
Lead Call Buttons Security & Risk Analysis
wordpress.org/plugins/lead-call-buttonsMake it easy for website visitors to reach you. When enabled adds customizable buttons to the mobile view of the website, i.e. Call, Map, Schedule.
Is Lead Call Buttons Safe to Use in 2026?
Generally Safe
Score 85/100Lead Call Buttons has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lead-call-buttons" v1.0.7 plugin exhibits a generally positive security posture, with a notable absence of known vulnerabilities and critical issues in taint analysis. The code signals indicate good practices in areas like SQL query handling (100% prepared statements) and the presence of nonce and capability checks. The attack surface appears minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. This suggests a developer with an awareness of common WordPress security pitfalls.
However, a significant concern arises from the output escaping. With only 29% of outputs properly escaped out of 79 total outputs, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This means that data displayed by the plugin, if manipulated by an attacker, could be rendered in the user's browser in an unintended and potentially malicious way. While taint analysis did not reveal any flows, the low output escaping rate is a critical area that needs immediate attention. The plugin's history of no vulnerabilities could be due to its limited exposure or simply a period of good luck, but the current code analysis reveals a significant potential weakness.
In conclusion, while the plugin demonstrates strengths in preventing SQL injection and maintaining a small, controlled attack surface, the poor output escaping is a glaring weakness that significantly elevates the risk. Addressing the XSS potential should be the top priority for improving its security. The lack of historical vulnerabilities is a positive sign, but it does not negate the current, observable risks within the codebase.
Key Concerns
- Low percentage of properly escaped output
Lead Call Buttons Security Vulnerabilities
Lead Call Buttons Code Analysis
Output Escaping
Lead Call Buttons Attack Surface
WordPress Hooks 11
Maintenance & Trust
Lead Call Buttons Maintenance & Trust
Maintenance Signals
Community Trust
Lead Call Buttons Alternatives
Footer Contacts D
dn-footer-contacts
Elegant and customizable buttons bar with "Call to Action" for Whatsapp, map address, phone, email, download and custom button.
Mobile Contact Buttons
mobile-contact-buttons
Adds Call, Email and SMS buttons on bottom of website. Only for Mobile View of website.
Max Mega Menu
megamenu
An easy to use mega menu plugin. Written the WordPress way.
MaxButtons – Create buttons
maxbuttons
Maxbuttons is the best and easiest button plugin for WordPress. Within minutes you can create beautiful buttons, share buttons and social icons.
WP Mobile Menu – The Mobile-Friendly Responsive Menu
mobile-menu
Need some help with the mobile website experience? Need an Mobile Menu plugin that keep your mobile visitors engaged?
Lead Call Buttons Developer Profile
1 plugin · 6K total installs
How We Detect Lead Call Buttons
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lead-call-buttons/assets/css/style.css/wp-content/plugins/lead-call-buttons/assets/js/main.js/wp-content/plugins/lead-call-buttons/assets/js/main.jslead-call-buttons/assets/css/style.css?ver=lead-call-buttons/assets/js/main.js?ver=HTML / DOM Fingerprints
main_buttonsmain_buttons_animatecallnow_areaschedule_areamap_areaoncallnow_bottomschedule_bottom+5 moreStart Lead Call Buttonsid="lcb_main_area"