Webphone Security & Risk Analysis

wordpress.org/plugins/webphone

Webphone plugin is a complement for Webphone customers that will make it easier to use the tool on your Wordpress website.

10 active installs v2.3 PHP 7.0+ WP 5.0+ Updated May 26, 2026
clicktocallwebphonewebphone-dinamciswebphone-dynamics
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Webphone Safe to Use in 2026?

Generally Safe

Score 100/100

Webphone has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'webphone' plugin v2.2.1 exhibits a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) and the plugin appears to implement some fundamental security checks, including nonce and capability checks. The absence of dangerous functions, file operations, and external HTTP requests is also reassuring. However, the static analysis reveals significant concerns regarding output sanitization, with only 6% of outputs being properly escaped. This presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website's frontend, potentially leading to session hijacking, data theft, or defacement.

Furthermore, the taint analysis identified one flow with an unsanitized path. While the severity was not categorized as critical or high, any unsanitized path is a potential entry point for path traversal or other file system manipulation attacks if not properly handled by the underlying WordPress environment. The lack of an extensive attack surface with no AJAX handlers, REST API routes, or shortcodes is a positive sign, indicating fewer direct entry points for attackers. However, the identified output escaping issue and the unsanitized path flow are significant weaknesses that require immediate attention to mitigate potential security risks.

Key Concerns

  • Low percentage of properly escaped output
  • Flow with unsanitized path
Vulnerabilities
None known

Webphone Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Webphone Release Timeline

v1.0
Code Analysis
Analyzed Mar 17, 2026

Webphone Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
48
3 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

6% escaped51 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
<admin_webphone_dynamics_button_page> (admin\views\admin_webphone_dynamics_button_page.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Webphone Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionadmin_footeradmin\class-webphone-dynamics-admin.php:142
actionplugins_loadedadmin\class-webphone-dynamics-admin.php:309
actionplugins_loadedincludes\class-webphone-dynamics.php:152
actionadmin_menuincludes\class-webphone-dynamics.php:167
actionadmin_enqueue_scriptsincludes\class-webphone-dynamics.php:169
actionadmin_enqueue_scriptsincludes\class-webphone-dynamics.php:170
actionwp_enqueue_scriptsincludes\class-webphone-dynamics.php:185
actionwp_enqueue_scriptsincludes\class-webphone-dynamics.php:186
actionwp_footerpublic\class-webphone-dynamics-public.php:121
actionthe_contentpublic\class-webphone-dynamics-public.php:127
actionadmin_initwebphone.php:93
actionadmin_initwebphone.php:94
filteradmin_footer_textwebphone.php:105
filterupdate_footerwebphone.php:108
Maintenance & Trust

Webphone Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedMay 26, 2026
PHP min version7.0
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Webphone Developer Profile

Webphone

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Webphone

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webphone-dynamics/admin/css/webphone-dynamics-admin.css/wp-content/plugins/webphone-dynamics/admin/js/webphone-dynamics-admin.js/wp-content/plugins/webphone-dynamics/admin/js/jquery.json-editor.min.js
Script Paths
https://llamamegratis.es/webphone-site/js/webphone.dinamics.js
Version Parameters
webphone-dynamics-admin.css?ver=webphone-dynamics-admin.js?ver=jquery.json-editor.min.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Currently plugin version. --><!-- Constant definitions --><!-- The code that runs during plugin activation. --><!-- The code that runs during plugin deactivation. -->+32 more
Data Attributes
id="webphoneConfigPluginWP"
JS Globals
WPHD_WEBPHONE_DYNAMICS_VERSIONWPHD_PLUGIN_NAMEWPHD_PLUGIN_PATHWPHD_POST_TYPEWPHD_activate_webphone_dynamicsWPHD_deactivate_webphone_dynamics+12 more
FAQ

Frequently Asked Questions about Webphone