
Mobile Call to Action Security & Risk Analysis
wordpress.org/plugins/mobile-call-to-actionMobile Call to Action plugin is used to add a custom Call to action button in the footer of your website. It can take 2 actions, one is for phone call …
Is Mobile Call to Action Safe to Use in 2026?
Generally Safe
Score 85/100Mobile Call to Action has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mobile-call-to-action plugin version 1.0 exhibits a generally good security posture based on the provided static analysis. The plugin boasts a zero attack surface, meaning it has no exposed AJAX handlers, REST API routes, shortcodes, or cron events that could serve as entry points for attackers. Furthermore, the code analysis reveals no dangerous functions, no direct SQL queries (all are prepared), no file operations, and no external HTTP requests. This suggests a well-contained and defensively coded plugin.
However, a significant concern arises from the output escaping. With 100% of outputs not being properly escaped, this presents a substantial risk. Unescaped output is a common vector for Cross-Site Scripting (XSS) vulnerabilities, where attackers could inject malicious scripts into the website, potentially leading to session hijacking, data theft, or defacement. The absence of taint analysis results and known vulnerability history is positive, but it does not negate the concrete risk identified in the output escaping.
In conclusion, while the plugin demonstrates strong architectural security by minimizing its attack surface and utilizing prepared statements, the lack of output escaping is a critical weakness. This requires immediate attention to prevent potential XSS attacks. The absence of past vulnerabilities is a positive indicator, but the current analysis highlights a clear and present danger that needs to be addressed.
Key Concerns
- Unescaped output detected
Mobile Call to Action Security Vulnerabilities
Mobile Call to Action Release Timeline
Mobile Call to Action Code Analysis
Output Escaping
Mobile Call to Action Attack Surface
WordPress Hooks 6
Maintenance & Trust
Mobile Call to Action Maintenance & Trust
Maintenance Signals
Community Trust
Mobile Call to Action Alternatives
No alternatives data available yet.
Mobile Call to Action Developer Profile
3 plugins · 20 total installs
How We Detect Mobile Call to Action
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mobile-call-to-action/assets/public/css/mcta-style.css/wp-content/plugins/mobile-call-to-action/assets/public/js/mcta-main.js/wp-content/plugins/mobile-call-to-action/assets/admin/js/mcta-admin.js/wp-content/plugins/mobile-call-to-action/assets/public/js/mcta-main.js/wp-content/plugins/mobile-call-to-action/assets/admin/js/mcta-admin.jsmobile-call-to-action/assets/public/js/mcta-main.js?ver=1.0.0mobile-call-to-action/assets/admin/js/mcta-admin.js?ver=1.0.0HTML / DOM Fingerprints
mcta-wrappermcta-relativemcta-iconsdata-default-color