
Bomb – SMS Notifier Security & Risk Analysis
wordpress.org/plugins/bomb-sms-notifierWooCommerce order sms, order notification, custom order sms, send quick sms.
Is Bomb – SMS Notifier Safe to Use in 2026?
Generally Safe
Score 85/100Bomb – SMS Notifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis, the "bomb-sms-notifier" plugin v1.0.0 exhibits a generally good security posture. There are no identified dangerous functions, SQL queries are all prepared, and the majority of output is properly escaped. The plugin also correctly implements nonce and capability checks, indicating an awareness of core WordPress security practices. The absence of any recorded vulnerabilities, CVEs, or concerning taint flows further strengthens this assessment.
However, it's important to note the complete lack of identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) in the static analysis. While this suggests a minimal attack surface, it could also indicate limitations in the static analysis tool itself or that the plugin's functionality is entirely passive and relies on external triggers. The bundled Guzzle library, while not explicitly flagged as a vulnerability here, should be monitored for potential security issues in its own right, especially if it's an older version.
In conclusion, "bomb-sms-notifier" v1.0.0 appears to be a secure plugin based on the current data, with strong adherence to fundamental WordPress security best practices. The lack of historical vulnerabilities is a positive indicator. The only minor points of consideration are the potential for the static analysis to be incomplete in identifying entry points and the general need to keep bundled libraries updated.
Key Concerns
- Bundled Guzzle library detected
Bomb – SMS Notifier Security Vulnerabilities
Bomb – SMS Notifier Code Analysis
Bundled Libraries
Output Escaping
Bomb – SMS Notifier Attack Surface
WordPress Hooks 7
Maintenance & Trust
Bomb – SMS Notifier Maintenance & Trust
Maintenance Signals
Community Trust
Bomb – SMS Notifier Alternatives
TextMe SMS
textme-sms-integration
Send custom SMS messages from your WordPress site to your customers using the TextMe SMS gateway.
Messagemedia for WooCommerce
messagemedia-for-woocommerce
Messagemedia Integration for WooCommerce
SwiftNotify – Instant Order Alerts for WooCommerce
whatswift-woo-notifier
Send instant messages to your WooCommerce customers and store admin when orders are placed or updated — powered by the SwiftNotify API.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
sms-alert
Send WooCommerce SMS notifications, OTP verification, abandoned cart recovery alerts, and real-time order updates to customers and admins.
Bomb – SMS Notifier Developer Profile
5 plugins · 300 total installs
How We Detect Bomb – SMS Notifier
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bomb-sms-notifier/assets/css/sms-notifier.css/wp-content/plugins/bomb-sms-notifier/assets/js/sms-notifier.js/wp-content/plugins/bomb-sms-notifier/assets/js/sms-notifier.jsbomb-sms-notifier/assets/css/sms-notifier.css?ver=bomb-sms-notifier/assets/js/sms-notifier.js?ver=HTML / DOM Fingerprints
SMS_NOTIFIER_DATA