
Focus SiteCall Lite Security & Risk Analysis
wordpress.org/plugins/focus-sitecall-liteSiteCall Lite is a simple widget for a callback on your website
Is Focus SiteCall Lite Safe to Use in 2026?
Generally Safe
Score 85/100Focus SiteCall Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "focus-sitecall-lite" plugin v1.0.1 presents a moderate security risk, primarily due to its unprotected entry points and concerning output sanitization practices. While the plugin demonstrates good practices in avoiding dangerous functions, raw SQL queries, and external HTTP requests, the presence of two AJAX handlers lacking authentication checks creates a significant attack surface. This means any user, even an unauthenticated one, could potentially interact with these handlers, leading to unintended consequences or further exploitation if vulnerabilities exist within them.
The taint analysis, while not revealing critical or high severity issues, did find all analyzed flows with unsanitized paths. This, combined with only 46% of output escaping being properly done, suggests a high probability of cross-site scripting (XSS) vulnerabilities. The plugin also fails to implement any nonce or capability checks, further exacerbating the risk associated with the unprotected AJAX handlers.
Fortunately, the plugin has no recorded vulnerability history, which is a positive sign. However, this could be due to a lack of thorough security auditing or simply good fortune. The absence of past vulnerabilities should not be seen as a guarantee of future safety, especially given the identified code-level weaknesses. The overall security posture is therefore a mixed bag; strengths in certain areas are overshadowed by critical oversights in input validation and output escaping, making it a target for attackers looking for easy entry points.
Key Concerns
- Unprotected AJAX handlers
- All analyzed flows have unsanitized paths
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Focus SiteCall Lite Security Vulnerabilities
Focus SiteCall Lite Code Analysis
Output Escaping
Data Flow Analysis
Focus SiteCall Lite Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
Focus SiteCall Lite Maintenance & Trust
Maintenance Signals
Community Trust
Focus SiteCall Lite Alternatives
Focus SiteCall Pro
focus-sitecall-pro
SiteCall Pro is a simple widget for a callback on your website.
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce
cartflows
1 WordPress funnel builder & WooCommerce checkout plugin. Boost AOV with one-click upsells, order bumps & high-converting checkout pages.
Brave Popup Builder – Popup, Optins, Lead Generation, Survey & Interactive Content
brave-popup-builder
The best drag-and-drop Popup Builder for WordPress. Create Popups, exit-intent popups, slide-ins, and lead generation forms & Woocommerce popups i …
Zoho SalesIQ – Live chat, chatbots, and visitor tracking
zoho-salesiq
Identify, engage and convert website visitors with live chat and visitor analytics.
Leadpages
leadpages
Easily publish your Leadpages landing pages to your WordPress site. Promote your lead magnets, events, promotions, and more.
Focus SiteCall Lite Developer Profile
2 plugins · 0 total installs
How We Detect Focus SiteCall Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/focus-sitecall-lite/css/admin-tabs.css/wp-content/plugins/focus-sitecall-lite/css/main.css/wp-content/plugins/focus-sitecall-lite/js/admin-tabs.js/wp-content/plugins/focus-sitecall-lite/public/widget.jsfocus-sitecall-lite/style.css?ver=focus-sitecall-lite/script.js?ver=HTML / DOM Fingerprints
FocusSitecallLite_widget_dropdownname="sitecalllite_widget"FocusSiteCallLite_widget_dropdownFocusSitecallLite