PayCall Analytics Security & Risk Analysis

wordpress.org/plugins/paycall-analytics

PayCall Google Analytics 4 integration for cross-channel lead attribution.

0 active installs v5.0 PHP 7.4+ WP 6.0+ Updated Jun 1, 2026
analyticsattributionga4google-analyticspaycall
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PayCall Analytics Safe to Use in 2026?

Generally Safe

Score 100/100

PayCall Analytics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'paycall-analytics' plugin v1.0 exhibits a generally strong security posture. The absence of any reported CVEs and the complete lack of dangerous functions, raw SQL queries, file operations, external HTTP requests, and file operations are significant positive indicators. Furthermore, the plugin's attack surface appears to be zero entry points, with no AJAX handlers, REST API routes, shortcodes, or cron events detected. This suggests a deliberate effort to minimize exposure to potential vulnerabilities.

However, a critical concern arises from the output escaping analysis. With 100% of its outputs not properly escaped, the plugin presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any data that is displayed to users or processed by the browser without proper sanitization could be exploited by attackers to inject malicious scripts. While the taint analysis and vulnerability history are clean, the lack of output escaping represents a glaring weakness that could be easily exploited, potentially negating the benefits of its otherwise robust design. Therefore, despite its strengths, the unescaped output is a serious deficiency that requires immediate attention.

Key Concerns

  • All outputs are unescaped
Vulnerabilities
None known

PayCall Analytics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

PayCall Analytics Release Timeline

v5.0Current
Code Analysis
Analyzed Mar 17, 2026

PayCall Analytics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

PayCall Analytics Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_footerpaycall-analytics.php:16
actionadmin_initpaycall-analytics.php:25
actionadmin_menupaycall-analytics.php:34
Maintenance & Trust

PayCall Analytics Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJun 1, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

PayCall Analytics Developer Profile

PayCall.co.il

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PayCall Analytics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://ws.callindex.co.il/campaign/send_analytics.js

HTML / DOM Fingerprints

Data Attributes
id="ptoken"
FAQ

Frequently Asked Questions about PayCall Analytics