
HT CALL ME Security & Risk Analysis
wordpress.org/plugins/ht-call-nowThis plugin places a Call Now button (click-to-call) to the bottom of the screen which is only visible for your mobile visitors.
Is HT CALL ME Safe to Use in 2026?
Generally Safe
Score 85/100HT CALL ME has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ht-call-now" plugin version 1.0.1 demonstrates a generally good security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface. Furthermore, the code shows no critical or high severity taint flows, no direct SQL queries (all use prepared statements), and no file operations or external HTTP requests, which are positive indicators of secure coding practices. The presence of nonce checks also suggests an attempt to protect against CSRF attacks.
However, there are areas for improvement. The fact that only 59% of output is properly escaped is a concern. This means that nearly half of all output points could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved and not handled securely. While the plugin has no recorded vulnerability history, this could be due to a lack of past scrutiny or simply a coincidence. The absence of capability checks for the two identified nonce checks is another potential weakness, as it implies that any authenticated user, regardless of their role or permissions, could potentially trigger the nonce-protected actions.
In conclusion, "ht-call-now" v1.0.1 has a strong foundation with its limited attack surface and use of prepared statements. The primary risk lies in the significant portion of unescaped output, which could open the door to XSS attacks. The lack of capability checks on nonce protected actions is also a notable concern. Addressing these specific issues would significantly bolster the plugin's security.
Key Concerns
- Unescaped output detected
- No capability checks on nonce actions
HT CALL ME Security Vulnerabilities
HT CALL ME Code Analysis
Output Escaping
HT CALL ME Attack Surface
WordPress Hooks 8
Maintenance & Trust
HT CALL ME Maintenance & Trust
Maintenance Signals
Community Trust
HT CALL ME Alternatives
EchBay Phonering Alo
echbay-phonering-alo
Add Phonering Alo button to your website. A very simple yet very effective plugin that adds a Call Now button to your website for every device (mobile …
Lucep Call Now Button
lucep-call-now-button
An award winning "call now" (or click to call) widget that works on all of your pages! Proven to increase sales by over 72% and it's fr …
ATP Call Now
atp-call-now
Show button Call Now on your website (support desktop and mobile).
WP Scarcity Jeet – Powerful scarcity and urgency timer for your landing pages
scarcity-jeet
Scarcity Jeet is a very flexible and powerful timer and banner widget. You can choose between many designs and even put in your own images and e-cove …
WebRTC Softphone
webrtc-softphone
WebRTC Softphone for Sip Calling with motion animate icon at the bottom of your site.
HT CALL ME Developer Profile
1 plugin · 30 total installs
How We Detect HT CALL ME
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ht-call-now/assets/css/style.css/wp-content/plugins/ht-call-now/assets/css/font-awesome.min.cssht-call-now/assets/css/style.css?ver=ht-call-now/assets/css/font-awesome.min.css?ver=HTML / DOM Fingerprints
ht-call-nowringing_phoneringing_phone_beforeringing_phone_afterdata-ht-call-now-phonedata-ht-call-now-bg-colordata-ht-call-now-colordata-ht-call-now-style