
Drona Call & Phone Click Analytics Security & Risk Analysis
wordpress.org/plugins/drona-call-phone-click-analyticsAutomatically tracks phone number clicks from tel: links and provides detailed analytics inside the WordPress admin dashboard.
Is Drona Call & Phone Click Analytics Safe to Use in 2026?
Generally Safe
Score 100/100Drona Call & Phone Click Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "drona-call-phone-click-analytics" plugin, v1.0.0, exhibits a generally good security posture, with no recorded vulnerabilities and strong adherence to basic security practices like output escaping, nonce checks, and capability checks on its identified entry points. The static analysis indicates all identified AJAX handlers and REST API routes (though none exist in this case) have proper authentication checks. This demonstrates a developer's awareness of common WordPress security pitfalls.
However, the taint analysis reveals one flow with an unsanitized path and a high severity. This is a significant concern as it suggests a potential for a security vulnerability, even if not yet exploited or publicly known. The presence of external HTTP requests also warrants careful review to ensure these are made securely and do not introduce further risks. While the plugin has no historical vulnerabilities, the single high-severity taint flow indicates a specific area of weakness that needs immediate attention.
In conclusion, the plugin has strong foundational security practices. The primary weakness lies in the identified high-severity taint flow, which overshadows the otherwise positive security indicators. Addressing this specific taint flow is crucial to maintaining a secure profile. The lack of historical vulnerabilities is positive, but the current taint analysis finding necessitates vigilance.
Key Concerns
- High severity taint flow with unsanitized path
- External HTTP request
Drona Call & Phone Click Analytics Security Vulnerabilities
Drona Call & Phone Click Analytics Release Timeline
Drona Call & Phone Click Analytics Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Drona Call & Phone Click Analytics Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
Drona Call & Phone Click Analytics Maintenance & Trust
Maintenance Signals
Community Trust
Drona Call & Phone Click Analytics Alternatives
Clixtell
clixtell-tracking-dynamic-phones
Clixtell Tracking & Dynamic Phones integrates Clixtell click fraud detection and dynamic phone number insertion into your WordPress site.
CallRail Phone Call Tracking
callrail-phone-call-tracking
Dynamically swap CallRail tracking phone numbers based on the visitor's referring source.
WhatConverts
whatconverts
Enables WhatConverts on all pages.
CallTrackingMetrics
call-tracking-metrics
CallTrackingMetrics integrates with your WordPress site to provide powerful call tracking and attribution.
Nimbata Call Tracking
nimbata-call-tracking
Dynamically swap your site's phone number with a nimbata tracking numbers. Track which sources generate phone leads to your business.
Drona Call & Phone Click Analytics Developer Profile
2 plugins · 20 total installs
How We Detect Drona Call & Phone Click Analytics
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/drona-call-phone-click-analytics/assets/tracker.js/wp-content/plugins/drona-call-phone-click-analytics/assets/tracker.jsdrona-call-phone-click-analytics/assets/tracker.js?ver=1.0HTML / DOM Fingerprints
pht_ajax