly in its unprotected AJAX endpoints and the absence of robust input validation and sanitization. These issues create a high risk of unauthorized actions, data manipulation, and potential XSS attacks, outweighing the positive aspects of a clean vulnerability history.
Key Concerns
- AJAX handlers without auth checks
- SQL queries without prepared statements
- Unescaped output
- No nonce checks
- No capability checks
CTCL Phone Pay Security Vulnerabilities
CTCL Phone Pay Code Analysis
SQL Query Safety
Output Escaping
CTCL Phone Pay Attack Surface
AJAX Handlers 2
WordPress Hooks 9
Maintenance & Trust
CTCL Phone Pay Maintenance & Trust
Maintenance Signals
Community Trust
CTCL Phone Pay Alternatives
CTCL Floating Cart
ctcl-floating-cart
🚀 Floating Cart for CT Commerce Lite 🛒
CTCL Analytics
ctcl-analytics
CT Commerce Lite addon to display store analytics
WooCommerce
woocommerce
Everything you need to launch an online store in days and keep it growing for years. From your first sale to millions in revenue, Woo is with you.
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation
optinmonster
🤩 Make popups & optin forms to get more email newsletter subscribers, leads, and sales - #1 most popular popup builder plugin! 🚀
WooCommerce PayPal Payments
woocommerce-paypal-payments
PayPal's latest payment processing solution. Accept PayPal, Pay Later, credit/debit cards, alternative digital wallets and bank accounts.
CTCL Phone Pay Developer Profile
17 plugins · 2K total installs
How We Detect CTCL Phone Pay
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ctcl-phone-pay/ctcl-phone-pay.phpHTML / DOM Fingerprints
ctcl-phone-pay-detailctcl-pay-phone-order-idctcl-phone-pay-rowctcl-phone-pay-button-rowctcl-pay-phone-open-detailctcl-pay-phone-mark-paidid='ctcl-pay-phone-order-id'/wp-json/ctcl/v1/phonePay