
Phone Button Security & Risk Analysis
wordpress.org/plugins/phone-buttonSimple plugin that allow you add call phone button to your wordpress site
Is Phone Button Safe to Use in 2026?
Generally Safe
Score 100/100Phone Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "phone-button" plugin version 2.1.2 demonstrates a strong security posture based on the provided static analysis. It correctly implements nonce and capability checks for its AJAX entry points, and all SQL queries are secured with prepared statements, indicating good development practices regarding common WordPress vulnerabilities.
Concerns are primarily related to output escaping. With 76% of outputs properly escaped, there's still a 24% portion that is not, which could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is handled improperly. The absence of any taint flows or dangerous functions is a positive sign, suggesting that the plugin is not directly introducing critical vulnerabilities in these areas. The clean vulnerability history with zero recorded CVEs further bolsters confidence in its current security state.
Overall, the plugin appears well-developed from a security perspective, with the main area for improvement being the consistent and comprehensive escaping of all outputs to mitigate potential XSS risks. The strong foundation in authentication and SQL security, combined with a lack of historical vulnerabilities, makes this a relatively low-risk plugin, provided the unescaped outputs do not handle sensitive user input.
Key Concerns
- Unescaped output detected (24%)
Phone Button Security Vulnerabilities
Phone Button Code Analysis
Output Escaping
Phone Button Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
Phone Button Maintenance & Trust
Maintenance Signals
Community Trust
Phone Button Alternatives
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
Mobile Call Buttons
mobile-call-buttons
Lightweight plugin that displays two fixed call buttons on mobile devices to boost conversions.
Simple Contact Bar
simple-contact-bar
Simple Contact Bar: A plugin that easily adds Call Now and WhatsApp Message buttons to your site, along with customizable options and a popup feature …
Buttons – Build Floating, Social Share & Print Buttons Easily
buttons
Easily build floating, social share, and print buttons in WordPress. Engage visitors, increase clicks, and let users share or print pages instantly.
Call From Web – Click to Call & Live Support Button for WordPress
call-from-web
🚀 Transform Your Website into a Direct Communication Channel! Get FREE Calls from Visitors Worldwide. Boost Conversions & Customer Satisfaction. 💪
Phone Button Developer Profile
11 plugins · 51K total installs
How We Detect Phone Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/phone-button/include/style.php/wp-content/plugins/phone-button/include/scripts.php/wp-content/plugins/phone-button/include/admin-output.php/wp-content/plugins/phone-button/include/install.php/wp-content/plugins/phone-button/include/functions.php/wp-content/plugins/phone-button/notices.php/wp-content/plugins/phone-button/include/front-end-output.phpHTML / DOM Fingerprints
yydev-phone-buttondata-activevalue