
Excitel – Click to call Security & Risk Analysis
wordpress.org/plugins/excitel-click-to-callExcitel helps your customers make calls from your site over Internet (free) using WebRTC, RTMP and SIP protocols.
Is Excitel – Click to call Safe to Use in 2026?
Generally Safe
Score 85/100Excitel – Click to call has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'excitel-click-to-call' plugin v1.5 demonstrates a mixed security posture. While it boasts zero known CVEs and a seemingly small attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication, there are significant concerns regarding its output sanitization and data handling. The analysis reveals that 100% of its outputs are not properly escaped, which is a critical weakness that could lead to Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis shows two flows with unsanitized paths, indicating potential avenues for data manipulation or injection, although currently without a critical or high severity rating. The plugin also makes an external HTTP request, the nature and security of which are not detailed here, but such requests can introduce risks if not handled carefully. Despite the lack of historical vulnerabilities and a low number of SQL queries, the unescaped output and unsanitized data flows are major red flags that cannot be overlooked. The plugin has strengths in its limited entry points and use of prepared statements for SQL, but these are overshadowed by the critical output sanitization issues. It is recommended that the plugin undergoes thorough security auditing, particularly focusing on output escaping and input validation to mitigate potential XSS and data injection risks.
Key Concerns
- All output is unescaped
- Taint flow with unsanitized paths
- External HTTP request
Excitel – Click to call Security Vulnerabilities
Excitel – Click to call Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Excitel – Click to call Attack Surface
WordPress Hooks 9
Maintenance & Trust
Excitel – Click to call Maintenance & Trust
Maintenance Signals
Community Trust
Excitel – Click to call Alternatives
WP Call Me
wp-call-me
Take calls from your website with an easy to install click to call button.
Easy Caller with Mocean
easy-caller-with-moceanapi
Easy Caller uses Mocean Voice API to connect calls with you and your customers both easily and efficiently.
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
API KEY for Google Maps
api-key-for-google-maps
Retroactively add Google Maps API KEY to any theme or plugin.
Really Simple Click To Call Bar
really-simple-click-to-call
A simple plugin that adds a click to call bar/call now button for mobile visitors.
Excitel – Click to call Developer Profile
1 plugin · 20 total installs
How We Detect Excitel – Click to call
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/excitel-click-to-call/css/voipAppWidget.cssvoipApp-admin-styles?ver=excitel-click-to-call-admin-styles?ver=excitel-click-to-call-main-styles?ver=HTML / DOM Fingerprints
window.location.hrefjQuery.post