
Fonetic Web Callback Security & Risk Analysis
wordpress.org/plugins/fonetic-web-callbackFonetic is a web call feature for your website that allows your visitors to be called back for free. Get a real leverage for your online conversions !
Is Fonetic Web Callback Safe to Use in 2026?
Generally Safe
Score 85/100Fonetic Web Callback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'fonetic-web-callback' plugin v2.0.1 presents a mixed security posture. On the positive side, the plugin exhibits an extremely small attack surface with zero identified AJAX handlers, REST API routes, shortcodes, or cron events. This significantly limits the potential entry points for attackers. Furthermore, there is no known vulnerability history, suggesting a potentially stable and well-maintained codebase regarding external exploits.
However, significant concerns arise from the static code analysis. The plugin fails to use prepared statements for any of its SQL queries, exposing it to SQL injection vulnerabilities. Additionally, none of the identified output operations are properly escaped, making it susceptible to cross-site scripting (XSS) attacks. The taint analysis reveals two high-severity flows with unsanitized paths, which, combined with the lack of output escaping, strongly suggests these flows are exploitable for XSS.
While the absence of a known vulnerability history is positive, it doesn't negate the critical flaws identified in the code. The lack of prepared statements and output escaping are fundamental security weaknesses that could be easily exploited, especially given the identified taint flows. The plugin's strengths lie in its limited attack surface, but its internal code practices pose a notable risk.
Key Concerns
- SQL queries without prepared statements
- Output not properly escaped
- High severity taint flows with unsanitized paths
Fonetic Web Callback Security Vulnerabilities
Fonetic Web Callback Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Fonetic Web Callback Attack Surface
WordPress Hooks 4
Maintenance & Trust
Fonetic Web Callback Maintenance & Trust
Maintenance Signals
Community Trust
Fonetic Web Callback Alternatives
Bitrix24
integration-with-bitrix24
This free Bitrix24 widget lets you insert live chat, call back request and various web forms into your website.
LeadBack – Callback, Chatbot and Live Chat Widgets for WordPress sites
leadback
This plugin makes a simple widget for callback and live chat on your website. Official LeadBack plugin.
Novocall – Callback Widget
novocall-callback-widget
Novocall is a powerful callback widget that helps increase your web conversion by prompting interested visitors with a free callback in seconds, while …
Callback widget Pozvonim
callback-widget-pozvonim
Виджет обратного звонка Pozvonim - позволяет повысить конверсию сайта
Vivocha Activation Tool
vivocha-activation-tool
Vivocha is a cloud-based service, tailored to businesses looking to engage their customers online, using chat, voice and video.
Fonetic Web Callback Developer Profile
1 plugin · 10 total installs
How We Detect Fonetic Web Callback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fonetic-web-callback/css/admin.css/wp-content/plugins/fonetic-web-callback/images/fonetic-logo-widget.png/wp-content/plugins/fonetic-web-callback/images/fonetic-menu-icon.png/wp-content/plugins/fonetic-web-callback/jscolor/jscolor.js/wp-content/plugins/fonetic-web-callback/images/webcallback.png/wp-content/plugins/fonetic-web-callback/jscolor/jscolor.jsHTML / DOM Fingerprints
fonetic_adminfonetic_enabledfonetic_short_keyfonetic_labelfonetic_colorfonetic_invertedfonetic_animated+6 morefonetic_web_callback