WEN Call To Action Security & Risk Analysis

wordpress.org/plugins/wen-call-to-action

Easily create call to action for your WordPress site

200 active installs v1.4.3 PHP + WP 4.8+ Updated Mar 17, 2024
call-to-actioncalls-to-actionctacta-buttonshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WEN Call To Action Safe to Use in 2026?

Generally Safe

Score 85/100

WEN Call To Action has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "wen-call-to-action" plugin version 1.4.3 exhibits a strong security posture based on the provided static analysis. There are no identified critical or high-severity code signals, and importantly, no taint analysis revealed any unsanitized data flows. The plugin also benefits from a clean vulnerability history, with no known CVEs or past vulnerabilities, suggesting a history of responsible development and maintenance.

Despite the positive indicators, a few areas warrant attention. The plugin utilizes 23 total outputs, with 78% properly escaped. While this is a good percentage, the remaining 22% of outputs that are not properly escaped present a potential risk for cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unescaped outputs. Furthermore, the presence of a shortcode as an entry point, while currently unprotected, is a minor concern if the shortcode's functionality were to be extended in the future without proper security considerations.

Overall, the plugin demonstrates good security practices with its use of prepared statements, nonce checks, and capability checks. The lack of known vulnerabilities is a significant strength. The primary area for improvement lies in ensuring all output is consistently and properly escaped to mitigate any potential XSS risks. The current security posture is good, but continued diligence in code review and output escaping is recommended.

Key Concerns

  • Unescaped outputs present potential XSS risks
  • Shortcode entry point lacks explicit authentication check
Vulnerabilities
None known

WEN Call To Action Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WEN Call To Action Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
18 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

78% escaped23 total outputs
Attack Surface

WEN Call To Action Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wen_cta] includes\class-wen-call-to-action.php:172
WordPress Hooks 13
actionplugins_loadedincludes\class-wen-call-to-action.php:160
actionadmin_enqueue_scriptsincludes\class-wen-call-to-action.php:187
actionadd_meta_boxesincludes\class-wen-call-to-action.php:194
actionsave_postincludes\class-wen-call-to-action.php:195
actionsave_postincludes\class-wen-call-to-action.php:196
filterpost_row_actionsincludes\class-wen-call-to-action.php:199
actionadmin_head-post.phpincludes\class-wen-call-to-action.php:202
actionadmin_head-post-new.phpincludes\class-wen-call-to-action.php:203
actionwp_enqueue_scriptsincludes\class-wen-call-to-action.php:218
filterinitincludes\class-wen-call-to-action.php:221
filterwen_call_to_action_filter_custom_classincludes\class-wen-call-to-action.php:224
filterwidget_textincludes\class-wen-call-to-action.php:227
filterwidget_textincludes\class-wen-call-to-action.php:228
Maintenance & Trust

WEN Call To Action Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMar 17, 2024
PHP min version
Downloads10K

Community Trust

Rating80/100
Number of ratings1
Active installs200
Developer Profile

WEN Call To Action Developer Profile

WEN Themes

63 plugins · 35K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect WEN Call To Action

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wen-call-to-action/css/wen-call-to-action-admin.css/wp-content/plugins/wen-call-to-action/css/wen-call-to-action-admin.min.css/wp-content/plugins/wen-call-to-action/js/wen-call-to-action-public.js/wp-content/plugins/wen-call-to-action/js/wen-call-to-action-public.min.js/wp-content/plugins/wen-call-to-action/js/wen-call-to-action-admin.js/wp-content/plugins/wen-call-to-action/js/wen-call-to-action-admin.min.js
Script Paths
admin/js/wen-call-to-action-admin.jspublic/js/wen-call-to-action-public.js
Version Parameters
wen-call-to-action/css/wen-call-to-action-admin.css?ver=wen-call-to-action/css/wen-call-to-action-admin.min.css?ver=wen-call-to-action/js/wen-call-to-action-public.js?ver=wen-call-to-action/js/wen-call-to-action-public.min.js?ver=wen-call-to-action/js/wen-call-to-action-admin.js?ver=wen-call-to-action/js/wen-call-to-action-admin.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
wen-cta-overlaywen-cta-button-wrapwen-cta-titlewen-cta-descriptionwen-cta-buttonwen-cta-container
HTML Comments
<!-- Call To Action Info --><!-- Usage --><!-- Call To Action Design --><!-- Shortcode Output -->+2 more
Data Attributes
data-iddata-themedata-custom-class
JS Globals
wen_call_to_action_params
Shortcode Output
[wen_cta id="
FAQ

Frequently Asked Questions about WEN Call To Action