
123eworld SMS Security & Risk Analysis
wordpress.org/plugins/123eworld-smsConfigure 123eworld account details and send sms using 123eworld SMS API.
Is 123eworld SMS Safe to Use in 2026?
Generally Safe
Score 100/100123eworld SMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "123eworld-sms" plugin version 1.0.0 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerability history, which suggests a level of diligence from the developer. However, the static analysis reveals significant security concerns, particularly in its handling of entry points.
The plugin has a total of one entry point, an AJAX handler, which critically lacks any authentication or capability checks. This is a major security flaw, as it exposes this handler to any unauthenticated user. While no dangerous functions were identified and external HTTP requests are present (which is not inherently bad), the absence of nonce checks and capability checks on the sole entry point creates a substantial risk. Taint analysis indicates flows with unsanitized paths, though no critical or high-severity issues were flagged in this specific analysis. The high percentage of properly escaped output (80%) is a positive signal, but it doesn't mitigate the risk posed by the unprotected AJAX handler.
In conclusion, the plugin's lack of authentication on its AJAX endpoint is its most pressing security weakness, overshadowing its strengths in SQL handling and its clean vulnerability history. This single unprotected entry point creates a direct path for potential exploitation. While the absence of known vulnerabilities is encouraging, the design of the AJAX handler poses an immediate and significant risk that needs urgent attention. The developer should prioritize implementing proper authentication and authorization mechanisms for all entry points.
Key Concerns
- AJAX handler without auth checks
- No nonce checks on entry points
- No capability checks on entry points
- Flows with unsanitized paths
- Some output not properly escaped
123eworld SMS Security Vulnerabilities
123eworld SMS Code Analysis
Output Escaping
Data Flow Analysis
123eworld SMS Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
123eworld SMS Maintenance & Trust
Maintenance Signals
Community Trust
123eworld SMS Alternatives
ClickSend SMS Woo Integration
clicksendsms
ClickSend SMS Woo Integration helps to send transactions & promotional sms to wooCommerce store owners.
text message sms plugin
text-message
text message by biz text lets your website receive and send text messages. reply to text messages from a pc or forward messages to your mobile phone.
Branded SMS Pakistan
branded-sms-pakistan
Branded SMS Pakistan - WooCommerce plugin will allow you to send Branded or Short Code SMS notification automatically for orders placed in WooCommerce …
Exsile SMS Gateway
exsile-sms-gateway
Sending SMS messages easily on your website when forms are submitted.
SB SMS Sender
sb-sms-sender
Send SMS to client using SMS club.
123eworld SMS Developer Profile
1 plugin · 0 total installs
How We Detect 123eworld SMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/123eworld-sms/css/admin.css/wp-content/plugins/123eworld-sms/js/admin.js123eworld-sms/css/admin.css?ver=123eworld-sms/js/admin.js?ver=HTML / DOM Fingerprints
wrapdescriptionupdatederrorname="123eworld_sms_option[user_name]"name="123eworld_sms_option[password]"name="123eworld_sms_option[senderid]"name="123eworld_sms_option[user_name]"name="123eworld_sms_option[password]"name="123eworld_sms_option[senderid]"+10 moreajax_object.ajax_url