
Awesome SMS for Woocommerce Security & Risk Analysis
wordpress.org/plugins/awesome-sms-for-woocommerceyou can now keep your customers up to date on their order process via SMS. Send the customer an SMS when they place the order, and also when the order …
Is Awesome SMS for Woocommerce Safe to Use in 2026?
Generally Safe
Score 100/100Awesome SMS for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'awesome-sms-for-woocommerce' plugin version 1.0 presents a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and avoiding dangerous functions and file operations, there are significant concerns regarding its attack surface and output sanitization.
The plugin exposes a total of 4 entry points through AJAX handlers, with a critical vulnerability: all 4 lack authentication checks. This means any unauthenticated user could potentially interact with these handlers, leading to various security issues if they are not properly secured within the handler's logic. Although the taint analysis didn't reveal critical or high severity unsanitized flows, the presence of one flow with an unsanitized path is a cause for concern, especially when combined with unprotected AJAX endpoints.
Furthermore, only 51% of outputs are properly escaped, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities, particularly on the endpoints that are also unprotected. The plugin's vulnerability history is clean, which is a positive sign, suggesting that past versions may have been developed with security in mind. However, this does not negate the immediate risks identified in the current code analysis. The conclusion is that while the plugin avoids some common pitfalls like raw SQL and dangerous functions, the lack of authentication on all AJAX handlers and the high percentage of unescaped outputs create a substantial security risk.
Key Concerns
- AJAX handlers without auth checks
- High percentage of unescaped output
- Flows with unsanitized paths (even if not critical)
Awesome SMS for Woocommerce Security Vulnerabilities
Awesome SMS for Woocommerce Code Analysis
Output Escaping
Data Flow Analysis
Awesome SMS for Woocommerce Attack Surface
AJAX Handlers 4
WordPress Hooks 28
Maintenance & Trust
Awesome SMS for Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
Awesome SMS for Woocommerce Alternatives
افزونه پیامک حرفه ای فراز اس ام اس
farazsms
شما می توانید با استفاده از افزونه فراز اس ام اس، سایت خود را با ابزاری خودکار برای ارسال پیامک و ذخیره شماره در دفترچه تلفن، تقویت کنید.
Gray SMS – Complete SMS Notificaitons for WordPress, Woocommerce & Multi Features
gray-sms
Send WooCommerce order notifications and individual SMS messages using Twilio, Vonage, Plivo, Clickatell and other SMS gateways.
KhudeBarta Order Notify
khudebarta-order-notify
Send SMS via KhudeBarta API and notify customers automatically when WooCommerce order statuses change.
SMSPlus for WooCommerce
smsplus-for-woocommerce
Send SMS notifications to your customers when WooCommerce order statuses change, powered by the SMSPlus API.
Zibad Smart Notifier
zibad-smart-notifier
Smart Notifier helps WooCommerce stores send automated SMS notifications for order events.
Awesome SMS for Woocommerce Developer Profile
3 plugins · 60 total installs
How We Detect Awesome SMS for Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/awesome-sms-for-woocommerce/css/style.css/wp-content/plugins/awesome-sms-for-woocommerce/js/scripts.jsawesome-sms-for-woocommerce/css/style.css?ver=awesome-sms-for-woocommerce/js/scripts.js?ver=HTML / DOM Fingerprints
asmsfw-admin-noticedata-sms-codedata-user-idasmsfw_ajax_object/wp-json/smscp/v2/activate//wp-json/smscp/v2/smsCreditDetails//wp-json/smscp/v2/sendSMS/