Mobile Contact Line Security & Risk Analysis

wordpress.org/plugins/mobile-contact-line

Simple plugin that allow you add mobile contact line to your wordpress site

1K active installs v2.4.2 PHP 5.2.4+ WP 5.0+ Updated Dec 10, 2025
call-now-buttonemail-buttonmobile-contact-linephone-buttonwhatsapp-button
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 3, 2025
Safety Verdict

Is Mobile Contact Line Safe to Use in 2026?

Generally Safe

Score 99/100

Mobile Contact Line has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 3, 2025Updated 3mo ago
Risk Assessment

This plugin, "mobile-contact-line" v2.4.2, exhibits a generally good security posture based on the static analysis. The absence of vulnerable AJAX handlers, REST API routes, shortcodes, and cron events, along with the complete lack of critical or high severity taint flows, are strong indicators of secure coding practices. Furthermore, all SQL queries utilize prepared statements, and the presence of nonce and capability checks on entry points is commendable.

However, there are minor areas for improvement. While the attack surface is small and currently shows no unprotected entry points, 70% output escaping is not ideal. This means that approximately 30% of output operations are not properly escaped, potentially leaving the plugin vulnerable to cross-site scripting (XSS) attacks if user-supplied data is involved in these unescaped outputs. The vulnerability history reveals a past medium severity vulnerability, specifically related to "Missing Authorization." While this vulnerability is currently patched, it suggests that the plugin has had security flaws in the past, and continuous vigilance is required.

In conclusion, "mobile-contact-line" v2.4.2 is relatively secure with many best practices being followed. The primary concern lies in the incomplete output escaping, which could be a vector for XSS. The past medium vulnerability, though patched, serves as a reminder that even well-coded plugins can have exploitable flaws. Continued development and rigorous testing are recommended to maintain its security.

Key Concerns

  • Incomplete output escaping (30% unescaped)
  • Past medium vulnerability (Missing Authorization)
Vulnerabilities
1

Mobile Contact Line Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58622medium · 4.3Missing Authorization

Mobile Contact Line <= 2.4.0 - Missing Authorization

Sep 3, 2025 Patched in 2.4.1 (7d)
Code Analysis
Analyzed Mar 16, 2026

Mobile Contact Line Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
89 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

70% escaped127 total outputs
Attack Surface

Mobile Contact Line Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_yydev_mobile_line_stop_notice_forevernotices.php:61
authwp_ajax_yydev_mobile_line_stop_notice_for_nownotices.php:83
WordPress Hooks 7
actionwp_headinclude\front-end-output.php:391
actionwp_footerinclude\front-end-output.php:402
filterbody_classinclude\front-end-output.php:419
actionwpinclude\front-end-output.php:448
actionadmin_menuindex.php:51
filterplugin_action_linksindex.php:70
actionadmin_noticesnotices.php:272
Maintenance & Trust

Mobile Contact Line Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 10, 2025
PHP min version5.2.4
Downloads7K

Community Trust

Rating100/100
Number of ratings5
Active installs1K
Developer Profile

Mobile Contact Line Developer Profile

yydevelopment

11 plugins · 51K total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
67 days
View full developer profile
Detection Fingerprints

How We Detect Mobile Contact Line

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mobile-contact-line/include/css/style.css/wp-content/plugins/mobile-contact-line/include/js/scripts.js
Script Paths
/wp-content/plugins/mobile-contact-line/include/js/scripts.js
Version Parameters
mobile-contact-line/include/css/style.css?ver=mobile-contact-line/include/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
yydev-mobile-line
Data Attributes
data-phone_button_hrefdata-phone_button_textdata-phone_background_colordata-phone_button_widthdata-phone_button_positiondata-email_button_href+20 more
FAQ

Frequently Asked Questions about Mobile Contact Line