Contact widget – Ocl.to Security & Risk Analysis

wordpress.org/plugins/ocl-widget

Generate your own contact widget and paste it to your Wordpress page. Gather information about clients and automatically transfer it to your Ocl CRM s …

0 active installs v1.0.1 PHP 7.1+ WP 4.7+ Updated Apr 27, 2021
client-listclients-managementcom-systemcontact-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Contact widget – Ocl.to Safe to Use in 2026?

Generally Safe

Score 85/100

Contact widget – Ocl.to has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "ocl-widget" plugin v1.0.1 demonstrates a strong adherence to secure coding practices in several key areas. Notably, it has zero recorded vulnerabilities (CVEs) and no known security issues, suggesting a history of stable and potentially secure development. The static analysis also reveals a minimal attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without proper checks. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is a significant positive indicator.

However, there are notable areas of concern. The plugin's SQL queries are entirely unparameterized, presenting a significant risk of SQL injection vulnerabilities, especially as there are five such queries. While the plugin has one capability check, the absence of nonce checks on any potential entry points (though zero are explicitly listed) and the fact that only 75% of outputs are properly escaped leave room for cross-site scripting (XSS) vulnerabilities. The zero taint flows analyzed is not necessarily a positive sign; it could indicate that the taint analysis tooling was limited or that the plugin's code structure did not allow for comprehensive taint flow tracking.

In conclusion, while the plugin's lack of historical vulnerabilities and small attack surface are commendable, the unparameterized SQL queries and incomplete output escaping pose tangible risks. These are common vectors for severe vulnerabilities and require immediate attention. The plugin's security posture is mixed, with strengths in attack surface reduction and vulnerability history, but significant weaknesses in data handling and output sanitization.

Key Concerns

  • SQL queries not using prepared statements
  • Output escaping not fully implemented
  • No nonce checks on entry points
Vulnerabilities
None known

Contact widget – Ocl.to Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Contact widget – Ocl.to Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
0 prepared
Unescaped Output
1
3 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared5 total queries

Output Escaping

75% escaped4 total outputs
Attack Surface

Contact widget – Ocl.to Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_footerincludes\menu_or_widget.php:31
actionadmin_enqueue_scriptsord_sys.php:64
actionadmin_enqueue_scriptsord_sys.php:65
actionadmin_menuord_sys.php:66
actionwp_enqueue_scriptsord_sys.php:70
Maintenance & Trust

Contact widget – Ocl.to Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedApr 27, 2021
PHP min version7.1
Downloads806

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Contact widget – Ocl.to Developer Profile

getreveltd

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact widget – Ocl.to

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ocl-widget/admin/css/style.css/wp-content/plugins/ocl-widget/admin/js/add-menu-script.js
Script Paths
https://widget.clientlist.io/js/widget.min.js
Version Parameters
ocl-widget/admin/css/style.css?ver=ocl-widget/admin/js/add-menu-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
ocl-widget-wrapperocl-widget-tabocl-widget-tab-nameocl-iframeocl-widget-close
Data Attributes
data-ocl-widget-urldata-ocl-widget-id
JS Globals
oclStartWidget
FAQ

Frequently Asked Questions about Contact widget – Ocl.to