
WP Call Button – Easy Click to Call Button for WordPress Security & Risk Analysis
wordpress.org/plugins/wp-call-buttonThe best WordPress call now button plugin. We help you add a clickable phone link (quick call button), so people can easily call your business phone.
Is WP Call Button – Easy Click to Call Button for WordPress Safe to Use in 2026?
Generally Safe
Score 92/100WP Call Button – Easy Click to Call Button for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-call-button plugin version 1.4.3 exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history indicate a well-maintained and secure codebase. The plugin utilizes prepared statements for all SQL queries and has a high rate of output escaping, which are strong indicators of secure coding practices. Furthermore, the limited attack surface, with all identified entry points (AJAX handlers and shortcodes) appearing to have proper authentication or permission checks, reduces the immediate risk of exploitation.
While the plugin demonstrates good security fundamentals, there are minor areas for attention. The 91% output escaping rate, while high, means that a small percentage of outputs are not properly escaped. Depending on the context of these unescaped outputs, they could potentially lead to cross-site scripting (XSS) vulnerabilities. Additionally, the presence of bundled libraries, such as Select2, always carries a potential risk if these libraries themselves have known vulnerabilities or are outdated. However, without specific information on the version of Select2 used or known vulnerabilities within it, this remains a theoretical concern.
Overall, wp-call-button v1.4.3 appears to be a secure plugin with a strong focus on preventing common web vulnerabilities. The lack of critical or high-severity issues in static analysis and no recorded past vulnerabilities are significant strengths. The minor concern regarding the unescaped outputs and the bundled library warrants a slight deduction, but the overall risk is low.
Key Concerns
- Minor percentage of unescaped outputs
- Bundled library (potential for outdated/vulnerable)
WP Call Button – Easy Click to Call Button for WordPress Security Vulnerabilities
WP Call Button – Easy Click to Call Button for WordPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Call Button – Easy Click to Call Button for WordPress Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
WP Call Button – Easy Click to Call Button for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
WP Call Button – Easy Click to Call Button for WordPress Alternatives
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
Really Simple Click To Call Bar
really-simple-click-to-call
A simple plugin that adds a click to call bar/call now button for mobile visitors.
All-in-one contact buttons – WPSHARE247
all-in-one-contact-buttons-wpshare247
Floating click to contact buttons All-In-One Tạo nút liên hệ gôm tất cả vào trong một nút duy nhất bao gồm: số hotline, zalo, facebook, messenger, ema …
Floating Click to Contact Buttons
floating-click-to-contact-buttons
Tạo các nút gọi, nút chat Zalo, nút Chat messenger, nút để lại thông tin để tư vấn, nút chỉ đường. Trình bày các nút đẹp mắt ở góc phải dưới màn hình, …
Click to Call or Chat Buttons
click-to-call-or-chat-buttons
This plugin adds Phone Call and WhatsApp button on your webpage.
WP Call Button – Easy Click to Call Button for WordPress Developer Profile
94 plugins · 23.5M total installs
How We Detect WP Call Button – Easy Click to Call Button for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-call-button/assets/css/jquery.minicolors.css/wp-content/plugins/wp-call-button/assets/css/intlTelInput.min.css/wp-content/plugins/wp-call-button/assets/css/select2.min.css/wp-content/plugins/wp-call-button/assets/css/custom_admin.css/wp-content/plugins/wp-call-button/assets/js/jquery.matchHeight.min.js/wp-content/plugins/wp-call-button/assets/js/jquery.minicolors.min.js/wp-content/plugins/wp-call-button/assets/js/select2.min.js/wp-content/plugins/wp-call-button/assets/js/clipboard.min.js+2 more/wp-content/plugins/wp-call-button/autoload-php-fig-psr4.phpwp-call-button/assets/css/jquery.minicolors.css?ver=wp-call-button/assets/css/intlTelInput.min.css?ver=wp-call-button/assets/css/select2.min.css?ver=wp-call-button/assets/css/custom_admin.css?ver=wp-call-button/assets/js/jquery.matchHeight.min.js?ver=wp-call-button/assets/js/jquery.minicolors.min.js?ver=wp-call-button/assets/js/select2.min.js?ver=wp-call-button/assets/js/clipboard.min.js?ver=wp-call-button/assets/js/intlTelInput.min.js?ver=wp-call-button/assets/js/utils.js?ver=HTML / DOM Fingerprints
wpcallbtn-containerwpcallbtn-buttonwpcallbtn-button-enabledwpcallbtn-phone-numwpcallbtn-button-filter-typewpcallbtn-button-filter-ids-showwpcallbtn-button-filter-ids-hideWpCallButtonPluginWpCallButtonUninstallReview