
WP Call Me Security & Risk Analysis
wordpress.org/plugins/wp-call-meTake calls from your website with an easy to install click to call button.
Is WP Call Me Safe to Use in 2026?
Generally Safe
Score 85/100WP Call Me has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-call-me plugin v1.7 exhibits a concerning security posture primarily due to a lack of proper authorization checks on its entry points and insecure handling of serialized data. The static analysis reveals two AJAX handlers, both of which are exposed without any authentication or capability checks, creating a significant attack surface. Furthermore, the presence of the 'unserialize' function without clear sanitization or validation indicates a potential for deserialization vulnerabilities, especially when combined with unsanitized input from the identified taint flows. While the plugin has no recorded vulnerability history, this absence should not be interpreted as a guarantee of current security. The lack of reported vulnerabilities might simply mean they haven't been discovered or publicly disclosed yet. The plugin's strengths lie in its use of prepared statements for SQL queries and the absence of file operations or external HTTP requests, which reduces some common attack vectors. However, the critical issues of unprotected AJAX endpoints and the 'unserialize' function heavily outweigh these positives, demanding immediate attention.
Key Concerns
- AJAX handlers without authentication
- Unescaped output detected
- Dangerous function 'unserialize' used
- Taint flows with unsanitized paths
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
WP Call Me Security Vulnerabilities
WP Call Me Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WP Call Me Attack Surface
AJAX Handlers 2
WordPress Hooks 4
Maintenance & Trust
WP Call Me Maintenance & Trust
Maintenance Signals
Community Trust
WP Call Me Alternatives
Excitel – Click to call
excitel-click-to-call
Excitel helps your customers make calls from your site over Internet (free) using WebRTC, RTMP and SIP protocols.
Easy Caller with Mocean
easy-caller-with-moceanapi
Easy Caller uses Mocean Voice API to connect calls with you and your customers both easily and efficiently.
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
Really Simple Click To Call Bar
really-simple-click-to-call
A simple plugin that adds a click to call bar/call now button for mobile visitors.
Floating Click to Contact Buttons
floating-click-to-contact-buttons
Tạo các nút gọi, nút chat Zalo, nút Chat messenger, nút để lại thông tin để tư vấn, nút chỉ đường. Trình bày các nút đẹp mắt ở góc phải dưới màn hình, …
WP Call Me Developer Profile
2 plugins · 20 total installs
How We Detect WP Call Me
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-call-me/js/intlTelInput.js/wp-content/plugins/wp-call-me/js/signup.jsjs/intlTelInput.jsjs/signup.jsHTML / DOM Fingerprints
wp_phone_form_tablewp_phone_default_number_shortcodeCopyright 2013 Taylor Hawkes (email : thawkes@woodstitch.com)stuff to do when we create pluginthese are for updting the cache automaticlyput all js stuff here+6 moreid="wp_phone_holder"id="wp_call_me_user_settings"id="wp_click_to_call_not_supported"id="wp_click_to_call_color_theme"intlTelInputsignup[wp_phone_clicktocall][wp_phone_number]