Freespee Call Tracking Security & Risk Analysis
wordpress.org/plugins/freespee-call-trackingSee which visitors ended up calling you, no coding required. Automated delivery of phone call data to your Google Analytics account.
Is Freespee Call Tracking Safe to Use in 2026?
Generally Safe
Score 85/100Freespee Call Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The freespee-call-tracking plugin v1.0 exhibits a generally positive security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals indicate no dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests, all of which are strong security indicators. The use of prepared statements for any SQL queries would also be a positive sign, although none were detected in this analysis.
However, a significant concern arises from the output escaping. With one total output and 0% properly escaped, there is a high likelihood of Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is displayed without proper sanitization. The presence of a capability check is good, but its effectiveness cannot be fully determined without knowing what it protects. The lack of nonce checks, while not a direct vulnerability in itself given the limited attack surface, could become a risk if new entry points are added in future versions without them.
The vulnerability history is completely clean, with no recorded CVEs. This suggests either a well-developed and secure plugin or that it has not been a target for significant security research or exploitation. While this is reassuring, it's important to remember that a clean history doesn't guarantee future security, especially when combined with potential weaknesses like the unescaped output.
Key Concerns
- Unescaped output detected
Freespee Call Tracking Security Vulnerabilities
Freespee Call Tracking Release Timeline
Freespee Call Tracking Code Analysis
Output Escaping
Freespee Call Tracking Attack Surface
WordPress Hooks 5
Maintenance & Trust
Freespee Call Tracking Maintenance & Trust
Maintenance Signals
Community Trust
Freespee Call Tracking Alternatives
CallRail Phone Call Tracking
callrail-phone-call-tracking
Dynamically swap CallRail tracking phone numbers based on the visitor's referring source.
Tracking Script Manager
tracking-script-manager
Easy tag management. Manage the tracking tags, codes and scripts you use in your WordPress site; easily add, update, reorder, delete, as required.
Nimbata Call Tracking
nimbata-call-tracking
Dynamically swap your site's phone number with a nimbata tracking numbers. Track which sources generate phone leads to your business.
Technoscore Google Tracking
technoscore-google-tracking
Technoscore Google Tracking is best Google Analytics plugin for WordPress. See how visitors find and use your website, so you can keep them coming ba …
AI Powered Marketing
kliken-marketing-for-google
Kliken's all-in-one marketing helps businesses reach high-intent customers, beat the competition and see sales growth while lowering conversion costs
Freespee Call Tracking Developer Profile
1 plugin · 10 total installs
How We Detect Freespee Call Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/freespee-call-tracking/templates/fs_conf_js.php/wp-content/plugins/freespee-call-tracking/templates/notify_banner.php/wp-content/plugins/freespee-call-tracking/templates/settings.php//analytics.freespee.com/js/external/fs.js