Floating Click to Contact Buttons Security & Risk Analysis

wordpress.org/plugins/floating-click-to-contact-buttons

Tạo các nút gọi, nút chat Zalo, nút Chat messenger, nút để lại thông tin để tư vấn, nút chỉ đường. Trình bày các nút đẹp mắt ở góc phải dưới màn hình, …

2K active installs v1.0 PHP + WP 3.5+ Updated Jan 10, 2020
call-buttoncall-now-buttoncall-to-actionclick-to-callquick-call-button
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Floating Click to Contact Buttons Safe to Use in 2026?

Generally Safe

Score 85/100

Floating Click to Contact Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of the 'floating-click-to-contact-buttons' plugin v1.0 reveals a generally positive security posture, with no apparent direct vulnerabilities detected in the provided data. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, and the fact that all identified entry points are protected is a strong indicator of good development practices. Furthermore, the complete absence of dangerous functions, file operations, and external HTTP requests, coupled with the use of prepared statements for all SQL queries, are excellent security measures. However, a weakness lies in the output escaping, where 26% of outputs are not properly escaped, presenting a potential risk for cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in these unescaped outputs. The plugin's vulnerability history is also clean, with no recorded CVEs, which suggests a history of secure development or a lack of targeted attacks. Overall, while the plugin demonstrates strong foundational security, the unescaped output warrants attention.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Floating Click to Contact Buttons Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Floating Click to Contact Buttons Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
23 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

74% escaped31 total outputs
Attack Surface

Floating Click to Contact Buttons Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menufloating-click-to-contact-buttons.php:13
actionadmin_initfloating-click-to-contact-buttons.php:97
actiontemplate_redirectfloating-click-to-contact-buttons.php:145
actionwp_footerfloating-click-to-contact-buttons.php:151
actiontemplate_redirectfloating-click-to-contact-buttons.php:181
actionwp_footerfloating-click-to-contact-buttons.php:184
actiontemplate_redirectfloating-click-to-contact-buttons.php:193
actionwp_footerfloating-click-to-contact-buttons.php:202
actiontemplate_redirectfloating-click-to-contact-buttons.php:248
actionwp_footerfloating-click-to-contact-buttons.php:256
Maintenance & Trust

Floating Click to Contact Buttons Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedJan 10, 2020
PHP min version
Downloads34K

Community Trust

Rating86/100
Number of ratings4
Active installs2K
Developer Profile

Floating Click to Contact Buttons Developer Profile

nhan772000

1 plugin · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Floating Click to Contact Buttons

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/floating-click-to-contact-buttons/css/callNow.css/wp-content/plugins/floating-click-to-contact-buttons/css/style.css
Script Paths
/wp-content/plugins/floating-click-to-contact-buttons/main.js
Version Parameters
floating-click-to-contact-buttons/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
hotline-phone-ring-wraphotline-phone-ringhotline-phone-ring-circlehotline-phone-ring-circle-fillhotline-phone-ring-img-circlepps-btn-imghotline-bartext-hotline+5 more
HTML Comments
<!-- Fab Buttons -->
Data Attributes
onclickdata-targetdata-toggledata-textdata-icondata-color+1 more
JS Globals
window.location.href
Shortcode Output
<div onclick="window.location.href= 'tel:'<a href="tel:<span class="text-hotline"><div class="inner-fabs">
FAQ

Frequently Asked Questions about Floating Click to Contact Buttons