
Toky Click To Call Security & Risk Analysis
wordpress.org/plugins/toky-click-to-callAdd a call button to your website to let your visitors and customers call you with a single click without leaving their browsers
Is Toky Click To Call Safe to Use in 2026?
Generally Safe
Score 85/100Toky Click To Call has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The toky-click-to-call plugin v1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any discovered CVEs and the lack of critical or high-severity taint flows are positive indicators. Furthermore, the code adheres to good practices by exclusively using prepared statements for SQL queries and not performing file operations or external HTTP requests, which minimizes common attack vectors. The plugin also boasts a zero attack surface, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, making it difficult for attackers to find entry points. This suggests a well-secured codebase for this version.
However, there are areas for improvement. The plugin has a concerningly low percentage of properly escaped output (67%), indicating that nearly a third of its output is not being sanitized. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected in the unescaped output. Additionally, the complete lack of nonce checks and capability checks, while potentially benign given the zero attack surface, is a weakness. If new entry points were to be introduced in future versions, these security measures would be essential to prevent unauthorized actions. The absence of any recorded vulnerabilities in its history is a strength, but it's crucial to remember that this is for version 1.0, and future versions might introduce new risks.
Key Concerns
- Significant amount of unescaped output
- Missing nonce checks
- Missing capability checks
Toky Click To Call Security Vulnerabilities
Toky Click To Call Code Analysis
Output Escaping
Toky Click To Call Attack Surface
WordPress Hooks 3
Maintenance & Trust
Toky Click To Call Maintenance & Trust
Maintenance Signals
Community Trust
Toky Click To Call Alternatives
Call-Now
call-now
Call Now is mobile calling plugin provide customer to call from website .
LiveCaller – Live Call & Chat Plugin for WordPress
livecaller
Communicate directly with your web visitors via live-chat, web-calls, and co-browsing no matter where you or they are!
Called.in Click To Call Plugin
wp-click-to-call-calledin
Called Click to call plugin allows you to easily issue a clickToCall service between two phone numbers.
Easy Caller with Mocean
easy-caller-with-moceanapi
Easy Caller uses Mocean Voice API to connect calls with you and your customers both easily and efficiently.
Live Agent Call
live-agent-call
Live Agent Call is Sip based Calling plugin provide customer to real time call with website agent.
Toky Click To Call Developer Profile
1 plugin · 10 total installs
How We Detect Toky Click To Call
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/toky-click-to-call/css/toky.cssHTML / DOM Fingerprints
toky-wptoky-wp-col-lefttoky-wp-logotoky-wp-desc-signuptoky-wp-btn-bluetoky-wp-col-righttoky-wp-containertoky-wp-title+5 moredata-toky-usernameToky<script>(function(v,p){ var s=document.createElement("script"); s.src="https://app.toky.co/resources/widgets/toky-widget.js?v="+v; s.onload=function(){Toky.load(p);}; document.head.appendChild(s); })("8dea735", {"$username":"