
WebRTC Softphone Security & Risk Analysis
wordpress.org/plugins/webrtc-softphoneWebRTC Softphone for Sip Calling with motion animate icon at the bottom of your site.
Is WebRTC Softphone Safe to Use in 2026?
Generally Safe
Score 85/100WebRTC Softphone has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The webrtc-softphone plugin v0.1.1 exhibits a generally positive security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are properly prepared, and there are no file operations or external HTTP requests. The absence of bundled libraries is also a good sign. However, a significant concern arises from the complete lack of output escaping, with 0% of the 13 identified outputs being properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be directly injected into the HTML without sanitization. The plugin also lacks nonce checks and capability checks, which, combined with the absence of any exposed entry points (AJAX, REST API, shortcodes, cron events), means there's no readily apparent attack surface to exploit. The vulnerability history is clean, with no recorded CVEs, which is encouraging. Despite the absence of traditional attack vectors, the unescaped output remains a critical weakness that could be exploited if any data is ever rendered dynamically. Therefore, while the plugin avoids many common pitfalls, the XSS risk is substantial and needs immediate attention.
Key Concerns
- Outputs not properly escaped
- Missing nonce checks
- Missing capability checks
WebRTC Softphone Security Vulnerabilities
WebRTC Softphone Code Analysis
Output Escaping
WebRTC Softphone Attack Surface
WordPress Hooks 7
Maintenance & Trust
WebRTC Softphone Maintenance & Trust
Maintenance Signals
Community Trust
WebRTC Softphone Alternatives
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements
mystickyelements
Get leads with a floating contact form tab, chat & social buttons like Facebook Messenger, WhatsApp, Viber, Telegram, Twitter, Instagram & more 🎉
All-in-one contact buttons – WPSHARE247
all-in-one-contact-buttons-wpshare247
Floating click to contact buttons All-In-One Tạo nút liên hệ gôm tất cả vào trong một nút duy nhất bao gồm: số hotline, zalo, facebook, messenger, ema …
Click to Call or Chat Buttons
click-to-call-or-chat-buttons
This plugin adds Phone Call and WhatsApp button on your webpage.
Mobile Contact Line
mobile-contact-line
Simple plugin that allow you add mobile contact line to your wordpress site
WebRTC Softphone Developer Profile
3 plugins · 50 total installs
How We Detect WebRTC Softphone
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webrtc-softphone/css.css/wp-content/plugins/webrtc-softphone/gui.js/wp-content/plugins/webrtc-softphone/init.js/wp-content/plugins/webrtc-softphone/sip-0.7.3.js/wp-content/plugins/webrtc-softphone/ua3.js/wp-content/plugins/webrtc-softphone/call.js/wp-content/plugins/webrtc-softphone/gui.js/wp-content/plugins/webrtc-softphone/init.js/wp-content/plugins/webrtc-softphone/sip-0.7.3.js/wp-content/plugins/webrtc-softphone/ua3.js/wp-content/plugins/webrtc-softphone/call.jswebrtc-softphone/css.css?ver=webrtc-softphone/gui.js?ver=webrtc-softphone/init.js?ver=webrtc-softphone/sip-0.7.3.js?ver=webrtc-softphone/ua3.js?ver=webrtc-softphone/call.js?ver=HTML / DOM Fingerprints
websp_settingsmypage-alo-phonemypage-alo-ph-circlemypage-alo-ph-circle-fillmypage-alo-ph-img-circleWebRTC Softphone 0.1.1 by Nabeel Yasindata-default-colorwebsp_VERSION