Really Simple Click To Call Bar Security & Risk Analysis

wordpress.org/plugins/really-simple-click-to-call

A simple plugin that adds a click to call bar/call now button for mobile visitors.

8K active installs v1.0.6 PHP + WP 4.0.0+ Updated May 31, 2019
call-buttoncall-nowcall-now-buttonclick-to-callclick-to-call-bar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Really Simple Click To Call Bar Safe to Use in 2026?

Generally Safe

Score 85/100

Really Simple Click To Call Bar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "really-simple-click-to-call" plugin version 1.0.6 presents a mixed security posture. On the positive side, the static analysis indicates a very limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all detected SQL queries utilize prepared statements, and there are no instances of dangerous functions, file operations, external HTTP requests, or bundled libraries, which are all good security practices. The lack of recorded vulnerabilities in its history also suggests a relatively stable past.

However, a significant concern arises from the complete lack of output escaping. With 6 total outputs identified, and 0% properly escaped, this represents a high risk for Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed by the plugin without proper sanitization and escaping could be exploited by attackers to inject malicious scripts. The absence of nonce and capability checks, while not directly indicating a vulnerability in this specific version due to the limited attack surface, means that if any new entry points were added in the future, they would likely be unprotected.

Key Concerns

  • 0% output escaping
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Really Simple Click To Call Bar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Really Simple Click To Call Bar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Attack Surface

Really Simple Click To Call Bar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menureally-simple-click-to-call.php:15
actionadmin_initreally-simple-click-to-call.php:16
actionadmin_enqueue_scriptsreally-simple-click-to-call.php:17
actionwp_footerreally-simple-click-to-call.php:21
Maintenance & Trust

Really Simple Click To Call Bar Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedMay 31, 2019
PHP min version
Downloads48K

Community Trust

Rating90/100
Number of ratings11
Active installs8K
Developer Profile

Really Simple Click To Call Bar Developer Profile

Joe Nickdow

1 plugin · 8K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Really Simple Click To Call Bar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/really-simple-click-to-call/css/ctc_style.css
Script Paths
/wp-content/plugins/really-simple-click-to-call/js/ctc.js
Version Parameters
ctc-styles

HTML / DOM Fingerprints

CSS Classes
ctc_barctc-icon-phone
Data Attributes
data-ctc-numberdata-ctc-messagedata-ctc-colordata-ctc-bg
JS Globals
ctc_phone_numberctc_messagectc_colorctc_bg_color
FAQ

Frequently Asked Questions about Really Simple Click To Call Bar