Call Response – Turn visitors into phone-leads. Get direct calls from your site Security & Risk Analysis

wordpress.org/plugins/wp-call-response

Get call requests from people with email notification, easily handle the requests with huge options to control the user interface.

0 active installs v1.0 PHP 5.2.4+ WP 4.6+ Updated Feb 20, 2020
customersinternet-marketingleads-gatheringlist-buildingsales
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Call Response – Turn visitors into phone-leads. Get direct calls from your site Safe to Use in 2026?

Generally Safe

Score 85/100

Call Response – Turn visitors into phone-leads. Get direct calls from your site has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The wp-call-response plugin version 1.0 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all its SQL queries and a high percentage of properly escaped outputs. There is also no recorded vulnerability history, suggesting a relatively stable and secure past.

However, significant concerns arise from the attack surface analysis. A substantial portion of the plugin's entry points, specifically 4 out of 5, lack authentication checks. This is particularly worrying as it includes 4 unprotected AJAX handlers, which are common targets for malicious exploitation. While no critical or high severity taint flows were identified, the lack of robust authentication on these entry points could still allow for unauthorized actions if specific vulnerabilities were to be discovered or exploited through other means.

The absence of known CVEs and a clean vulnerability history is a strong positive, indicating that the plugin has not been a source of widespread security issues in the past. Nevertheless, the high number of unprotected AJAX handlers presents a clear and present risk that should be addressed. The plugin's strengths lie in its secure database interaction and output handling, but its weaknesses are evident in its vulnerable entry points.

Key Concerns

  • 4 unprotected AJAX handlers
  • Large attack surface without auth (4/5 entry points)
  • 2 external HTTP requests (potential for SSRF or misconfiguration)
Vulnerabilities
None known

Call Response – Turn visitors into phone-leads. Get direct calls from your site Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Call Response – Turn visitors into phone-leads. Get direct calls from your site Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
11 prepared
Unescaped Output
12
130 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared11 total queries

Output Escaping

92% escaped142 total outputs
Data Flows
All sanitized

Data Flow Analysis

5 flows
<callresponse> (callresponse.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Call Response – Turn visitors into phone-leads. Get direct calls from your site Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 4

authwp_ajax_cractionresponse_adminajxlcncindex.php:128
authwp_ajax_crresponsecallstatupindex.php:142
authwp_ajax_cllrspncsubmitrqstindex.php:152
noprivwp_ajax_cllrspncsubmitrqstindex.php:153

Shortcodes 1

[CallResponse] index.php:84
WordPress Hooks 6
actionadmin_menuindex.php:30
actionwp_footerindex.php:72
actionwp_enqueue_scriptsindex.php:89
actionadmin_enqueue_scriptsindex.php:101
actionadmin_footerresponse-sequence\plugin.php:22
actionadmin_menuresponse-sequence\plugin.php:236
Maintenance & Trust

Call Response – Turn visitors into phone-leads. Get direct calls from your site Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedFeb 20, 2020
PHP min version5.2.4
Downloads1K

Community Trust

Rating100/100
Number of ratings6
Active installs0
Developer Profile

Call Response – Turn visitors into phone-leads. Get direct calls from your site Developer Profile

Teknikforce Ventures

7 plugins · 60 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Call Response – Turn visitors into phone-leads. Get direct calls from your site

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-call-response/shortcodecss/style.css/wp-content/plugins/wp-call-response/asset/bootstrap/css/bootstrap.min.css/wp-content/plugins/wp-call-response/asset/bootstrap/js/popper.min.js/wp-content/plugins/wp-call-response/asset/bootstrap/js/bootstrap.min.js/wp-content/plugins/wp-call-response/asset/fontawesome/css/all.css
Script Paths
/wp-content/plugins/wp-call-response/shortcodecss/style.css

HTML / DOM Fingerprints

Shortcode Output
[CallResponse]
FAQ

Frequently Asked Questions about Call Response – Turn visitors into phone-leads. Get direct calls from your site