EchBay Phonering Alo Security & Risk Analysis

wordpress.org/plugins/echbay-phonering-alo

Add Phonering Alo button to your website. A very simple yet very effective plugin that adds a Call Now button to your website for every device (mobile …

1K active installs v1.3.1 PHP + WP 4.8+ Updated Nov 28, 2025
callcontactcustomersphoneringsales
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EchBay Phonering Alo Safe to Use in 2026?

Generally Safe

Score 100/100

EchBay Phonering Alo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The echbay-phonering-alo v1.3.1 plugin exhibits a mixed security posture. On one hand, the static analysis reveals a remarkably small attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication or permission checks. Furthermore, there are no identified dangerous functions, external HTTP requests, or taint analysis findings, which are strong indicators of good development practices concerning direct code execution and data manipulation risks.

However, significant concerns arise from the handling of SQL queries and output escaping. All SQL queries are performed without prepared statements, leaving them vulnerable to SQL injection attacks. Additionally, a substantial portion of output (80%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output. The presence of file operations without further context also warrants caution, though no specific risks were flagged in the static analysis.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive sign, suggesting a lack of previously discovered vulnerabilities. However, the absence of past vulnerabilities does not guarantee future security, especially given the identified risks in SQL handling and output escaping. In conclusion, while the plugin demonstrates strengths in limiting its attack surface and avoiding known dangerous code patterns, the unaddressed SQL injection and XSS risks represent critical weaknesses that require immediate attention.

Key Concerns

  • Raw SQL queries without prepared statements
  • Significant unescaped output (80%)
Vulnerabilities
None known

EchBay Phonering Alo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

EchBay Phonering Alo Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
40
10 escaped
Nonce Checks
1
Capability Checks
1
File Operations
13
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

20% escaped50 total outputs
Attack Surface

EchBay Phonering Alo Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuepa-old.php:456
actionwp_footerepa-old.php:462
actionadmin_menuepa.php:132
actionadmin_initepa.php:133
actionwp_footerepa.php:235
Maintenance & Trust

EchBay Phonering Alo Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version
Downloads26K

Community Trust

Rating100/100
Number of ratings1
Active installs1K
Developer Profile

EchBay Phonering Alo Developer Profile

Dao Quoc Dai

8 plugins · 2K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect EchBay Phonering Alo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/echbay-phonering-alo/assets/css/styles.css/wp-content/plugins/echbay-phonering-alo/assets/js/scripts.js
Version Parameters
echbay-phonering-alo/assets/css/styles.css?v=echbay-phonering-alo/assets/js/scripts.js?v=

HTML / DOM Fingerprints

CSS Classes
epa-callnow-block
HTML Comments
<!-- EchBay Phonering Alo --><!-- END EchBay Phonering Alo -->
Data Attributes
data-phone_numberdata-header_bgdata-custom_icondata-html_templatedata-mobile_griddata-email_address+11 more
JS Globals
EPA_Actions_ModuleEPA_DF_VERSIONEPA_THIS_PLUGIN_NAME
FAQ

Frequently Asked Questions about EchBay Phonering Alo