
Video Call Button by Gruveo Security & Risk Analysis
wordpress.org/plugins/gruveo-call-buttonLet your website visitors call you with voice and video using the Gruveo button. No account or installs are needed for callers!
Is Video Call Button by Gruveo Safe to Use in 2026?
Generally Safe
Score 85/100Video Call Button by Gruveo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The gruveo-call-button plugin v1.3 presents a generally good security posture with some notable areas for concern. The absence of known CVEs and the plugin's limited attack surface, with no unprotected entry points identified in the static analysis, are positive indicators. Furthermore, the plugin demonstrates good practice by exclusively using prepared statements for its SQL queries and avoiding file operations and external HTTP requests, which are common vectors for vulnerabilities.
However, the static analysis reveals a significant weakness in output escaping, with only 40% of outputs being properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is not handled carefully before being displayed. The lack of nonce checks and capability checks on the identified entry points (though the number of entry points is small) is also a concern, as it could allow unauthorized actions if an attacker can trigger these functions. The absence of any taint analysis results, while potentially meaning no critical issues were found, could also suggest that the analysis was incomplete or not sufficiently deep to uncover subtle taint flows.
Overall, while the plugin benefits from a clean vulnerability history and good handling of database interactions, the insufficient output escaping and the absence of robust authorization checks on its limited entry points represent the primary security risks. Addressing these areas would significantly strengthen the plugin's security.
Key Concerns
- Low output escaping percentage
- No capability checks on entry points
- No nonce checks on entry points
Video Call Button by Gruveo Security Vulnerabilities
Video Call Button by Gruveo Code Analysis
Output Escaping
Video Call Button by Gruveo Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Video Call Button by Gruveo Maintenance & Trust
Maintenance Signals
Community Trust
Video Call Button by Gruveo Alternatives
Overtok Call Conversion
overtok
Convert inbound calls into additional actions. Connect business calls from any digital asset with an outstanding on-site visual journey that converts …
3CX Webinars
3cx-webinars
The 3CX Webinars plugin provides free Webinars functionality to website visitors through 3CX.
Click to call button
click-to-call-button
Shows a Click to Call / Call Now Button to your visitors and turns your website into a phone with call recording, voicemail and SMS.
Easy Video Call [GWE]
easy-video-call
Easy Video Call is a simple plugin for making video call easily. To display the video call option simply add this [easy-video-call] shortcode inside y …
Sequel
sequel
Turn your WordPress website into a virtual or hybrid live engagement platform, powered by Sequel.io
Video Call Button by Gruveo Developer Profile
1 plugin · 10 total installs
How We Detect Video Call Button by Gruveo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gruveo-call-button/css/admin.cssHTML / DOM Fingerprints
[gruveo-button handle='handle_value' size='size_value' type='type_value' language='language_value']