Mobile Call to Action Security & Risk Analysis

wordpress.org/plugins/mobile-call-to-action

Mobile Call to Action plugin is used to add a custom Call to action button in the footer of your website. It can take 2 actions, one is for phone call …

0 active installs v1.0 PHP 5.6+ WP 4.7+ Updated Oct 23, 2018
mobile-call-to-actionmobile-footer-ctaphone-call-to-actionphone-cta
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mobile Call to Action Safe to Use in 2026?

Generally Safe

Score 85/100

Mobile Call to Action has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The mobile-call-to-action plugin version 1.0 exhibits a generally good security posture based on the provided static analysis. The plugin boasts a zero attack surface, meaning it has no exposed AJAX handlers, REST API routes, shortcodes, or cron events that could serve as entry points for attackers. Furthermore, the code analysis reveals no dangerous functions, no direct SQL queries (all are prepared), no file operations, and no external HTTP requests. This suggests a well-contained and defensively coded plugin.

However, a significant concern arises from the output escaping. With 100% of outputs not being properly escaped, this presents a substantial risk. Unescaped output is a common vector for Cross-Site Scripting (XSS) vulnerabilities, where attackers could inject malicious scripts into the website, potentially leading to session hijacking, data theft, or defacement. The absence of taint analysis results and known vulnerability history is positive, but it does not negate the concrete risk identified in the output escaping.

In conclusion, while the plugin demonstrates strong architectural security by minimizing its attack surface and utilizing prepared statements, the lack of output escaping is a critical weakness. This requires immediate attention to prevent potential XSS attacks. The absence of past vulnerabilities is a positive indicator, but the current analysis highlights a clear and present danger that needs to be addressed.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Mobile Call to Action Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Mobile Call to Action Release Timeline

v1.0Current
Code Analysis
Analyzed Apr 16, 2026

Mobile Call to Action Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Mobile Call to Action Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedmobile-call-to-action.php:40
actionwp_footermobile-call-to-action.php:65
actionadmin_menumobile-call-to-action.php:80
actionadmin_initmobile-call-to-action.php:149
actionwp_enqueue_scriptsmobile-call-to-action.php:179
actionadmin_enqueue_scriptsmobile-call-to-action.php:191
Maintenance & Trust

Mobile Call to Action Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedOct 23, 2018
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs0
Alternatives

Mobile Call to Action Alternatives

No alternatives data available yet.

Developer Profile

Mobile Call to Action Developer Profile

Galib Riad

3 plugins · 20 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mobile Call to Action

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mobile-call-to-action/assets/public/css/mcta-style.css/wp-content/plugins/mobile-call-to-action/assets/public/js/mcta-main.js/wp-content/plugins/mobile-call-to-action/assets/admin/js/mcta-admin.js
Script Paths
/wp-content/plugins/mobile-call-to-action/assets/public/js/mcta-main.js/wp-content/plugins/mobile-call-to-action/assets/admin/js/mcta-admin.js
Version Parameters
mobile-call-to-action/assets/public/js/mcta-main.js?ver=1.0.0mobile-call-to-action/assets/admin/js/mcta-admin.js?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
mcta-wrappermcta-relativemcta-icons
Data Attributes
data-default-color
FAQ

Frequently Asked Questions about Mobile Call to Action