
Smartarget Click to call Security & Risk Analysis
wordpress.org/plugins/smartarget-click-to-callAdd click to call button on your site
Is Smartarget Click to call Safe to Use in 2026?
Generally Safe
Score 100/100Smartarget Click to call has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "smartarget-click-to-call" v1.5 reveals an exceptionally clean codebase with no apparent vulnerabilities. The plugin demonstrates excellent security practices, including the complete absence of dangerous functions, file operations, and external HTTP requests. All SQL queries are properly prepared, and all outputs are correctly escaped, mitigating common injection and cross-site scripting risks. Furthermore, the lack of any observed taint flows with unsanitized paths suggests a robust approach to data handling.
The plugin's vulnerability history is also remarkably clean, with zero recorded CVEs. This indicates a history of secure development and potentially prompt patching if any issues have ever arisen. The absence of any identified attack surface points, such as unprotected AJAX handlers, REST API routes, or shortcodes, further strengthens its security profile. While the lack of nonce and capability checks on entry points is technically present in the data, given there are zero entry points, this is not a practical concern. The plugin's strengths lie in its minimalist design and diligent adherence to secure coding principles.
In conclusion, "smartarget-click-to-call" v1.5 presents a very low security risk based on the provided static analysis and vulnerability history. Its thorough implementation of secure coding practices and the absence of any detected vulnerabilities make it a highly secure option. The lack of common attack vectors and its clean audit trail are significant strengths.
Smartarget Click to call Security Vulnerabilities
Smartarget Click to call Release Timeline
Smartarget Click to call Code Analysis
Output Escaping
Smartarget Click to call Attack Surface
WordPress Hooks 7
Maintenance & Trust
Smartarget Click to call Maintenance & Trust
Maintenance Signals
Community Trust
Smartarget Click to call Alternatives
ZVI CallBack widget
zvi-callback-widget
This plugin makes a simple widget for callback on your website.
CallBack Widget for WordPress
callback-widget
The conversion of the site and landing pages up to 50%. Integrate CallBack widget by CallBackHunter in WordPress. And livechat, feedback form.
Forms by Systemo
forms-by-systemo
Fully customise WordPress forms with powerful shortcodes.
EngageDock AI – Smart Support Assistant
engagedock-ai-smart-support-assistant
Floating contact widget with click-to-call, click-to-text, callback form, business hours, vCard, and analytics.
Lunatec Callback Widget
lunatec-callback-widget
A simple, customizable plugin for callback requests via a floating button and modal. Includes Hubspot, Slack and Email integrations.
Smartarget Click to call Developer Profile
22 plugins · 2K total installs
How We Detect Smartarget Click to call
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/smartarget-click-to-call/admin/css/smartarget-call-button-admin.css/wp-content/plugins/smartarget-click-to-call/admin/js/smartarget-call-button-admin.js/wp-content/plugins/smartarget-click-to-call/public/css/smartarget-call-button-public.css/wp-content/plugins/smartarget-click-to-call/public/js/smartarget-call-button-public.jshttps://smartarget.online/wp-dashboard/package.jshttps://smartarget.online/loader.jssmartarget-call-button-public.css?ver=smartarget-call-button-public.js?ver=HTML / DOM Fingerprints
smartarget-call-buttonsmartarget-call-button-wrapper<!-- ST_CALL_BUTTON_START --><!-- ST_CALL_BUTTON_END --><!-- Smartarget Click to call -->data-smartarget-widget-idsmartarget_params[smartarget_call_button]