AP SMS Manager Security & Risk Analysis

wordpress.org/plugins/ap-sms-manager

AP SMS Manager helps you turn your website into an SMS as a service web app. It makes it a breeze to send bulk sms messages to your contacts, using pr …

10 active installs v0.0.6 PHP 7.2+ WP 5.2+ Updated May 22, 2022
smssms-apisms-gatewayssms-manager
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AP SMS Manager Safe to Use in 2026?

Generally Safe

Score 85/100

AP SMS Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "ap-sms-manager" v0.0.6 plugin exhibits a generally strong security posture based on the provided static analysis. There are no detected dangerous functions, SQL queries are all prepared, and output is properly escaped. Crucially, the taint analysis reveals no critical or high severity flows, and there are no recorded historical vulnerabilities. This indicates a thoughtful development process regarding common web application security threats. The absence of external HTTP requests and file operations further reduces potential attack vectors. The plugin also utilizes bundled libraries like Lodash and Guzzle, which are common and generally well-maintained.

However, the lack of any nonces or capability checks, combined with zero entry points identified, raises a significant concern. While no *active* vulnerabilities are reported, this absence of security measures on potential entry points suggests a potential blind spot. If new entry points are introduced or if the analysis missed a subtle way to interact with the plugin's logic, the lack of these fundamental security checks could expose the site to attacks that might otherwise be prevented. The vulnerability history being completely clean is a positive sign, but it cannot entirely mitigate the risk posed by the missing authentication and authorization checks on any potential (even if currently unidentified) entry points.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

AP SMS Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AP SMS Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

LodashGuzzle

SQL Query Safety

100% prepared1 total queries
Attack Surface

AP SMS Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitap-sms-manager.php:26
actionrest_api_initsrc\Core\Hooks\Routes.php:14
Maintenance & Trust

AP SMS Manager Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMay 22, 2022
PHP min version7.2
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

AP SMS Manager Developer Profile

Support@Appsbay

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AP SMS Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ap-sms-manager/assets/styles/app.css/wp-content/plugins/ap-sms-manager/assets/js/app.js/wp-content/plugins/ap-sms-manager/assets/fonts/fonts.css
Script Paths
/wp-content/plugins/ap-sms-manager/assets/js/app.js
Version Parameters
ap-sms-manager/assets/styles/app.css?ver=ap-sms-manager/assets/js/app.js?ver=ap-sms-manager/assets/fonts/fonts.css?ver=0.0.1

HTML / DOM Fingerprints

JS Globals
aps_globals_one
REST Endpoints
/wp-json/apps-bay-sms-manager/v1/contacts/sync/woocommerce
FAQ

Frequently Asked Questions about AP SMS Manager