
Broadnet SMS Services Security & Risk Analysis
wordpress.org/plugins/broadnet-sms-servicesA plugin for sending SMS notification to customers and administrator when orders status is changed using WooCommerce.
Is Broadnet SMS Services Safe to Use in 2026?
Generally Safe
Score 85/100Broadnet SMS Services has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "broadnet-sms-services" plugin version 0.0.2 presents a mixed security posture. While it exhibits strengths in avoiding dangerous functions, utilizing prepared statements for SQL queries, and having no recorded historical vulnerabilities, significant concerns arise from its attack surface. The plugin has two identified AJAX handlers, both of which lack authentication checks, creating a direct pathway for unauthorized actions. The output escaping is also a concern, with only 51% of outputs being properly escaped, leaving room for potential cross-site scripting (XSS) vulnerabilities. The absence of taint analysis results is neutral; it could indicate clean code or insufficient analysis.
Given the identified unprotected AJAX endpoints, there is a clear risk of privilege escalation or unauthorized data manipulation if these handlers perform sensitive operations. The moderate output escaping rate further exacerbates this risk, potentially allowing malicious scripts to be injected and executed. The plugin's clean vulnerability history is a positive indicator, suggesting a generally secure development approach, but it does not negate the immediate risks identified in the static analysis.
In conclusion, the "broadnet-sms-services" plugin has a concerning lack of security controls on its AJAX endpoints, which is the most critical weakness. While its SQL handling and historical security are positive, the unprotected entry points and moderate output escaping create a tangible risk that needs immediate attention. Developers should prioritize implementing proper authentication and capability checks for all AJAX handlers and improve output escaping to mitigate these vulnerabilities.
Key Concerns
- AJAX handlers without auth checks
- Moderate output escaping rate
Broadnet SMS Services Security Vulnerabilities
Broadnet SMS Services Code Analysis
Output Escaping
Broadnet SMS Services Attack Surface
AJAX Handlers 2
WordPress Hooks 32
Maintenance & Trust
Broadnet SMS Services Maintenance & Trust
Maintenance Signals
Community Trust
Broadnet SMS Services Alternatives
No alternatives data available yet.
Broadnet SMS Services Developer Profile
1 plugin · 0 total installs
How We Detect Broadnet SMS Services
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/broadnet-sms-services/css/broadnet-sms-services-admin.css/wp-content/plugins/broadnet-sms-services/js/broadnet-sms-services-admin.jsbroadnet-sms-services-admin.css?ver=broadnet-sms-services-admin.js?ver=