INVOX Call Tracking Security & Risk Analysis
wordpress.org/plugins/invox-call-trackingThe INVOX Call Tracking plugin lets WordPress users easily add Dynamic Number Insertion (DNI) to their site without technical or coding skills.
Is INVOX Call Tracking Safe to Use in 2026?
Generally Safe
Score 100/100INVOX Call Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The invox-call-tracking plugin version 1.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or critical taint flows is commendable. Furthermore, the lack of recorded vulnerabilities in its history suggests a history of secure development and maintenance.
However, the analysis does reveal potential areas of concern. The complete absence of nonce checks and capability checks across all entry points, including the entirely unprotected attack surface of AJAX handlers, REST API routes, shortcodes, and cron events, represents a significant weakness. While the current version might not be exploited due to its limited attack surface and potentially clean code, this lack of authorization checks on all potential entry points leaves the plugin vulnerable to privilege escalation or unauthorized actions if new entry points are added or if external data is processed without proper validation.
In conclusion, the plugin scores well on code hygiene and a clean vulnerability history. Its strength lies in its clean code and lack of known exploits. The primary weakness is the comprehensive lack of authentication and authorization mechanisms on its entry points, which poses a future risk should the attack surface grow or if it's integrated into more complex environments. A balanced assessment points to a plugin that is currently safe but could benefit from robust access control implementation.
Key Concerns
- No capability checks on entry points
- No nonce checks on entry points
- Unprotected attack surface (AJAX, REST, shortcodes, cron)
INVOX Call Tracking Security Vulnerabilities
INVOX Call Tracking Code Analysis
Output Escaping
INVOX Call Tracking Attack Surface
WordPress Hooks 3
Maintenance & Trust
INVOX Call Tracking Maintenance & Trust
Maintenance Signals
Community Trust
INVOX Call Tracking Alternatives
Clixtell
clixtell-tracking-dynamic-phones
Clixtell Tracking & Dynamic Phones integrates Clixtell click fraud detection and dynamic phone number insertion into your WordPress site.
CallRoot
callroot
CallRoot wordpress plugin facilitates Dynamic Number Insertion (DNI), i.e., it automatically inserts the javascript code for swapping phone numbers in …
800.com Call Tracking
800-com-call-tracking
Seamlessly add 800.com dynamic number insertion to your WordPress site for enhanced call tracking and marketing attribution.
Dynamic Number Insertion
dynamic-number-insertion
Dynamically replace phone numbers on specific pages for location-based businesses, landing pages, and call tracking campaigns.
CallRail Phone Call Tracking
callrail-phone-call-tracking
Dynamically swap CallRail tracking phone numbers based on the visitor's referring source.
INVOX Call Tracking Developer Profile
1 plugin · 40 total installs
How We Detect INVOX Call Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
//app.invox.eu/invox_tracking.js?v=HTML / DOM Fingerprints
wrap