
ZVI CallBack widget Security & Risk Analysis
wordpress.org/plugins/zvi-callback-widgetThis plugin makes a simple widget for callback on your website.
Is ZVI CallBack widget Safe to Use in 2026?
Generally Safe
Score 100/100ZVI CallBack widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zvi-callback-widget v1.0 plugin demonstrates a generally good security posture with several strong practices in place. Notably, it boasts no known vulnerabilities, no external HTTP requests, and all SQL queries are correctly prepared. The presence of nonce and capability checks on its two AJAX entry points is also a positive sign, indicating an awareness of common WordPress security pitfalls. However, a significant concern lies in its output escaping. With 96 total outputs and only 15% properly escaped, this plugin presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis did not reveal critical or high-severity flows, the high rate of unescaped output means that even low-severity flows could be leveraged into XSS. The single file operation without further context is also a point of mild concern, though its impact is unclear without knowing the specific operation and its context. The absence of any vulnerability history is a strength, but coupled with the output escaping issue, it might indicate that the plugin has not been extensively targeted or that existing vulnerabilities have gone unnoticed. Overall, the plugin is built on a reasonably secure foundation, but the widespread lack of output escaping is a critical weakness that needs immediate attention.
Key Concerns
- Insufficient output escaping (85% unescaped)
- Presence of file operations
ZVI CallBack widget Security Vulnerabilities
ZVI CallBack widget Code Analysis
Output Escaping
Data Flow Analysis
ZVI CallBack widget Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
ZVI CallBack widget Maintenance & Trust
Maintenance Signals
Community Trust
ZVI CallBack widget Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Contact Form 7 – Dynamic Text Extension
contact-form-7-dynamic-text-extension
Extends Contact Form 7 by adding dynamic form fields that accepts shortcodes to prepopulate form fields with default values and dynamic placeholders.
ZVI CallBack widget Developer Profile
1 plugin · 100 total installs
How We Detect ZVI CallBack widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zvi-callback-widget/css/zvi-widget.css/wp-content/plugins/zvi-callback-widget/js/zvi-widget.js/wp-content/plugins/zvi-callback-widget/css/zvi-widget-admin.css/wp-content/plugins/zvi-callback-widget/js/jqColorPicker.min.js/wp-content/plugins/zvi-callback-widget/js/zvi-widget.js/wp-content/plugins/zvi-callback-widget/js/jqColorPicker.min.jsHTML / DOM Fingerprints
callback_overlaycallback_popupcallback_close-btnzviinputcallback_buttonphoncirclcircl-fill+2 moreid="zviform"id="zvi_callback_title"id="zvi_callback_subtitle"id="callback_form"id="name"id="tel"+1 morezviCallback<div class="callback_overlay"></div><div id="zviform" class="callback_popup text-center"><div class="callback_close-btn">×</div><h2 id="zvih2">