Smartarget Click to call Security & Risk Analysis

wordpress.org/plugins/smartarget-click-to-call

Add click to call button on your site

0 active installs v1.5 PHP 5.2.4+ WP 3.0.1+ Updated Feb 13, 2026
callcallbackcontactcontact-usform
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Smartarget Click to call Safe to Use in 2026?

Generally Safe

Score 100/100

Smartarget Click to call has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The static analysis of "smartarget-click-to-call" v1.5 reveals an exceptionally clean codebase with no apparent vulnerabilities. The plugin demonstrates excellent security practices, including the complete absence of dangerous functions, file operations, and external HTTP requests. All SQL queries are properly prepared, and all outputs are correctly escaped, mitigating common injection and cross-site scripting risks. Furthermore, the lack of any observed taint flows with unsanitized paths suggests a robust approach to data handling.

The plugin's vulnerability history is also remarkably clean, with zero recorded CVEs. This indicates a history of secure development and potentially prompt patching if any issues have ever arisen. The absence of any identified attack surface points, such as unprotected AJAX handlers, REST API routes, or shortcodes, further strengthens its security profile. While the lack of nonce and capability checks on entry points is technically present in the data, given there are zero entry points, this is not a practical concern. The plugin's strengths lie in its minimalist design and diligent adherence to secure coding principles.

In conclusion, "smartarget-click-to-call" v1.5 presents a very low security risk based on the provided static analysis and vulnerability history. Its thorough implementation of secure coding practices and the absence of any detected vulnerabilities make it a highly secure option. The lack of common attack vectors and its clean audit trail are significant strengths.

Vulnerabilities
None known

Smartarget Click to call Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Smartarget Click to call Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Smartarget Click to call Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Smartarget Click to call Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedincludes/class-smartarget-call-button.php:142
actionadmin_enqueue_scriptsincludes/class-smartarget-call-button.php:157
actionadmin_enqueue_scriptsincludes/class-smartarget-call-button.php:158
actionadmin_menuincludes/class-smartarget-call-button.php:160
actionadmin_initincludes/class-smartarget-call-button.php:165
actionwp_enqueue_scriptsincludes/class-smartarget-call-button.php:179
actionwp_enqueue_scriptsincludes/class-smartarget-call-button.php:180
Maintenance & Trust

Smartarget Click to call Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 13, 2026
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Smartarget Click to call Developer Profile

Erez Hadas-Sonnenschein

22 plugins · 2K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smartarget Click to call

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smartarget-click-to-call/admin/css/smartarget-call-button-admin.css/wp-content/plugins/smartarget-click-to-call/admin/js/smartarget-call-button-admin.js/wp-content/plugins/smartarget-click-to-call/public/css/smartarget-call-button-public.css/wp-content/plugins/smartarget-click-to-call/public/js/smartarget-call-button-public.js
Script Paths
https://smartarget.online/wp-dashboard/package.jshttps://smartarget.online/loader.js
Version Parameters
smartarget-call-button-public.css?ver=smartarget-call-button-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
smartarget-call-buttonsmartarget-call-button-wrapper
HTML Comments
<!-- ST_CALL_BUTTON_START --><!-- ST_CALL_BUTTON_END --><!-- Smartarget Click to call -->
Data Attributes
data-smartarget-widget-id
JS Globals
smartarget_params
Shortcode Output
[smartarget_call_button]
FAQ

Frequently Asked Questions about Smartarget Click to call