
Lunatec Callback Widget Security & Risk Analysis
wordpress.org/plugins/lunatec-callback-widgetA simple, customizable plugin for callback requests via a floating button and modal. Includes Hubspot, Slack and Email integrations.
Is Lunatec Callback Widget Safe to Use in 2026?
Generally Safe
Score 100/100Lunatec Callback Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The lunatec-callback-widget plugin, version 1.0.3, exhibits a generally strong security posture with good development practices. All identified entry points (AJAX handlers and shortcodes) appear to be protected by appropriate authorization checks, and SQL queries are exclusively executed using prepared statements, mitigating risks of SQL injection. Furthermore, all output is properly escaped, and nonce checks are implemented, which are crucial for preventing Cross-Site Request Forgery (CSRF) and other related attacks. The plugin also has no recorded vulnerability history, indicating a history of secure development or prompt patching of any past issues.
Despite these strengths, the static analysis reveals a potential concern within the taint analysis. There are 3 flows with unsanitized paths, and one of these is flagged as high severity. While the number of flows is small, a high-severity taint flow is a significant indicator of a potential vulnerability, likely related to how user-supplied data is handled before being used in sensitive operations, even if it doesn't directly lead to a critical vulnerability in this version. The presence of file operations and external HTTP requests, while not inherently insecure, are areas that warrant careful review in conjunction with the identified taint flows.
Overall, the plugin is well-secured in terms of common web vulnerabilities like SQL injection and XSS. However, the high-severity unsanitized path identified in the taint analysis introduces a notable risk that requires further investigation and remediation. The plugin's clean vulnerability history is a positive sign, but the taint analysis finding suggests that vigilance is still necessary.
Key Concerns
- High severity unsanitized path in taint analysis
Lunatec Callback Widget Security Vulnerabilities
Lunatec Callback Widget Release Timeline
Lunatec Callback Widget Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Lunatec Callback Widget Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Lunatec Callback Widget Maintenance & Trust
Maintenance Signals
Community Trust
Lunatec Callback Widget Alternatives
Lead Form Builder & Contact Form
lead-form-builder
Drag & Drop Contact Form Builder for WordPress to create contact, lead generation, newsletter & registration forms. Works with Elementor & Gutenberg.
WS Form LITE – Drag & Drop Contact Form Builder
ws-form
Contact form builder for WordPress. Create professional, accessible, mobile-friendly forms in minutes without coding.
Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-hubspot
Send Contact Form 7, WPForms, Elementor, Ninja Forms, WPforms, Elementor, Ninja Forms, Contact Form Entries Plugin and many other contact form submiss …
Boei – Chat Widget & AI Chatbot with 50+ Channels
boei-help
Capture every lead. Reply instantly. Close more deals. AI chatbot, 50+ contact channels, single inbox, and lead tracking—all in one WordPress plugin.
Contact Forms by Cimatti
contact-forms
Create and publish forms in your WordPress website with drag and drop. Contact forms, landing page forms, invitations, and more.
Lunatec Callback Widget Developer Profile
2 plugins · 0 total installs
How We Detect Lunatec Callback Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lunatec-callback-widget/assets/css/style.css/wp-content/plugins/lunatec-callback-widget/assets/vendor/intl-tel-input/css/intlTelInput.min.css/wp-content/plugins/lunatec-callback-widget/assets/js/frontend.js/wp-content/plugins/lunatec-callback-widget/assets/vendor/intl-tel-input/js/intlTelInput.min.js/wp-content/plugins/lunatec-callback-widget/assets/vendor/intl-tel-input/js/utils.js/wp-content/plugins/lunatec-callback-widget/assets/js/frontend.js/wp-content/plugins/lunatec-callback-widget/assets/vendor/intl-tel-input/js/intlTelInput.min.js/wp-content/plugins/lunatec-callback-widget/assets/vendor/intl-tel-input/js/utils.jslunatec-callback-widget/assets/css/style.css?ver=lunatec-callback-widget/assets/vendor/intl-tel-input/css/intlTelInput.min.css?ver=lunatec-callback-widget/assets/js/frontend.js?ver=lunatec-callback-widget/assets/vendor/intl-tel-input/js/intlTelInput.min.js?ver=lunatec-callback-widget/assets/vendor/intl-tel-input/js/utils.js?ver=HTML / DOM Fingerprints
lcbw-callback-widget-buttonlcbw-modallcbw-modal-contentlcbw-modal-headerlcbw-modal-bodylcbw-modal-footerlcbw-form-grouplcbw-input-field+6 moredata-lcbw-button-textdata-lcbw-button-colordata-lcbw-button-text-colordata-lcbw-modal-titledata-lcbw-modal-subtextdata-lcbw-submit-button-color+9 morelcbw_ajax_objectintlTelInput/wp-json/lcbw/v1/submit-request<button class="lcbw-callback-widget-button" [dynamic_styles]><div id="lcbw-callback-modal"<div class="lcbw-modal-header"><div class="lcbw-modal-body">